AC-4(16) Access Control

Information Transfers on Interconnected Systems

High Risk Complex High Cost

AC-4(16) requires information transfers on interconnected systems as an enhancement to base AC-4 information flow enforcement. Base AC-4 establishes that flows must be authorized; this enhancement adds: Control ePHI transfers across interconnected hospitals, affiliates, HIEs, and cloud tenants with explicit interconnection agreements and technical mediation. Healthcare delivery organizations rely on this to keep ePHI within approved clinical, billing, and research pathways.

Control Objective

Control information transfers on interconnected systems so ePHI crosses organizational connections only on approved paths.

Implementation Guidance

  1. Inventory interconnections (affiliates, HIE, cloud peers, telehealth).
  2. Require interconnection security agreements matching technical paths.
  3. Mediate transfers through approved brokers only.
  4. Block ad-hoc VPN file copies between orgs.
  5. Reassess when new cloud peerings appear.
  6. Log cross-org transfers for audit.
  7. Align BAAs with technical allow-lists.
  8. Test that undocumented paths fail.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Multi-hospital interconnection

Affiliate hospitals exchange ADTs only through the agreed interface engine and TLS profile — ad-hoc VPN file copies denied.

Cloud tenant peering

Analytics VPC peered to EHR integration subnet may receive only approved message types per interconnection agreement.

Telehealth BA link

New telehealth BA connection cannot carry full chart export until interconnection security review completes.

Best Practices

  • Tie AC-4(16) to named owners in IAM/privacy/security.
  • Prefer system enforcement over informal email approval.
  • Measure coverage on systems that store or transmit ePHI.
  • Review exceptions at least quarterly.
  • Correlate events into SIEM use cases.
  • Document mapping to HIPAA safeguards in the SSP.

Common Gaps & Violations

  • Policy claims information transfers on interconnected systems but no technical enforcement on EHR paths.
  • Exceptions granted permanently without review.
  • Vendors and research feeds left out of scope.
  • Logs not retained or not reviewed.
  • Upgrades silently disable the control.

Required Documentation

  • Policy/procedure for Information Transfers on Interconnected Systems (AC-4(16))
  • Configuration baselines and diagrams
  • Exception register
  • Sample logs/alerts
  • Training or runbook evidence

How to Test & Validate

  1. Attempt a prohibited action related to information transfers on interconnected systems; confirm block or required workflow.
  2. Complete an authorized path; confirm success and logging.
  3. Sample exceptions for expiry and approval.
  4. Verify ePHI systems in scope are covered (not only corporate IT).
  5. Confirm SIEM/alert or retention evidence for the last 90 days.

Audit Considerations

Assessors look for operating evidence of Information Transfers on Interconnected Systems on systems touching ePHI — screenshots, logs, and failed-test results — not only a policy paragraph referencing AC-4(16).

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.312(a)(1) Access Control — limit system access and, by extension, unauthorized information movement.
  • 164.312(e)(1) Transmission Security — guard ePHI transmitted over networks and interconnections.
  • 164.308(a)(4) Information Access Management — policies for access and disclosure pathways.
  • 164.530(c) Safeguards / 164.514 Minimum Necessary — reduce unnecessary data in flows.

Compliance Tips

  • List AC-4(16) explicitly in the system security plan control matrix.
  • Prioritize EHR, VPN, HIE, and BA file-transfer paths.
  • Keep a one-page evidence pack (config + sample log + exception list) ready for assessors.

Frequently Asked Questions

Is a BAA enough?

BAA is necessary but not sufficient — need technical mediation and agreed paths on the interconnection.

Multi-cloud in scope?

Yes — treat cloud peerings as interconnected systems.

Evidence for auditors?

Interconnection agreements plus firewall/broker rules matching them.

References & Resources

  • NIST SP 800-53 Rev. 5 — AC-4(16)
  • Related controls: AC-4, CA-3, SC-7

Need Help Implementing AC-4(16)?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.