AC-4(20) Access Control

Approved Solutions

High Risk Moderate Medium Cost

AC-4(20) requires approved solutions as an enhancement to base AC-4 information flow enforcement. Base AC-4 establishes that flows must be authorized; this enhancement adds: Permit only approved transfer solutions (managed file transfer, HIE, EHR Direct) for ePHI — block shadow IT file shares and personal email. Healthcare delivery organizations rely on this to keep ePHI within approved clinical, billing, and research pathways.

Control Objective

Require organization-approved solutions when transferring ePHI across flow-controlled boundaries.

Implementation Guidance

  1. Publish approved ePHI transfer solutions list.
  2. Technically allow-list only approved MFT/HIE/portal paths.
  3. Block consumer email and shadow file-share apps on clinical endpoints.
  4. CASB/proxy enforce sanctioned cloud.
  5. Intake process for new solution approval with BAA.
  6. Remove department shadow tools.
  7. Train workforce on approved paths.
  8. Audit outbound channels quarterly.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Personal email blocked

Clinician cannot send visit summaries via personal Gmail — only approved secure messaging or patient portal.

Shadow MFT replaced

Department stops using consumer file-share links; approved managed file transfer is the only ePHI path.

Unapproved Direct address

Outbound Direct messages only to addresses on the approved HISP/solution list.

Best Practices

  • Tie AC-4(20) to named owners in IAM/privacy/security.
  • Prefer system enforcement over informal email approval.
  • Measure coverage on systems that store or transmit ePHI.
  • Review exceptions at least quarterly.
  • Correlate events into SIEM use cases.
  • Document mapping to HIPAA safeguards in the SSP.

Common Gaps & Violations

  • Policy claims approved solutions but no technical enforcement on EHR paths.
  • Exceptions granted permanently without review.
  • Vendors and research feeds left out of scope.
  • Logs not retained or not reviewed.
  • Upgrades silently disable the control.

Required Documentation

  • Policy/procedure for Approved Solutions (AC-4(20))
  • Configuration baselines and diagrams
  • Exception register
  • Sample logs/alerts
  • Training or runbook evidence

How to Test & Validate

  1. Attempt a prohibited action related to approved solutions; confirm block or required workflow.
  2. Complete an authorized path; confirm success and logging.
  3. Sample exceptions for expiry and approval.
  4. Verify ePHI systems in scope are covered (not only corporate IT).
  5. Confirm SIEM/alert or retention evidence for the last 90 days.

Audit Considerations

Assessors look for operating evidence of Approved Solutions on systems touching ePHI — screenshots, logs, and failed-test results — not only a policy paragraph referencing AC-4(20).

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.312(a)(1) Access Control — limit system access and, by extension, unauthorized information movement.
  • 164.312(e)(1) Transmission Security — guard ePHI transmitted over networks and interconnections.
  • 164.308(a)(4) Information Access Management — policies for access and disclosure pathways.
  • 164.530(c) Safeguards / 164.514 Minimum Necessary — reduce unnecessary data in flows.

Compliance Tips

  • List AC-4(20) explicitly in the system security plan control matrix.
  • Prioritize EHR, VPN, HIE, and BA file-transfer paths.
  • Keep a one-page evidence pack (config + sample log + exception list) ready for assessors.

Frequently Asked Questions

What are approved solutions?

Managed file transfer, HIE, EHR Direct/portal — not personal email or consumer sharing links.

How enforce?

Technical allow-lists, CASB, and endpoint controls — not memo alone.

New tool request?

Security/privacy review plus BAA before approval.

References & Resources

  • NIST SP 800-53 Rev. 5 — AC-4(20)
  • Related controls: AC-4, CM-7, SA-4

Need Help Implementing AC-4(20)?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.