Patient portal IDOR bug
Pre-prod authZ testing under SA-11 finds users can open other patients’ visit summaries by changing an ID. Release is blocked until fixed and retested.
SA-11 requires requiring developers to create and implement a security and privacy assessment plan; perform testing/evaluation; produce evidence; correct flaws; and control testing environments and data. Shipping untested patient portals, billing APIs, or device gateways is a recurring HIPAA breach pattern.
Ensure software and configurations affecting ePHI undergo planned security and privacy testing with tracked remediation before production use — using protected test data and environments.
How this control shows up in healthcare and HIPAA-covered environments.
Pre-prod authZ testing under SA-11 finds users can open other patients’ visit summaries by changing an ID. Release is blocked until fixed and retested.
A vendor asks for a full EHR DB copy for QA. SA-11 policy denies prod ePHI in test; synthetic cohort is provisioned instead.
Scanner finds a critical library in a scheduling API. Defect is tracked, patched, and regression-tested before the weekend deploy.
OCR and assessors frequently examine whether apps were tested and whether test environments leaked ePHI. SA-11 evidence should show planned testing and controlled data — not last-minute scans after go-live.
How this NIST control supports HIPAA Security Rule expectations.
Periodic independent tests help, but SA-11 also requires developer testing/evaluation on an ongoing basis for changes — not only an annual snapshot.
Prefer synthetic or de-identified data; if limited ePHI is ever required, apply minimum necessary, controls, and documentation equal to production sensitivity.
Scale testing to risk — privilege, disclosure, and interface changes still need evaluation even when little custom code is written.
Related controls that commonly accompany SA-11.
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.