Shared password culture
Rules of behavior explicitly ban credential sharing; repeated violations feed sanctions — supporting AC-2/IA-2 enforcement culturally.
PL-4 requires establishing and providing to individuals requiring access a set of rules describing responsibilities and expected behavior for information and system usage, receiving documented acknowledgment before authorizing access, updating rules frequently, and including social media and related restrictions where defined. Rules of behavior make acceptable use enforceable for people who touch ePHI.
Give every user clear, acknowledged rules for how they may use systems and data — including ePHI — before access is granted and whenever rules materially change.
How this control shows up in healthcare and HIPAA-covered environments.
Rules of behavior explicitly ban credential sharing; repeated violations feed sanctions — supporting AC-2/IA-2 enforcement culturally.
Staff post identifiable patient info. PL-4 rules + AC-22 processes support investigation and corrective action.
Updated rules add home-office ePHI expectations; LMS forces re-acknowledgment before continued remote EHR use.
Assessors sample acknowledgment records. Missing or outdated AUP acknowledgments weaken workforce security narratives.
How this NIST control supports HIPAA Security Rule expectations.
Only if it includes system/ePHI behavior rules and you capture documented acknowledgment tied to access authorization.
At least when rules are updated; many orgs also require annual re-ack.
AC-8 is the system use notification at logon; PL-4 is the broader acknowledged ruleset for behavior.
Related controls that commonly accompany PL-4.
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.