Patient self-scheduling widget added to a brochure site
Widget collects DOB and MRN; RA-2 recategorizes the property and pulls it under ePHI controls and a BAA with the widget vendor.
RA-2 requires categorizing the system and information it processes, storing categorization results with the system owner, and ensuring the categorization is reviewed and approved by designated personnel. In healthcare, correctly recognizing High confidentiality for ePHI drives control selection — under-categorizing a patient portal as "low" leads to weak protections and audit failure.
Assign and approve security categories (confidentiality, integrity, availability impact) for systems based on the information types they handle — especially ePHI — and keep categorizations current.
How this control shows up in healthcare and HIPAA-covered environments.
Widget collects DOB and MRN; RA-2 recategorizes the property and pulls it under ePHI controls and a BAA with the widget vendor.
Integrity and availability remain important; confidentiality impact may differ if truly de-identified — category documents the distinction carefully.
Different categories prevent one-size-fits-none security spending and clarify monitoring priority.
Mis-tiered systems explain many control gaps. Assessors expect categories that reflect ePHI harm, not convenience.
How this NIST control supports HIPAA Security Rule expectations.
Risk analysis (RA-3 related practices) assesses risk; RA-2 specifically categorizes systems/information impact to drive consistent baselines.
Use a documented High/Moderate/Low (or equivalent) scheme mapped to your control catalog; FIPS 199 is the common reference model.
At least annually and on significant change — document the cadence.
Related controls that commonly accompany RA-2.
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.