Patient portal categorized too low
Portal exposes clinical summaries but was treated as Low. PL-10 re-selection raises baseline expectations for authN and audit.
PL-10 requires selecting a control baseline for the system. Healthcare organizations mapping to NIST should select baselines (or equivalent tailored sets) that match system impact — under-selecting for EHR platforms leaves predictable HIPAA gaps.
Select an appropriate security and privacy control baseline for each ePHI system based on impact analysis so subsequent tailoring and implementation have a sound starting point.
How this control shows up in healthcare and HIPAA-covered environments.
Portal exposes clinical summaries but was treated as Low. PL-10 re-selection raises baseline expectations for authN and audit.
Identifiable genomic ePHI increases impact. Baseline selection is revisited before go-live.
Organization selects baseline controls it must implement vs inherit from the BA and documents the split.
Baseline selection sets the ceiling for later assessor expectations. Undocumented or obviously wrong selections undermine the entire control program narrative.
How this NIST control supports HIPAA Security Rule expectations.
HIPAA is regulation; PL-10 is about selecting a control baseline (often NIST). Many orgs select NIST and map HIPAA — document your approach.
Enterprise overlays help, but system impact differences still matter for EHR vs low-impact utilities.
Typically authorizing official / security governance defined in your program policy.
Related controls that commonly accompany PL-10.
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.