AC-4(21) Access Control

Physical or Logical Separation of Information Flows

High Risk Complex High Cost

AC-4(21) requires physical or logical separation of information flows as an enhancement to base AC-4 information flow enforcement. Base AC-4 establishes that flows must be authorized; this enhancement adds: Physically or logically separate flows of differing sensitivity (e.g., guest vs clinical, cardholder vs EHR, research identifiable vs de-identified). Healthcare delivery organizations rely on this to keep ePHI within approved clinical, billing, and research pathways.

Control Objective

Separate information flows of different character physically or logically so ePHI paths do not mix with lower-trust traffic.

Implementation Guidance

  1. Classify flows by character (guest, clinical, payment, research identifiable).
  2. Implement physical or logical separation matching classification.
  3. Verify no hairpin mixing between guest and EHR.
  4. Separate PCI and ePHI paths where both exist.
  5. Use dedicated VRFs/VPCs for identifiable research.
  6. Test separation after network changes.
  7. Document separation in diagrams.
  8. Include separation in risk analysis.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Guest vs clinical separation

Guest Wi-Fi physically/logically separated from EHR VLANs; captive portal cannot reach charting subnets.

Cardholder vs ePHI

Payment flows separated from clinical information flows to reduce blended PCI/HIPAA blast radius.

Research identifiable enclave

Identifiable research traffic stays on dedicated VRFs apart from general corporate collaboration traffic.

Best Practices

  • Tie AC-4(21) to named owners in IAM/privacy/security.
  • Prefer system enforcement over informal email approval.
  • Measure coverage on systems that store or transmit ePHI.
  • Review exceptions at least quarterly.
  • Correlate events into SIEM use cases.
  • Document mapping to HIPAA safeguards in the SSP.

Common Gaps & Violations

  • Policy claims physical or logical separation of information flows but no technical enforcement on EHR paths.
  • Exceptions granted permanently without review.
  • Vendors and research feeds left out of scope.
  • Logs not retained or not reviewed.
  • Upgrades silently disable the control.

Required Documentation

  • Policy/procedure for Physical or Logical Separation of Information Flows (AC-4(21))
  • Configuration baselines and diagrams
  • Exception register
  • Sample logs/alerts
  • Training or runbook evidence

How to Test & Validate

  1. Attempt a prohibited action related to physical or logical separation of information flows; confirm block or required workflow.
  2. Complete an authorized path; confirm success and logging.
  3. Sample exceptions for expiry and approval.
  4. Verify ePHI systems in scope are covered (not only corporate IT).
  5. Confirm SIEM/alert or retention evidence for the last 90 days.

Audit Considerations

Assessors look for operating evidence of Physical or Logical Separation of Information Flows on systems touching ePHI — screenshots, logs, and failed-test results — not only a policy paragraph referencing AC-4(21).

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.312(a)(1) Access Control — limit system access and, by extension, unauthorized information movement.
  • 164.312(e)(1) Transmission Security — guard ePHI transmitted over networks and interconnections.
  • 164.308(a)(4) Information Access Management — policies for access and disclosure pathways.
  • 164.530(c) Safeguards / 164.514 Minimum Necessary — reduce unnecessary data in flows.

Compliance Tips

  • List AC-4(21) explicitly in the system security plan control matrix.
  • Prioritize EHR, VPN, HIE, and BA file-transfer paths.
  • Keep a one-page evidence pack (config + sample log + exception list) ready for assessors.

Frequently Asked Questions

Physical vs logical?

Either can meet the enhancement if flows of different character cannot mix unsafely.

Guest Wi-Fi classic case?

Yes — separate guest from clinical information flows.

Cloud equivalent?

Separate VPCs/projects and path controls for differing data character.

References & Resources

  • NIST SP 800-53 Rev. 5 — AC-4(21)
  • Related controls: AC-4, AC-4(2), SC-7, SC-32

Need Help Implementing AC-4(21)?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.