PL-2 Planning

System Security Plan

Medium Risk Moderate Low Cost

PL-2 requires developing system security and privacy plans that define the system boundary, operational environment, relationships/connections, security/privacy requirements, and how controls are implemented; distributing plans to authorized personnel; reviewing plans on a defined frequency; updating them to address changes/problems; and protecting plans from unauthorized disclosure. For healthcare, the SSP (and privacy plan elements) is the living blueprint assessors expect for each major ePHI system.

Control Objective

Maintain accurate, reviewed security and privacy plans for systems that create, receive, maintain, or transmit ePHI so control implementation, ownership, and boundaries are clear and current.

Implementation Guidance

  1. Identify in-scope systems (EHR, HIE gateway, imaging, revenue cycle, identity, backups) and owners.
  2. Document boundary diagrams including cloud SaaS, interfaces, and BAs that process ePHI.
  3. Map implemented controls (or HIPAA safeguard equivalents) to components — note inherited vs hybrid vs system-specific.
  4. Record environment assumptions, data types (ePHI elements), users, and key contacts.
  5. Distribute plans to system owners, security, privacy, and operations — not only store in a binder.
  6. Review at least annually and after major changes (go-lives, cloud migrations, new HIE).
  7. Protect plans: they reveal architecture useful to attackers; limit distribution and mark sensitive.
  8. Coordinate PL-2 with CA-3 interconnections, CM-8 inventory, and RA-3 risk assessment outputs.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Cloud EHR migration

On-prem SSP still shows local data centers. PL-2 update redraws the boundary around the SaaS tenant, IdP federation, and BA subprocessors before authorization to operate is reaffirmed.

New radiology AI adjunct

A vendor model receives de-identified — then later limited — datasets. Privacy plan sections update data flows, BA status, and monitoring ownership under PL-2.

Audit asks for the EHR control narrative

Assessors request how audit controls and access management are implemented. The PL-2 plan plus inheritance tables answer without scrambling through tribal knowledge.

Best Practices

  • One plan (or modular plan set) per major system of record.
  • Keep diagrams synchronized with interconnection registers.
  • Annual review with change-triggered updates.
  • Explicit privacy content for ePHI processing.
  • Controlled distribution and version history.
  • Link to evidence repositories (policies, configs).

Common Gaps & Violations

  • SSP written once for Meaningful Use and never updated.
  • Cloud and BA components missing from boundary.
  • Plans exist but system owners have never seen them.
  • No privacy considerations — only generic security boilerplate.
  • Architecture details posted on open SharePoint.

Required Documentation

  • System security and privacy plan template
  • Current plans for major ePHI systems
  • Boundary / data-flow diagrams
  • Review and approval records
  • Distribution and access-control evidence for plans

How to Test & Validate

  1. Select a major ePHI system; verify a current PL-2 plan exists.
  2. Compare plan boundary to live interfaces (CA-3/CM-8).
  3. Confirm last review date meets policy.
  4. Interview owner: can they locate their plan?
  5. Check plan repository permissions are restricted.

Audit Considerations

HIPAA evaluations and NIST-based assessments both look for system-level descriptions of safeguards. Stale plans that ignore cloud EHR reality undermine the entire control narrative.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.316 Policies and procedures — implement reasonable and appropriate policies and procedures; PL-2 documents how they apply to a system.
  • 164.308(a)(1) Security Management Process — risk analysis/management outputs should be reflected in system plans.
  • 164.308(a)(8) Evaluation — periodic technical and nontechnical evaluation benefits from current system plans.
  • 164.530(c) Safeguards — privacy safeguard expectations belong in privacy plan content for ePHI systems.

Compliance Tips

  • Trigger PL-2 updates from the same change board that approves EHR major releases.
  • Use a short executive summary plus detailed annexes so leaders actually read ownership sections.
  • Cross-link BAA inventory inside the boundary appendix.

Frequently Asked Questions

Do we need a separate SSP for every clinic workstation?

No. Plan at the system/enclave level (e.g., EHR ecosystem, clinic endpoint estate) with components listed — not one binder per laptop.

Is a HIPAA risk analysis enough for PL-2?

Risk analysis feeds the plan; PL-2 still needs boundary, control implementation, and operational descriptions.

Who approves the plan?

Typically the system owner and authorizing official / security leadership defined in your governance model.

References & Resources

  • NIST SP 800-53 Rev. 5 — PL-2
  • NIST SP 800-18 Guide for Developing Security Plans
  • Related controls: CA-3, CM-8, RA-3, SA-5, PM-9

Need Help Implementing PL-2?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.