New telehealth vendor onboarding
CM-13 map shows recording storage, BA access, and retention before go-live—blocking an unmapped cloud archive.
CM-13 develops and documents a map of system data actions for personally identifiable / sensitive information. For HIPAA entities, mapping create/read/update/disclose/dispose actions across EHR, interfaces, analytics, and BA paths clarifies Privacy Rule and Security Rule accountability.
Maintain a current map of data actions affecting ePHI (and related PII) across systems, interfaces, and organizations.
How this control shows up in healthcare and HIPAA-covered environments.
CM-13 map shows recording storage, BA access, and retention before go-live—blocking an unmapped cloud archive.
Mapping reveals registration sending full clinical notes to a scheduling BA; action map drives field reduction.
Data action map lists downstream consumers of ADT feeds so IR knows which partners to notify and isolate.
CM-13 evidence is usable maps that match production flows—not decorative posters.
How this NIST control supports HIPAA Security Rule expectations.
The control is PII-oriented; healthcare should map ePHI/PII actions as the sensitive information of concern.
CM-12 focuses on location; CM-13 focuses on actions performed on the data.
Map significant processing and disclosure paths first; deepen where risk is high.
Related controls that commonly accompany CM-13.
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.