AC-4(5) Access Control

Embedded Data Types

High Risk Complex Medium Cost

AC-4(5) requires embedded data types as an enhancement to base AC-4 information flow enforcement. Base AC-4 establishes that flows must be authorized; this enhancement adds: Inspect nested/embedded types (macros, OLE, private DICOM tags, nested ZIPs) so hidden ePHI cannot bypass simple extension filters. Healthcare delivery organizations rely on this to keep ePHI within approved clinical, billing, and research pathways.

Control Objective

Control flows based on embedded data types that may conceal or carry ePHI inside documents, images, or messages.

Implementation Guidance

  1. List high-risk embeddings (macros, OLE, private DICOM tags, nested ZIP).
  2. Deploy inspection that unpacks common containers at egress.
  3. Block/quarantine disallowed embedded types on clinical email/MFT.
  4. Scrub unexpected private tags on outbound imaging.
  5. Train HIM/research that renaming files does not hide PHI.
  6. Log embedded-type detections.
  7. Update parsers when new clinical formats appear.
  8. Pair with malware controls for macro-borne exfil.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Macro-enabled discharge census

Case manager emails an .xlsm with macros and a discharge list. Gateway quarantine catches the embedded type before it leaves.

DICOM private tag leak

Export to an outside researcher includes private tags with MRNs. Filter blocks or scrubs before media leave.

Nested ZIP on vendor SFTP

Vendor upload nests PHI CSVs inside nested archives; inspection unpacks and applies DLP before accept.

Best Practices

  • Tie AC-4(5) to named owners in IAM/privacy/security.
  • Prefer system enforcement over informal email approval.
  • Measure coverage on systems that store or transmit ePHI.
  • Review exceptions at least quarterly.
  • Correlate events into SIEM use cases.
  • Document mapping to HIPAA safeguards in the SSP.

Common Gaps & Violations

  • Policy claims embedded data types but no technical enforcement on EHR paths.
  • Exceptions granted permanently without review.
  • Vendors and research feeds left out of scope.
  • Logs not retained or not reviewed.
  • Upgrades silently disable the control.

Required Documentation

  • Policy/procedure for Embedded Data Types (AC-4(5))
  • Configuration baselines and diagrams
  • Exception register
  • Sample logs/alerts
  • Training or runbook evidence

How to Test & Validate

  1. Attempt a prohibited action related to embedded data types; confirm block or required workflow.
  2. Complete an authorized path; confirm success and logging.
  3. Sample exceptions for expiry and approval.
  4. Verify ePHI systems in scope are covered (not only corporate IT).
  5. Confirm SIEM/alert or retention evidence for the last 90 days.

Audit Considerations

Assessors look for operating evidence of Embedded Data Types on systems touching ePHI — screenshots, logs, and failed-test results — not only a policy paragraph referencing AC-4(5).

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.312(a)(1) Access Control — limit system access and, by extension, unauthorized information movement.
  • 164.312(e)(1) Transmission Security — guard ePHI transmitted over networks and interconnections.
  • 164.308(a)(4) Information Access Management — policies for access and disclosure pathways.
  • 164.530(c) Safeguards / 164.514 Minimum Necessary — reduce unnecessary data in flows.

Compliance Tips

  • List AC-4(5) explicitly in the system security plan control matrix.
  • Prioritize EHR, VPN, HIE, and BA file-transfer paths.
  • Keep a one-page evidence pack (config + sample log + exception list) ready for assessors.

Frequently Asked Questions

Is this only steganography?

Stego is in scope, but so are macros, nested archives, and encapsulated clinical payloads.

Will unpacking slow interfaces?

Risk-base which channels get deep inspection; human egress usually first.

Are FHIR attachments in scope?

Yes — Binary/DocumentReference payloads should meet the same embedded-type policy.

References & Resources

  • NIST SP 800-53 Rev. 5 — AC-4(5)
  • Related controls: AC-4, SI-3, SI-4, MP-6

Need Help Implementing AC-4(5)?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.