Behavioral health telehealth platform RFP
SA-4 pack requires BAA, session encryption, audit logs for chart access, and data return/destruction on contract end before vendors can bid.
SA-4 requires including security and privacy requirements, descriptions, and acceptance criteria in acquisition contracts; functional and security property requirements; requirements for developer evidence; and controls for systems, components, and services. In healthcare, SA-4 turns SA-1 policy into the concrete RFP/contract checklist used when buying EHR modules, cloud services, devices, and interfaces that can expose ePHI.
Ensure every acquisition of systems or services that may affect ePHI includes explicit security/privacy requirements, evidence expectations, and acceptance criteria before purchase and go-live.
How this control shows up in healthcare and HIPAA-covered environments.
SA-4 pack requires BAA, session encryption, audit logs for chart access, and data return/destruction on contract end before vendors can bid.
Go-live acceptance tests confirm TLS, file integrity checks, and access logging meet contract criteria.
Acquisition process requires OEM security whitepaper, patch cadence, and remote support controls before network enablement.
Procurement files reveal whether security was required or optional. SA-4 evidence is persuasive when paired with BAAs and technical acceptance tests.
How this NIST control supports HIPAA Security Rule expectations.
Yes — renewals should re-confirm security requirements, especially if features or subprocessors changed.
Specific enough to test (e.g., “support SSO MFA,” “provide audit export”) rather than only “be secure.”
Document compensating controls and formal residual risk acceptance under your RA process.
Related controls that commonly accompany SA-4.
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.