View-only VIP chart
Risk management may view VIP chart in a view-only pane — download, print, and export disabled.
AC-4(22) requires access only as an enhancement to base AC-4 information flow enforcement. Base AC-4 establishes that flows must be authorized; this enhancement adds: Provide access-only paths where users may view ePHI without download/export/print capabilities that would create uncontrolled secondary flows. Healthcare delivery organizations rely on this to keep ePHI within approved clinical, billing, and research pathways.
Provide access-only mechanisms so authorized viewers can use ePHI without enabling unauthorized onward transfer.
How this control shows up in healthcare and HIPAA-covered environments.
Risk management may view VIP chart in a view-only pane — download, print, and export disabled.
Assessor reviews sample ePHI in a Citrix access-only session with clipboard and USB redirection off.
Community physician portal allows view of shared CCD sections without bulk export APIs.
Assessors look for operating evidence of Access Only on systems touching ePHI — screenshots, logs, and failed-test results — not only a policy paragraph referencing AC-4(22).
How this NIST control supports HIPAA Security Rule expectations.
Yes when download/print/export/clipboard are technically disabled — not honor-system.
Use for high-risk viewers (auditors, some VIP access); clinicians keep needed capabilities under AC-3/AC-6.
Access-only VDI with USB/clipboard controls is a common pattern.
Related controls that commonly accompany AC-4(22).
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.