Legacy modality cannot support MFA agent
PL-11 documents compensating segmentation, unique device auth, and monitored jump host instead of endpoint agent MFA.
PL-11 requires tailoring selected control baselines by applying defined tailoring actions (scoping, selecting/ compensating, assigning parameters). Blindly applying every control identically to infusion pumps and EHR databases fails; undocumented tailoring also fails audits.
Tailor control baselines to the clinical and technical reality of each ePHI system using documented scoping, parameter assignment, and compensating controls — without silently dropping HIPAA-necessary safeguards.
How this control shows up in healthcare and HIPAA-covered environments.
PL-11 documents compensating segmentation, unique device auth, and monitored jump host instead of endpoint agent MFA.
Audit retention and session timeout parameters assigned to match HIPAA documentation needs and clinical workflow.
Prior team scoped out AU controls for a billing warehouse. Tailoring review restores audit expectations for ePHI extracts.
Assessors accept risk-based tailoring — not invisible gaps. Clear PL-11 records distinguish mature programs from checkbox failures.
How this NIST control supports HIPAA Security Rule expectations.
Addressable HIPAA encryption still requires a documented equivalent or rationale; treat weakening as formal risk acceptance, not casual scoping.
Security architecture/governance with system owner and privacy input.
Overlays are a form of predefined tailoring; still document application to each system.
Related controls that commonly accompany PL-11.
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.