AC-4(15) Access Control

Detection of Unsanctioned Information

High Risk Complex Medium Cost

AC-4(15) requires detection of unsanctioned information as an enhancement to base AC-4 information flow enforcement. Base AC-4 establishes that flows must be authorized; this enhancement adds: Detect unsanctioned information in flows (unexpected ePHI in tickets, chat, or research drops) and block or alert before wider disclosure. Healthcare delivery organizations rely on this to keep ePHI within approved clinical, billing, and research pathways.

Control Objective

Detect unsanctioned information within transfers and take organization-defined actions to protect ePHI.

Implementation Guidance

  1. Extend detection to tickets, chat, email, and collaboration sites.
  2. Tune detectors for MRN/DOB/SSN and clinical note patterns.
  3. Define block vs alert actions by severity.
  4. Integrate with incident response when public exposure risk exists.
  5. Reduce false positives with allow-lists for known safe patterns.
  6. Cover research and QI drop folders.
  7. Report unsanctioned-info metrics monthly.
  8. Educate workforce using real redacted examples.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

PHI pasted into ITSM ticket

Detector flags MRN+DOB in a ServiceNow comment and blocks or redacts before wider IT sees it.

Chat exfil of discharge summary

DLP on collaboration tools detects unsanctioned paste of discharge text into an external channel.

Shadow research folder

Scan finds identifiable spreadsheets in a public SharePoint; flow to external guests is cut and owners notified.

Best Practices

  • Tie AC-4(15) to named owners in IAM/privacy/security.
  • Prefer system enforcement over informal email approval.
  • Measure coverage on systems that store or transmit ePHI.
  • Review exceptions at least quarterly.
  • Correlate events into SIEM use cases.
  • Document mapping to HIPAA safeguards in the SSP.

Common Gaps & Violations

  • Policy claims detection of unsanctioned information but no technical enforcement on EHR paths.
  • Exceptions granted permanently without review.
  • Vendors and research feeds left out of scope.
  • Logs not retained or not reviewed.
  • Upgrades silently disable the control.

Required Documentation

  • Policy/procedure for Detection of Unsanctioned Information (AC-4(15))
  • Configuration baselines and diagrams
  • Exception register
  • Sample logs/alerts
  • Training or runbook evidence

How to Test & Validate

  1. Attempt a prohibited action related to detection of unsanctioned information; confirm block or required workflow.
  2. Complete an authorized path; confirm success and logging.
  3. Sample exceptions for expiry and approval.
  4. Verify ePHI systems in scope are covered (not only corporate IT).
  5. Confirm SIEM/alert or retention evidence for the last 90 days.

Audit Considerations

Assessors look for operating evidence of Detection of Unsanctioned Information on systems touching ePHI — screenshots, logs, and failed-test results — not only a policy paragraph referencing AC-4(15).

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.312(a)(1) Access Control — limit system access and, by extension, unauthorized information movement.
  • 164.312(e)(1) Transmission Security — guard ePHI transmitted over networks and interconnections.
  • 164.308(a)(4) Information Access Management — policies for access and disclosure pathways.
  • 164.530(c) Safeguards / 164.514 Minimum Necessary — reduce unnecessary data in flows.

Compliance Tips

  • List AC-4(15) explicitly in the system security plan control matrix.
  • Prioritize EHR, VPN, HIE, and BA file-transfer paths.
  • Keep a one-page evidence pack (config + sample log + exception list) ready for assessors.

Frequently Asked Questions

Is this DLP again?

Overlaps DLP but focuses on detecting unsanctioned information inside otherwise allowed channels.

What action on detect?

Block, quarantine, redact, or alert per policy severity.

Include tickets and chat?

Yes — common leakage paths for ePHI.

References & Resources

  • NIST SP 800-53 Rev. 5 — AC-4(15)
  • Related controls: AC-4, SI-4, AU-6

Need Help Implementing AC-4(15)?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.