Personal cloud sync blocked
Clinician installs consumer sync client; controls deny the encrypted tunnel from the clinical VLAN so charts cannot silently leave.
AC-4(4) requires flow control of encrypted information as an enhancement to base AC-4 information flow enforcement. Base AC-4 establishes that flows must be authorized; this enhancement adds: Prevent encryption (personal VPN, consumer sync, rogue tunnels) from bypassing DLP/flow controls; allow-list approved encrypted clinical paths. Healthcare delivery organizations rely on this to keep ePHI within approved clinical, billing, and research pathways.
Ensure encrypted information cannot circumvent ePHI information flow-control mechanisms.
How this control shows up in healthcare and HIPAA-covered environments.
Clinician installs consumer sync client; controls deny the encrypted tunnel from the clinical VLAN so charts cannot silently leave.
Only the HIE proxy endpoint is allowed for community exchange; ad-hoc HTTPS posts of CCD files to random URLs are blocked.
Unapproved remote-support tools from EHR servers are denied; support uses PAM-brokered sessions instead.
Assessors look for operating evidence of Flow Control of Encrypted Information on systems touching ePHI — screenshots, logs, and failed-test results — not only a policy paragraph referencing AC-4(4).
How this NIST control supports HIPAA Security Rule expectations.
No. Encryption must not bypass flow control — inspection is one method; allow-listing approved encrypted paths is another.
Possibly — maintain exclusions and test; prefer destination allow-lists where inspection is impractical.
Backup flows should use approved channels and destinations under the same flow policy.
Related controls that commonly accompany AC-4(4).
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.