SA-15 System Acquisition

Development Process, Standards, and Tools

High Risk Complex Medium Cost

SA-15 requires requiring the developer to follow documented development process standards and tools, delivering evidence, and managing tool integrity. Unapproved compilers, random VS Code extensions, and unmanaged CI runners become pathways to implant malware into apps that handle ePHI.

Control Objective

Mandate and oversee development processes, standards, and tools used to build and maintain ePHI-related software so toolchains are approved, integrity-protected, and evidenced.

Implementation Guidance

  1. Publish approved development standards (coding, review, secret handling) for ePHI-impacting software.
  2. Approve toolchains and CI platforms; inventory extensions/plugins.
  3. Require SAST/dependency scanning tools in the pipeline.
  4. Protect build servers and signing keys.
  5. Obtain evidence from internal and BA developers (process docs, scan reports).
  6. Ban production credentials in developer tools.
  7. Review toolchain changes under change control.
  8. Align with SA-10 CM and SA-11 testing.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Unapproved CI plugin

A marketplace plugin with weak ratings appears in the FHIR app pipeline. SA-15 approval list blocks it until reviewed.

BA delivers without process evidence

Custom EHR form vendor cannot show coding standards or scan results. Contractual SA-15 clause holds acceptance.

Build server as shared workstation

Developers browse the web on the build host. Hardening and separation under SA-15 protect artifact integrity.

Best Practices

  • Approved tools/process standards.
  • Pipeline security scanning.
  • Protected build infrastructure.
  • Evidence from vendors.
  • Inventory of plugins/extensions.
  • Change control for toolchain.

Common Gaps & Violations

  • Any tool allowed on developer laptops for prod code.
  • No SBOM or dependency scan.
  • Unsigned artifacts.
  • Vendor code accepted on trust alone.
  • Secrets in IDE sync cloud.

Required Documentation

  • Development process and tools standard (SA-15)
  • Approved toolchain inventory
  • Pipeline configuration baselines
  • Vendor evidence requirements
  • Build system hardening standards

How to Test & Validate

  1. Review approved toolchain list vs actual CI config.
  2. Sample pipeline for required scanners.
  3. Inspect build server access controls.
  4. Review BA deliverable evidence package.
  5. Check secret scanning/policy enforcement.

Audit Considerations

Toolchain compromise is a high-impact supply-chain path. Assessors increasingly ask how healthcare software is built, not only how it is hosted.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.312(c) Integrity — protect ePHI from improper alteration; secure development tools support system integrity.
  • 164.308(a)(1) Risk Management — manage risks from software development practices.
  • 164.308(b) BA requirements — developers who create systems with ePHI need contractual process assurances.
  • 164.312(b) Audit Controls — development evidence supports accountability.

Compliance Tips

  • Maintain a short allow-list of IDE extensions for clinical app teams.
  • Require SA-15 evidence in vendor SOWs for custom ePHI work.
  • Protect code signing like a Tier-0 asset.

Frequently Asked Questions

Does SA-15 apply if we only configure Epic?

Scale to your customizations, extensions, and integrations; heavy configuration shops still need standards for scripts and automation.

How does SA-15 relate to SA-3?

SA-3 is the life cycle; SA-15 details process standards and tools developers must follow within that life cycle.

Are low-code platforms in scope?

Yes when used to process ePHI — approve platforms and govern connectors/tools.

References & Resources

  • NIST SP 800-53 Rev. 5 — SA-15
  • Related controls: SA-3, SA-10, SA-11, SR-3, SI-7

Need Help Implementing SA-15?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.