AC-4(6) Access Control

Metadata

High Risk Moderate Medium Cost

AC-4(6) requires metadata as an enhancement to base AC-4 information flow enforcement. Base AC-4 establishes that flows must be authorized; this enhancement adds: Use and protect metadata (MRN in filenames, DICOM headers, FHIR meta, document properties) as part of flow decisions; stop unsafe metadata leakage. Healthcare delivery organizations rely on this to keep ePHI within approved clinical, billing, and research pathways.

Control Objective

Enforce information flow control based on metadata associated with ePHI and prevent unauthorized metadata disclosure.

Implementation Guidance

  1. Inventory metadata used in routing (filenames, DICOM headers, FHIR meta).
  2. Include metadata checks in DLP/flow gates.
  3. Prevent leakage of identifiers via filenames on external shares.
  4. Normalize required meta tags for cross-org FHIR exchange.
  5. Protect metadata stores from unauthorized edit.
  6. Alert on missing/invalid metadata at egress.
  7. Document metadata standards with interface owners.
  8. Retest after imaging/EHR upgrades.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

MRN in filename stopped

User tries to SFTP `Smith_MRN12345_labs.csv`; metadata/filename policy quarantines the transfer.

DICOM header exposure

Teaching-file export strips patient-name headers before leaving radiology; raw headers blocked on external share.

FHIR meta.tag misuse

API client omits required confidentiality meta tags; gateway rejects the Bundle for cross-org share.

Best Practices

  • Tie AC-4(6) to named owners in IAM/privacy/security.
  • Prefer system enforcement over informal email approval.
  • Measure coverage on systems that store or transmit ePHI.
  • Review exceptions at least quarterly.
  • Correlate events into SIEM use cases.
  • Document mapping to HIPAA safeguards in the SSP.

Common Gaps & Violations

  • Policy claims metadata but no technical enforcement on EHR paths.
  • Exceptions granted permanently without review.
  • Vendors and research feeds left out of scope.
  • Logs not retained or not reviewed.
  • Upgrades silently disable the control.

Required Documentation

  • Policy/procedure for Metadata (AC-4(6))
  • Configuration baselines and diagrams
  • Exception register
  • Sample logs/alerts
  • Training or runbook evidence

How to Test & Validate

  1. Attempt a prohibited action related to metadata; confirm block or required workflow.
  2. Complete an authorized path; confirm success and logging.
  3. Sample exceptions for expiry and approval.
  4. Verify ePHI systems in scope are covered (not only corporate IT).
  5. Confirm SIEM/alert or retention evidence for the last 90 days.

Audit Considerations

Assessors look for operating evidence of Metadata on systems touching ePHI — screenshots, logs, and failed-test results — not only a policy paragraph referencing AC-4(6).

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.312(a)(1) Access Control — limit system access and, by extension, unauthorized information movement.
  • 164.312(e)(1) Transmission Security — guard ePHI transmitted over networks and interconnections.
  • 164.308(a)(4) Information Access Management — policies for access and disclosure pathways.
  • 164.530(c) Safeguards / 164.514 Minimum Necessary — reduce unnecessary data in flows.

Compliance Tips

  • List AC-4(6) explicitly in the system security plan control matrix.
  • Prioritize EHR, VPN, HIE, and BA file-transfer paths.
  • Keep a one-page evidence pack (config + sample log + exception list) ready for assessors.

Frequently Asked Questions

Is filename policy enough?

Filenames help, but also DICOM/FHIR/document properties used in routing decisions.

Can metadata itself be ePHI?

Yes — MRNs in headers/filenames are ePHI and must be protected in flows.

Who owns metadata standards?

Assign data stewards for clinical message metadata with interface engineering.

References & Resources

  • NIST SP 800-53 Rev. 5 — AC-4(6)
  • Related controls: AC-4, AC-4(1), AC-16, SI-12

Need Help Implementing AC-4(6)?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.