Multi-hospital interconnection
Affiliate hospitals exchange ADTs only through the agreed interface engine and TLS profile — ad-hoc VPN file copies denied.
AC-4(16) requires information transfers on interconnected systems as an enhancement to base AC-4 information flow enforcement. Base AC-4 establishes that flows must be authorized; this enhancement adds: Control ePHI transfers across interconnected hospitals, affiliates, HIEs, and cloud tenants with explicit interconnection agreements and technical mediation. Healthcare delivery organizations rely on this to keep ePHI within approved clinical, billing, and research pathways.
Control information transfers on interconnected systems so ePHI crosses organizational connections only on approved paths.
How this control shows up in healthcare and HIPAA-covered environments.
Affiliate hospitals exchange ADTs only through the agreed interface engine and TLS profile — ad-hoc VPN file copies denied.
Analytics VPC peered to EHR integration subnet may receive only approved message types per interconnection agreement.
New telehealth BA connection cannot carry full chart export until interconnection security review completes.
Assessors look for operating evidence of Information Transfers on Interconnected Systems on systems touching ePHI — screenshots, logs, and failed-test results — not only a policy paragraph referencing AC-4(16).
How this NIST control supports HIPAA Security Rule expectations.
BAA is necessary but not sufficient — need technical mediation and agreed paths on the interconnection.
Yes — treat cloud peerings as interconnected systems.
Interconnection agreements plus firewall/broker rules matching them.
Related controls that commonly accompany AC-4(16).
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.