AC-4(22) Access Control

Access Only

Medium Risk Moderate Low Cost

AC-4(22) requires access only as an enhancement to base AC-4 information flow enforcement. Base AC-4 establishes that flows must be authorized; this enhancement adds: Provide access-only paths where users may view ePHI without download/export/print capabilities that would create uncontrolled secondary flows. Healthcare delivery organizations rely on this to keep ePHI within approved clinical, billing, and research pathways.

Control Objective

Provide access-only mechanisms so authorized viewers can use ePHI without enabling unauthorized onward transfer.

Implementation Guidance

  1. Identify roles needing access-only (auditors, some VIP viewers, external reviewers).
  2. Disable download/print/export/clipboard where required.
  3. Prefer VDI/Citrix access-only with USB redirect off.
  4. Keep clinical users on appropriate editable access under least privilege.
  5. Log access-only session activity.
  6. Review access-only exceptions.
  7. Test that export APIs are denied.
  8. Train support not to 'enable copy' casually.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

View-only VIP chart

Risk management may view VIP chart in a view-only pane — download, print, and export disabled.

External auditor access-only

Assessor reviews sample ePHI in a Citrix access-only session with clipboard and USB redirection off.

Referring MD portal

Community physician portal allows view of shared CCD sections without bulk export APIs.

Best Practices

  • Tie AC-4(22) to named owners in IAM/privacy/security.
  • Prefer system enforcement over informal email approval.
  • Measure coverage on systems that store or transmit ePHI.
  • Review exceptions at least quarterly.
  • Correlate events into SIEM use cases.
  • Document mapping to HIPAA safeguards in the SSP.

Common Gaps & Violations

  • Policy claims access only but no technical enforcement on EHR paths.
  • Exceptions granted permanently without review.
  • Vendors and research feeds left out of scope.
  • Logs not retained or not reviewed.
  • Upgrades silently disable the control.

Required Documentation

  • Policy/procedure for Access Only (AC-4(22))
  • Configuration baselines and diagrams
  • Exception register
  • Sample logs/alerts
  • Training or runbook evidence

How to Test & Validate

  1. Attempt a prohibited action related to access only; confirm block or required workflow.
  2. Complete an authorized path; confirm success and logging.
  3. Sample exceptions for expiry and approval.
  4. Verify ePHI systems in scope are covered (not only corporate IT).
  5. Confirm SIEM/alert or retention evidence for the last 90 days.

Audit Considerations

Assessors look for operating evidence of Access Only on systems touching ePHI — screenshots, logs, and failed-test results — not only a policy paragraph referencing AC-4(22).

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.312(a)(1) Access Control — limit system access and, by extension, unauthorized information movement.
  • 164.312(e)(1) Transmission Security — guard ePHI transmitted over networks and interconnections.
  • 164.308(a)(4) Information Access Management — policies for access and disclosure pathways.
  • 164.530(c) Safeguards / 164.514 Minimum Necessary — reduce unnecessary data in flows.

Compliance Tips

  • List AC-4(22) explicitly in the system security plan control matrix.
  • Prioritize EHR, VPN, HIE, and BA file-transfer paths.
  • Keep a one-page evidence pack (config + sample log + exception list) ready for assessors.

Frequently Asked Questions

Is view-only a real control?

Yes when download/print/export/clipboard are technically disabled — not honor-system.

Breaks clinical work?

Use for high-risk viewers (auditors, some VIP access); clinicians keep needed capabilities under AC-3/AC-6.

VDI helpful?

Access-only VDI with USB/clipboard controls is a common pattern.

References & Resources

  • NIST SP 800-53 Rev. 5 — AC-4(22)
  • Related controls: AC-4, AC-3, AC-6

Need Help Implementing AC-4(22)?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.