Guest vs clinical separation
Guest Wi-Fi physically/logically separated from EHR VLANs; captive portal cannot reach charting subnets.
AC-4(21) requires physical or logical separation of information flows as an enhancement to base AC-4 information flow enforcement. Base AC-4 establishes that flows must be authorized; this enhancement adds: Physically or logically separate flows of differing sensitivity (e.g., guest vs clinical, cardholder vs EHR, research identifiable vs de-identified). Healthcare delivery organizations rely on this to keep ePHI within approved clinical, billing, and research pathways.
Separate information flows of different character physically or logically so ePHI paths do not mix with lower-trust traffic.
How this control shows up in healthcare and HIPAA-covered environments.
Guest Wi-Fi physically/logically separated from EHR VLANs; captive portal cannot reach charting subnets.
Payment flows separated from clinical information flows to reduce blended PCI/HIPAA blast radius.
Identifiable research traffic stays on dedicated VRFs apart from general corporate collaboration traffic.
Assessors look for operating evidence of Physical or Logical Separation of Information Flows on systems touching ePHI — screenshots, logs, and failed-test results — not only a policy paragraph referencing AC-4(21).
How this NIST control supports HIPAA Security Rule expectations.
Either can meet the enhancement if flows of different character cannot mix unsafely.
Yes — separate guest from clinical information flows.
Separate VPCs/projects and path controls for differing data character.
Related controls that commonly accompany AC-4(21).
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.