MRN in filename stopped
User tries to SFTP `Smith_MRN12345_labs.csv`; metadata/filename policy quarantines the transfer.
AC-4(6) requires metadata as an enhancement to base AC-4 information flow enforcement. Base AC-4 establishes that flows must be authorized; this enhancement adds: Use and protect metadata (MRN in filenames, DICOM headers, FHIR meta, document properties) as part of flow decisions; stop unsafe metadata leakage. Healthcare delivery organizations rely on this to keep ePHI within approved clinical, billing, and research pathways.
Enforce information flow control based on metadata associated with ePHI and prevent unauthorized metadata disclosure.
How this control shows up in healthcare and HIPAA-covered environments.
User tries to SFTP `Smith_MRN12345_labs.csv`; metadata/filename policy quarantines the transfer.
Teaching-file export strips patient-name headers before leaving radiology; raw headers blocked on external share.
API client omits required confidentiality meta tags; gateway rejects the Bundle for cross-org share.
Assessors look for operating evidence of Metadata on systems touching ePHI — screenshots, logs, and failed-test results — not only a policy paragraph referencing AC-4(6).
How this NIST control supports HIPAA Security Rule expectations.
Filenames help, but also DICOM/FHIR/document properties used in routing decisions.
Yes — MRNs in headers/filenames are ePHI and must be protected in flows.
Assign data stewards for clinical message metadata with interface engineering.
Related controls that commonly accompany AC-4(6).
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.