SA-2 System Acquisition

Allocation of Resources

High Risk Moderate Medium Cost

SA-2 requires determining the high-level security and privacy requirements for the system and allocating resources required to protect the system as part of capital planning and investment. Healthcare IT projects that fund features but not logging, IAM, or contingency leave ePHI under-protected by design.

Control Objective

Identify security/privacy requirements early and allocate budget, people, and tooling so ePHI protections are funded through build, operate, and retire phases.

Implementation Guidance

  1. Include security/privacy requirements in business cases for systems touching ePHI.
  2. Estimate resources for IAM, logging, encryption, testing, BA oversight, and contingency.
  3. Assign funded owners — not volunteer-only security.
  4. Track security spend/resources in project governance gates.
  5. Fund sustainment (licenses, FTE) not only go-live.
  6. For SaaS, budget for configuration hardening and monitoring, not assume vendor covers all.
  7. Escalate under-funded high-risk systems to leadership risk committees.
  8. Align SA-2 with PL-2 and organizational budgeting cycles.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

EHR module funded without SSO budget

Project tries to launch with local passwords. SA-2 gate requires IAM integration funding before approval.

Understaffed SOC after clinic expansion

New sites add ePHI logs but no analyst capacity. Resource allocation plan adds SIEM licensing and FTE.

Backup immutability unfunded

Ransomware readiness item sits idle. Capital planning under SA-2 funds immutable storage for EHR backups.

Best Practices

  • Security/privacy line items in project budgets.
  • Sustainment funding, not only go-live.
  • Named resource owners.
  • Gate underfunded ePHI projects.
  • Include BA oversight costs.
  • Leadership visibility on gaps.

Common Gaps & Violations

  • Security asked to support after go-live for free.
  • No budget for logging storage.
  • Ignoring license renewals for EDR on clinical PCs.
  • Cloud project assumes shared responsibility is free.
  • Privacy program unfunded for new data uses.

Required Documentation

  • Resource allocation procedure (SA-2)
  • Security/privacy requirements in business case templates
  • Budget/staffing evidence for major ePHI systems
  • Gate checklists
  • Risk acceptances for known underfunding

How to Test & Validate

  1. Sample a recent ePHI project business case for security resources.
  2. Verify sustainment funding for a production control (e.g., EDR).
  3. Review escalation of an underfunded risk.
  4. Confirm SaaS project budgeted monitoring/config work.
  5. Interview security leadership on planning cycle input.

Audit Considerations

Many HIPAA gaps are resource gaps. SA-2 evidence shows security was planned as an investment, not an afterthought.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.306 General rules — reasonable and appropriate safeguards consider size and capabilities — still require intentional resource allocation.
  • 164.308(a)(1) Risk Management — reducing risks requires funded measures.
  • 164.308(a)(8) Evaluation — evaluation is meaningless if fixes cannot be resourced.
  • 164.316 Policies and procedures — maintaining documentation and controls implies ongoing resources.

Compliance Tips

  • Add a security estimate field to every IT demand request involving ePHI.
  • Report unfunded critical controls as formal risks.
  • Revisit SA-2 annually during budget season.

Frequently Asked Questions

Does SA-2 require a separate security budget code?

Helpful but not mandatory — show that resources are identified and allocated somehow.

What if leadership accepts underfunding?

Document risk acceptance; SA-2 still requires the determination and allocation decision be explicit.

Are BA costs in scope?

Yes when BA services are required to meet security/privacy requirements for ePHI.

References & Resources

  • NIST SP 800-53 Rev. 5 — SA-2
  • Related controls: PL-2, PM-2, RA-3, SA-3

Need Help Implementing SA-2?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.