Marketing analytics wants full EHR feed
PL-13 privacy architecture requires minimization and purpose limitation; project is redirected to a limited dataset with BA controls.
PL-13 requires describing security and privacy architectures in a manner that guides and constrains design, documenting how architectures integrate, and reviewing/updating them. Security-only designs that ignore minimum necessary, patient rights workflows, and de-identification create HIPAA privacy failures even when firewalls are strong.
Define and maintain integrated security and privacy architectures that constrain how ePHI systems are designed, interconnected, and operated — with periodic review.
How this control shows up in healthcare and HIPAA-covered environments.
PL-13 privacy architecture requires minimization and purpose limitation; project is redirected to a limited dataset with BA controls.
Architecture mandates authN, audit, and verification steps aligned to HIPAA individual access before portal expansion.
Security wants verbose payloads; privacy limits ePHI in logs. PL-13 resolves with redaction patterns and retention rules.
OCR looks for privacy integrated into operations, not only Notice of Privacy Practices. PL-13 shows design-level integration with security.
How this NIST control supports HIPAA Security Rule expectations.
PL-8 focuses on information security architecture; PL-13 explicitly addresses security and privacy architectures and their integration.
PIAs inform architecture but do not replace documented architecture constraints and reviews.
Focus is system architectures; paper workflows still need privacy safeguards under HIPAA administrative requirements.
Related controls that commonly accompany PL-13.
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.