PL-13 Planning

Security and Privacy Architectures

High Risk Complex Medium Cost

PL-13 requires describing security and privacy architectures in a manner that guides and constrains design, documenting how architectures integrate, and reviewing/updating them. Security-only designs that ignore minimum necessary, patient rights workflows, and de-identification create HIPAA privacy failures even when firewalls are strong.

Control Objective

Define and maintain integrated security and privacy architectures that constrain how ePHI systems are designed, interconnected, and operated — with periodic review.

Implementation Guidance

  1. Produce architecture views covering both security controls and privacy requirements (use limitation, retention, patient access paths).
  2. Show how identity, consent/authorization, logging, and data minimization interact.
  3. Constrain projects: designs conflicting with architecture require exception.
  4. Integrate with PL-8 security architecture; avoid duplicate conflicting diagrams.
  5. Include BA and cloud shared-responsibility privacy boundaries.
  6. Review annually and after major regulatory or platform changes.
  7. Engage privacy officer as co-owner of PL-13 content.
  8. Use architecture checkpoints in SDLC gates (SA-3).

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Marketing analytics wants full EHR feed

PL-13 privacy architecture requires minimization and purpose limitation; project is redirected to a limited dataset with BA controls.

Patient access API design

Architecture mandates authN, audit, and verification steps aligned to HIPAA individual access before portal expansion.

Conflicting security vs privacy logging

Security wants verbose payloads; privacy limits ePHI in logs. PL-13 resolves with redaction patterns and retention rules.

Best Practices

  • Dual security/privacy architecture ownership.
  • Design constraints enforced in projects.
  • Minimization and retention views.
  • BA boundary clarity.
  • Annual review.
  • SDLC checkpoint use.

Common Gaps & Violations

  • Security architecture with no privacy content.
  • Privacy policy disconnected from technical design.
  • Exceptions granted silently.
  • Logging ePHI without retention limits.
  • Cloud data residency ignored.

Required Documentation

  • Security and privacy architecture documentation (PL-13)
  • Design constraint checklist for projects
  • Review records
  • Exception log
  • Integration references to PL-8/PL-2

How to Test & Validate

  1. Verify privacy content exists in architecture artifacts.
  2. Sample a project for architecture checkpoint evidence.
  3. Confirm privacy officer co-ownership.
  4. Review exception handling.
  5. Compare BA data flows to architecture.

Audit Considerations

OCR looks for privacy integrated into operations, not only Notice of Privacy Practices. PL-13 shows design-level integration with security.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.530(c) Safeguards — administrative, technical, physical safeguards for PHI.
  • 164.502 Uses and disclosures — architecture should enforce permitted uses/minimum necessary.
  • 164.312 Technical safeguards — security architecture implements technical privacy protections.
  • 164.316 Policies and procedures — document how privacy/security designs are maintained.

Compliance Tips

  • Require joint security/privacy sign-off on architecture updates.
  • Add minimization questions to every interface design review.
  • Keep a pattern library for safe logging of clinical events.

Frequently Asked Questions

How does PL-13 differ from PL-8?

PL-8 focuses on information security architecture; PL-13 explicitly addresses security and privacy architectures and their integration.

Is a privacy impact assessment enough?

PIAs inform architecture but do not replace documented architecture constraints and reviews.

Does PL-13 apply to pure paper PHI?

Focus is system architectures; paper workflows still need privacy safeguards under HIPAA administrative requirements.

References & Resources

  • NIST SP 800-53 Rev. 5 — PL-13
  • Related controls: PL-8, PL-2, SA-8, AC-4, SI-12

Need Help Implementing PL-13?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.