CM-13 Configuration Management

Data Action Mapping

Medium Risk Moderate Low Cost

CM-13 develops and documents a map of system data actions for personally identifiable / sensitive information. For HIPAA entities, mapping create/read/update/disclose/dispose actions across EHR, interfaces, analytics, and BA paths clarifies Privacy Rule and Security Rule accountability.

Control Objective

Maintain a current map of data actions affecting ePHI (and related PII) across systems, interfaces, and organizations.

Implementation Guidance

  1. Inventory systems that create, receive, maintain, or transmit ePHI.
  2. Document actions: collect, use, access, disclose, retain, dispose for key flows.
  3. Include HL7/FHIR, claims, patient portal, research extracts, and BA paths.
  4. Tie actions to lawful/purpose bases and minimum necessary notes.
  5. Update maps after major interface or SaaS changes.
  6. Use maps in RA-3 and DPIA-like reviews.
  7. Align with SI-12 information management.
  8. Store maps where privacy and security both can maintain them.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

New telehealth vendor onboarding

CM-13 map shows recording storage, BA access, and retention before go-live—blocking an unmapped cloud archive.

Minimum necessary redesign

Mapping reveals registration sending full clinical notes to a scheduling BA; action map drives field reduction.

Ransomware impact analysis

Data action map lists downstream consumers of ADT feeds so IR knows which partners to notify and isolate.

Best Practices

  • Keep living data-action diagrams.
  • Cover BA and interface actions.
  • Link to privacy purposes.
  • Update on change tickets.
  • Use in risk assessments.
  • Avoid one-time consultant binders that rot.

Common Gaps & Violations

  • Network diagram only, no data actions.
  • Missing BA processing steps.
  • Maps years out of date.
  • Ignoring analytics derivatives of ePHI.
  • Privacy and security maintaining conflicting maps.

Required Documentation

  • Data action mapping standard (CM-13)
  • Current ePHI data-action maps
  • Change-triggered update procedure
  • BA coverage checklist
  • Linkage to RA/privacy reviews

How to Test & Validate

  1. Pick a patient-registration flow; walk the map vs reality.
  2. Confirm last update date after a known interface change.
  3. Verify BA actions appear.
  4. Use map in a sample risk review artifact.
  5. Check disposal actions are documented.

Audit Considerations

CM-13 evidence is usable maps that match production flows—not decorative posters.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.308(a)(1) Risk Analysis — understanding data actions is foundational.
  • 164.514 Minimum Necessary — maps reveal over-disclosure.
  • 164.308(a)(4) Access Management — actions inform who needs access.
  • 164.530 Policies — privacy policies should reflect actual processing.

Compliance Tips

  • Maintain maps in the same repo/tool as interface inventory.
  • Require CM-13 update as a CAB checkbox for ePHI flows.
  • Reuse for BA inventory and RoPA-like needs.

Frequently Asked Questions

Is CM-13 only for federal PII programs?

The control is PII-oriented; healthcare should map ePHI/PII actions as the sensitive information of concern.

How related to CM-12?

CM-12 focuses on location; CM-13 focuses on actions performed on the data.

Do we need every button in the EHR?

Map significant processing and disclosure paths first; deepen where risk is high.

References & Resources

  • NIST SP 800-53 Rev. 5 — CM-13
  • Related controls: CM-4, CM-8, SI-12, RA-3

Need Help Implementing CM-13?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.