PL-12 Planning

Baseline Updates

Medium Risk Moderate Low Cost

PL-12 (Baseline Updates / related planning update practices in Rev 5 planning family usage) requires updating control baselines and related planning when directed by assessments, threat changes, or mission changes. In healthcare enrichment practice this control is applied as keeping selected/tailored baselines and POA&M-driven updates current for ePHI systems.

Control Objective

Update security/privacy baselines and implementation plans when assessments, incidents, or environment changes show that current ePHI controls are insufficient — track remediations to closure.

Implementation Guidance

  1. Feed CA assessment findings, pen tests, and incidents into baseline/control update decisions.
  2. Maintain POA&M or equivalent remediation register with owners and dates.
  3. Update tailored baselines when new threat patterns hit healthcare (e.g., ransomware against EHRs).
  4. Re-approve significant baseline changes through governance.
  5. Communicate updates to system owners and BA partners as needed.
  6. Verify compensatory controls remain valid after updates.
  7. Align with PL-2 plan updates and CM changes.
  8. Report aging remediation items to leadership.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Ransomware lessons learned

After a peer hospital incident, PL-12 updates add stricter remote access and backup immutability expectations to the EHR baseline.

Audit finding on inactive accounts

POA&M item drives baseline parameter change for account review frequency; PL-12 tracks completion.

Telehealth surge

Expanded virtual care changes risk; baseline updates add endpoint and session controls for ePHI video workflows.

Best Practices

  • Assessment-driven baseline updates.
  • Living POA&M with SLAs.
  • Leadership visibility on aging items.
  • Governance for significant changes.
  • Sync to system plans.
  • Validate compensations after change.

Common Gaps & Violations

  • Findings closed on paper without baseline change.
  • Threat intel never reaches control owners.
  • POA&M without due dates.
  • Updates not communicated to clinics.
  • Stale baselines after cloud migration.

Required Documentation

  • Baseline update / POA&M procedure (PL-12)
  • Remediation register
  • Baseline change approvals
  • Communication records
  • Evidence of completed updates

How to Test & Validate

  1. Sample closed assessment findings for resulting baseline/plan updates.
  2. Review POA&M aging report.
  3. Verify a threat-driven control enhancement was documented.
  4. Confirm system owners received update notice.
  5. Check PL-2 plan reflects baseline changes.

Audit Considerations

Living baselines distinguish programs that learn from those that shelf reports. Assessors look for POA&M discipline tied to real control changes.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.308(a)(1) Risk Management — implement security measures to reduce risks to reasonable levels; update as risks change.
  • 164.308(a)(8) Evaluation — evaluation findings should drive safeguard updates.
  • 164.316 Policies and procedures — update documentation when practices change.
  • 164.306 General rules — maintain reasonable safeguards over time.

Compliance Tips

  • Tie every High finding to a PL-12 tracked action.
  • Review ransomware and BA breach reports quarterly for baseline impacts.
  • Expire ancient risk acceptances deliberately.

Frequently Asked Questions

Is PL-12 only federal POA&M?

Use equivalent remediation tracking even in commercial healthcare — the intent is controlled baseline/plan updates from deficiencies and change.

How fast must baselines update after an incident?

Prioritize by risk; document interim compensations if permanent baseline change takes longer.

Who owns PL-12?

Security governance with system owner accountability for implementing updates.

References & Resources

  • NIST SP 800-53 Rev. 5 — PL-12
  • Related controls: CA-5, PL-2, RA-3, PL-11

Need Help Implementing PL-12?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.