Label integrity on CCD
Confidentiality label bound with signature; stripping the label in transit causes receiving filter to reject the document.
AC-4(18) requires security attribute binding as an enhancement to base AC-4 information flow enforcement. Base AC-4 establishes that flows must be authorized; this enhancement adds: Bind security/privacy attributes to ePHI with integrity protection so labels cannot be silently stripped in transit across interfaces. Healthcare delivery organizations rely on this to keep ePHI within approved clinical, billing, and research pathways.
Bind security and privacy attributes to transmitted ePHI with sufficient integrity to support trustworthy flow enforcement.
How this control shows up in healthcare and HIPAA-covered environments.
Confidentiality label bound with signature; stripping the label in transit causes receiving filter to reject the document.
Consent flag travels with the message under integrity protection so intermediaries cannot silently clear it.
Protocol attribute bound to extract; altered tag fails validation at the research landing zone.
Assessors look for operating evidence of Security Attribute Binding on systems touching ePHI — screenshots, logs, and failed-test results — not only a policy paragraph referencing AC-4(18).
How this NIST control supports HIPAA Security Rule expectations.
So labels/consent tags cannot be stripped or altered undetected in transit.
TLS protects the channel; binding protects attribute integrity end-to-end across intermediaries.
Fail closed when binding validation fails.
Related controls that commonly accompany AC-4(18).
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.