AC-4(2) Access Control

Processing Domains

High Risk Complex High Cost

AC-4(2) requires processing domains as an enhancement to base AC-4 information flow enforcement. Base AC-4 establishes that flows must be authorized; this enhancement adds: Segment clinical, research, guest, IoMT, and corporate processing domains and allow only ordered, mediated flows between them. Healthcare delivery organizations rely on this to keep ePHI within approved clinical, billing, and research pathways.

Control Objective

Separate ePHI processing into protected domains and enforce ordered information flow between those domains.

Implementation Guidance

  1. Define processing domains (clinical EHR, imaging, research, corporate, guest, IoMT, DMZ).
  2. Enforce boundaries with firewalls, microsegmentation, and identity-aware proxies.
  3. Document allowed ordered flows and deny reverse/ad-hoc paths.
  4. Place de-identification and bulk extract in dedicated domains.
  5. Prohibit dual-homed workstations bridging clinical and guest domains.
  6. Monitor cross-domain connection attempts.
  7. Review domain membership when systems move to cloud.
  8. Align domain model with SSP network diagrams.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Research analytics domain

Identifiable extracts land only in a research processing domain with no direct write path back to production EHR APIs.

IoMT pump VLAN

Infusion pumps stay in an IoMT domain; only a broker may send limited ADT demographics — pumps cannot initiate sessions into the EHR database domain.

Guest Wi-Fi isolation

Patient/visitor Wi-Fi has no route to clinical domains; captive portal traffic stays in guest processing space.

Best Practices

  • Tie AC-4(2) to named owners in IAM/privacy/security.
  • Prefer system enforcement over informal email approval.
  • Measure coverage on systems that store or transmit ePHI.
  • Review exceptions at least quarterly.
  • Correlate events into SIEM use cases.
  • Document mapping to HIPAA safeguards in the SSP.

Common Gaps & Violations

  • Policy claims processing domains but no technical enforcement on EHR paths.
  • Exceptions granted permanently without review.
  • Vendors and research feeds left out of scope.
  • Logs not retained or not reviewed.
  • Upgrades silently disable the control.

Required Documentation

  • Policy/procedure for Processing Domains (AC-4(2))
  • Configuration baselines and diagrams
  • Exception register
  • Sample logs/alerts
  • Training or runbook evidence

How to Test & Validate

  1. Attempt a prohibited action related to processing domains; confirm block or required workflow.
  2. Complete an authorized path; confirm success and logging.
  3. Sample exceptions for expiry and approval.
  4. Verify ePHI systems in scope are covered (not only corporate IT).
  5. Confirm SIEM/alert or retention evidence for the last 90 days.

Audit Considerations

Assessors look for operating evidence of Processing Domains on systems touching ePHI — screenshots, logs, and failed-test results — not only a policy paragraph referencing AC-4(2).

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.312(a)(1) Access Control — limit system access and, by extension, unauthorized information movement.
  • 164.312(e)(1) Transmission Security — guard ePHI transmitted over networks and interconnections.
  • 164.308(a)(4) Information Access Management — policies for access and disclosure pathways.
  • 164.530(c) Safeguards / 164.514 Minimum Necessary — reduce unnecessary data in flows.

Compliance Tips

  • List AC-4(2) explicitly in the system security plan control matrix.
  • Prioritize EHR, VPN, HIE, and BA file-transfer paths.
  • Keep a one-page evidence pack (config + sample log + exception list) ready for assessors.

Frequently Asked Questions

Are VLANs alone enough?

VLANs help, but processing domains need enforced ordered flow policy between them — not just port labels.

How does this differ from SC-7?

SC-7 focuses on system boundaries; AC-4(2) emphasizes ordered information flow across processing domains.

Do SaaS EHR tenants count as domains?

Treat each trust environment (prod, nonprod, analytics) as a domain and control flows among them.

References & Resources

  • NIST SP 800-53 Rev. 5 — AC-4(2)
  • Related controls: AC-4, SC-7, SC-32, AC-4(21)

Need Help Implementing AC-4(2)?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.