Macro-enabled discharge census
Case manager emails an .xlsm with macros and a discharge list. Gateway quarantine catches the embedded type before it leaves.
AC-4(5) requires embedded data types as an enhancement to base AC-4 information flow enforcement. Base AC-4 establishes that flows must be authorized; this enhancement adds: Inspect nested/embedded types (macros, OLE, private DICOM tags, nested ZIPs) so hidden ePHI cannot bypass simple extension filters. Healthcare delivery organizations rely on this to keep ePHI within approved clinical, billing, and research pathways.
Control flows based on embedded data types that may conceal or carry ePHI inside documents, images, or messages.
How this control shows up in healthcare and HIPAA-covered environments.
Case manager emails an .xlsm with macros and a discharge list. Gateway quarantine catches the embedded type before it leaves.
Export to an outside researcher includes private tags with MRNs. Filter blocks or scrubs before media leave.
Vendor upload nests PHI CSVs inside nested archives; inspection unpacks and applies DLP before accept.
Assessors look for operating evidence of Embedded Data Types on systems touching ePHI — screenshots, logs, and failed-test results — not only a policy paragraph referencing AC-4(5).
How this NIST control supports HIPAA Security Rule expectations.
Stego is in scope, but so are macros, nested archives, and encapsulated clinical payloads.
Risk-base which channels get deep inspection; human egress usually first.
Yes — Binary/DocumentReference payloads should meet the same embedded-type policy.
Related controls that commonly accompany AC-4(5).
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.