PHI pasted into ITSM ticket
Detector flags MRN+DOB in a ServiceNow comment and blocks or redacts before wider IT sees it.
AC-4(15) requires detection of unsanctioned information as an enhancement to base AC-4 information flow enforcement. Base AC-4 establishes that flows must be authorized; this enhancement adds: Detect unsanctioned information in flows (unexpected ePHI in tickets, chat, or research drops) and block or alert before wider disclosure. Healthcare delivery organizations rely on this to keep ePHI within approved clinical, billing, and research pathways.
Detect unsanctioned information within transfers and take organization-defined actions to protect ePHI.
How this control shows up in healthcare and HIPAA-covered environments.
Detector flags MRN+DOB in a ServiceNow comment and blocks or redacts before wider IT sees it.
DLP on collaboration tools detects unsanctioned paste of discharge text into an external channel.
Scan finds identifiable spreadsheets in a public SharePoint; flow to external guests is cut and owners notified.
Assessors look for operating evidence of Detection of Unsanctioned Information on systems touching ePHI — screenshots, logs, and failed-test results — not only a policy paragraph referencing AC-4(15).
How this NIST control supports HIPAA Security Rule expectations.
Overlaps DLP but focuses on detecting unsanctioned information inside otherwise allowed channels.
Block, quarantine, redact, or alert per policy severity.
Yes — common leakage paths for ePHI.
Related controls that commonly accompany AC-4(15).
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.