PL-10 Planning

Baseline Selection

Medium Risk Moderate Low Cost

PL-10 requires selecting a control baseline for the system. Healthcare organizations mapping to NIST should select baselines (or equivalent tailored sets) that match system impact — under-selecting for EHR platforms leaves predictable HIPAA gaps.

Control Objective

Select an appropriate security and privacy control baseline for each ePHI system based on impact analysis so subsequent tailoring and implementation have a sound starting point.

Implementation Guidance

  1. Categorize systems (confidentiality/integrity/availability impact) with ePHI sensitivity in mind.
  2. Select the corresponding NIST baseline or organization-approved equivalent overlay (e.g., HIPAA mapping set).
  3. Document selection rationale and approver.
  4. Feed selection into PL-11 tailoring and PL-2 plans.
  5. Revisit selection when system mission or data types change (e.g., research identifiable data added).
  6. Train system owners that baseline selection is a governance act — not a paperwork afterthought.
  7. Align cloud offerings to inherited baseline responsibilities.
  8. Record selection in the GRC tool of record.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Patient portal categorized too low

Portal exposes clinical summaries but was treated as Low. PL-10 re-selection raises baseline expectations for authN and audit.

New genomics module

Identifiable genomic ePHI increases impact. Baseline selection is revisited before go-live.

BA-hosted billing

Organization selects baseline controls it must implement vs inherit from the BA and documents the split.

Best Practices

  • Impact-driven baseline selection.
  • Documented approval.
  • Link to tailoring (PL-11).
  • Revisit on data/mission change.
  • Cloud inheritance clarity.
  • GRC recording.

Common Gaps & Violations

  • Same baseline checkbox for intranet FAQ and EHR.
  • No documented selection decision.
  • Selection copied from unrelated federal system without healthcare rethink.
  • Never revisited after major expansion.
  • Privacy baseline ignored.

Required Documentation

  • Baseline selection procedure (PL-10)
  • System categorization records
  • Selected baseline per system
  • Approval evidence
  • Linkage to tailoring records

How to Test & Validate

  1. Sample ePHI systems for documented baseline selection.
  2. Compare selection to categorization impact.
  3. Verify approval signatures/dates.
  4. Check a system change triggered re-selection.
  5. Confirm privacy controls considered.

Audit Considerations

Baseline selection sets the ceiling for later assessor expectations. Undocumented or obviously wrong selections undermine the entire control program narrative.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.306 Security standards general rules — select reasonable and appropriate safeguards; baseline selection structures that judgment.
  • 164.308(a)(1) Risk Analysis — impact/categorization informs safeguard selection.
  • 164.316 Policies and procedures — document how control sets are chosen.
  • 164.308(a)(8) Evaluation — evaluation compares implemented controls to selected expectations.

Compliance Tips

  • Pair PL-10 decisions with RA-2/RA-3 outputs in one workflow.
  • Use a short decision template assessors can read.
  • Do not silently adopt a baseline meant for a different data type.

Frequently Asked Questions

Is HIPAA a baseline under PL-10?

HIPAA is regulation; PL-10 is about selecting a control baseline (often NIST). Many orgs select NIST and map HIPAA — document your approach.

Can one baseline cover the whole enterprise?

Enterprise overlays help, but system impact differences still matter for EHR vs low-impact utilities.

Who approves selection?

Typically authorizing official / security governance defined in your program policy.

References & Resources

  • NIST SP 800-53 Rev. 5 — PL-10
  • Related controls: PL-11, RA-2, PL-2, CM-2

Need Help Implementing PL-10?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.