New telehealth platform go-live
Project wants weekend cutover. CA-6 gate holds until AO reviews BAA, encryption, and residual risk; conditional ATO issued with 60-day MFA milestone.
CA-6 requires assigning a senior official as the authorizing official for the system, ensuring the official authorizes the system for operation before commencement, and updating the authorization when required. In healthcare terms, someone accountable must accept residual risk for EHR, imaging, patient portals, and BA platforms — go-live is not only a project decision, it is a security authorization decision.
Ensure a designated authorizing official formally accepts residual risk and authorizes operation of ePHI systems before production use and when significant changes occur.
How this control shows up in healthcare and HIPAA-covered environments.
Project wants weekend cutover. CA-6 gate holds until AO reviews BAA, encryption, and residual risk; conditional ATO issued with 60-day MFA milestone.
Re-authorization is triggered by architecture change; AO accepts residual risk only after SC-8/SC-28 evidence and updated diagrams.
Security finds it in use without CA-6; access is suspended until authorization package and BAA are completed.
Lack of formal risk acceptance for systems holding ePHI undermines the risk-management story. Assessors expect named accountability, not informal go-lives.
How this NIST control supports HIPAA Security Rule expectations.
The control language comes from RMF, but the practice — formal residual risk acceptance before operating ePHI systems — is valuable and mappable for healthcare.
A senior official with authority to accept risk for the organization; often CIO/CISO or a documented delegate — not the project manager alone.
CA-6 may authorize with conditions; those conditions become POA&M items under CA-5.
Related controls that commonly accompany CA-6.
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.