Personal email blocked
Clinician cannot send visit summaries via personal Gmail — only approved secure messaging or patient portal.
AC-4(20) requires approved solutions as an enhancement to base AC-4 information flow enforcement. Base AC-4 establishes that flows must be authorized; this enhancement adds: Permit only approved transfer solutions (managed file transfer, HIE, EHR Direct) for ePHI — block shadow IT file shares and personal email. Healthcare delivery organizations rely on this to keep ePHI within approved clinical, billing, and research pathways.
Require organization-approved solutions when transferring ePHI across flow-controlled boundaries.
How this control shows up in healthcare and HIPAA-covered environments.
Clinician cannot send visit summaries via personal Gmail — only approved secure messaging or patient portal.
Department stops using consumer file-share links; approved managed file transfer is the only ePHI path.
Outbound Direct messages only to addresses on the approved HISP/solution list.
Assessors look for operating evidence of Approved Solutions on systems touching ePHI — screenshots, logs, and failed-test results — not only a policy paragraph referencing AC-4(20).
How this NIST control supports HIPAA Security Rule expectations.
Managed file transfer, HIE, EHR Direct/portal — not personal email or consumer sharing links.
Technical allow-lists, CASB, and endpoint controls — not memo alone.
Security/privacy review plus BAA before approval.
Related controls that commonly accompany AC-4(20).
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.