Non-bypassable SSN rule
Admin cannot configure a filter profile that allows raw SSN + full chart to public cloud — constraint blocks the save.
AC-4(14) requires security or privacy policy filter constraints as an enhancement to base AC-4 information flow enforcement. Base AC-4 establishes that flows must be authorized; this enhancement adds: Constrain filters so they cannot be configured to violate non-bypassable rules (e.g., never allow raw SSN+full chart to public cloud). Healthcare delivery organizations rely on this to keep ePHI within approved clinical, billing, and research pathways.
Place constraints on policy filters so administrators cannot weaken mandatory ePHI flow protections.
How this control shows up in healthcare and HIPAA-covered environments.
Admin cannot configure a filter profile that allows raw SSN + full chart to public cloud — constraint blocks the save.
Even emergency profiles must keep audit logging and VIP tag enforcement — cannot configure silent full open.
Test filter configs cannot be promoted if they disable mandatory ePHI destination checks.
Assessors look for operating evidence of Security or Privacy Policy Filter Constraints on systems touching ePHI — screenshots, logs, and failed-test results — not only a policy paragraph referencing AC-4(14).
How this NIST control supports HIPAA Security Rule expectations.
Only within constrained emergency profiles that preserve mandatory protections.
Security architecture with privacy — not local filter admins alone.
Attempt to save a noncompliant filter config and confirm reject.
Related controls that commonly accompany AC-4(14).
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.