PL-11 Planning

Baseline Tailoring

High Risk Complex Low Cost

PL-11 requires tailoring selected control baselines by applying defined tailoring actions (scoping, selecting/ compensating, assigning parameters). Blindly applying every control identically to infusion pumps and EHR databases fails; undocumented tailoring also fails audits.

Control Objective

Tailor control baselines to the clinical and technical reality of each ePHI system using documented scoping, parameter assignment, and compensating controls — without silently dropping HIPAA-necessary safeguards.

Implementation Guidance

  1. Start from the PL-10 selected baseline.
  2. Scope out controls that cannot apply with rationale (e.g., certain PE controls for pure SaaS).
  3. Assign organization parameters (frequencies, roles, thresholds) explicitly.
  4. Select compensating controls when baseline controls are infeasible for medical devices.
  5. Record tailoring in control implementation statements / SSP.
  6. Privacy officer reviews tailoring that affects PHI minimum necessary or patient rights.
  7. Re-tailor when architecture changes.
  8. Forbid informal we skip that without risk acceptance.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Legacy modality cannot support MFA agent

PL-11 documents compensating segmentation, unique device auth, and monitored jump host instead of endpoint agent MFA.

SaaS EHR parameter assignment

Audit retention and session timeout parameters assigned to match HIPAA documentation needs and clinical workflow.

Over-scoping removed controls

Prior team scoped out AU controls for a billing warehouse. Tailoring review restores audit expectations for ePHI extracts.

Best Practices

  • Document every tailoring action.
  • Compensating controls for clinical constraints.
  • Explicit parameter values.
  • Privacy review on PHI-impacting tailoring.
  • Tie to risk acceptance when weakening.
  • Update on system change.

Common Gaps & Violations

  • Silent omissions with no rationale.
  • Copy-paste tailoring across unlike systems.
  • Compensating controls not implemented.
  • Parameters left as organization-defined blank.
  • Scoping out controls still needed for HIPAA.

Required Documentation

  • Baseline tailoring procedure (PL-11)
  • Tailoring decision records per system
  • Compensating control descriptions
  • Parameter assignment tables
  • Risk acceptance linkage

How to Test & Validate

  1. Review tailoring record for a major ePHI system.
  2. Verify scoped-out controls have rationale.
  3. Confirm compensating controls exist in production.
  4. Check parameters are populated (not TBD).
  5. Sample privacy review on a PHI-related tailoring.

Audit Considerations

Assessors accept risk-based tailoring — not invisible gaps. Clear PL-11 records distinguish mature programs from checkbox failures.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.306 Flexibility of approach — tailor safeguards to size, complexity, and capabilities while meeting addressable/required rules.
  • 164.308(a)(1) Risk Management — tailoring decisions are risk treatments.
  • 164.316 Documentation — document policies, procedures, and rationale.
  • 164.312 Technical safeguards — parameter choices (timeouts, encryption) implement addressable specifications.

Compliance Tips

  • Use a tailoring worksheet with HIPAA mapping columns.
  • Never scope out audit or access control for systems storing ePHI without strong compensation.
  • Keep device compensating controls owned by clinical engineering.

Frequently Asked Questions

Can we tailor away encryption?

Addressable HIPAA encryption still requires a documented equivalent or rationale; treat weakening as formal risk acceptance, not casual scoping.

Who performs PL-11?

Security architecture/governance with system owner and privacy input.

How does PL-11 relate to overlays?

Overlays are a form of predefined tailoring; still document application to each system.

References & Resources

  • NIST SP 800-53 Rev. 5 — PL-11
  • Related controls: PL-10, PL-2, RA-3, CM-6

Need Help Implementing PL-11?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.