SA-4 System Acquisition

Acquisition Process

High Risk Moderate Low Cost

SA-4 requires including security and privacy requirements, descriptions, and acceptance criteria in acquisition contracts; functional and security property requirements; requirements for developer evidence; and controls for systems, components, and services. In healthcare, SA-4 turns SA-1 policy into the concrete RFP/contract checklist used when buying EHR modules, cloud services, devices, and interfaces that can expose ePHI.

Control Objective

Ensure every acquisition of systems or services that may affect ePHI includes explicit security/privacy requirements, evidence expectations, and acceptance criteria before purchase and go-live.

Implementation Guidance

  1. Maintain a standard security/privacy requirements pack for ePHI-impacting acquisitions.
  2. Insert requirements into RFPs, statements of work, and contracts (encryption, MFA, logging, BA terms, breach notice).
  3. Require vendor architecture and admin documentation sufficient to operate controls (SA-5 linkage).
  4. Define acceptance tests: MFA works, audit events export, encryption verified, BAA executed.
  5. Evaluate developer/vendor secure development claims for custom or configurable products.
  6. Capture residual gaps in risk acceptance before production ePHI use.
  7. Apply scaled SA-4 checklists to medical devices and smaller SaaS — not only mega-EHR deals.
  8. Retain acquisition security artifacts with the contract file.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Behavioral health telehealth platform RFP

SA-4 pack requires BAA, session encryption, audit logs for chart access, and data return/destruction on contract end before vendors can bid.

Acceptance of a new claims clearinghouse

Go-live acceptance tests confirm TLS, file integrity checks, and access logging meet contract criteria.

Surgical robot networked service contract

Acquisition process requires OEM security whitepaper, patch cadence, and remote support controls before network enablement.

Best Practices

  • Standard reusable requirements exhibit.
  • Acceptance criteria tied to ePHI controls.
  • BAA and security schedule in one packet.
  • Evidence requests proportional to criticality.
  • No production data until acceptance signed.
  • Archive requirements vs vendor responses.

Common Gaps & Violations

  • Security questionnaire after contract signature only.
  • Vague “comply with HIPAA” clause with no specifics.
  • Acceptance based on clinical functionality alone.
  • Devices purchased by departments without SA-4 checklist.
  • Missing data destruction/return requirements.

Required Documentation

  • SA-4 acquisition security checklist / exhibit
  • Sample RFPs with security requirements
  • Acceptance test records
  • Contract security schedules
  • Risk acceptance for unmet requirements

How to Test & Validate

  1. Sample a recent ePHI-related acquisition for SA-4 requirements inclusion.
  2. Verify acceptance criteria were tested before go-live.
  3. Confirm BAA and breach language present when required.
  4. Review vendor evidence retained in contract files.
  5. Trace one gap to documented risk acceptance.

Audit Considerations

Procurement files reveal whether security was required or optional. SA-4 evidence is persuasive when paired with BAAs and technical acceptance tests.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.308(b) Business Associate Contracts — contractual satisfactory assurances for BAs.
  • 164.314(a) — required implementation specifications in BA contracts.
  • 164.306 — reasonable and appropriate safeguards selected through acquisition decisions.
  • 164.308(a)(1) Risk Management — unmet vendor controls must be treated as risk.

Compliance Tips

  • Make the SA-4 checklist a mandatory attachment in the contract management system.
  • Train clinical buyers with a two-page “ePHI purchase” guide.
  • Reuse acceptance tests as annual vendor assurance evidence.

Frequently Asked Questions

Does SA-4 apply to renewals?

Yes — renewals should re-confirm security requirements, especially if features or subprocessors changed.

How detailed must requirements be?

Specific enough to test (e.g., “support SSO MFA,” “provide audit export”) rather than only “be secure.”

What if a sole-source clinical device cannot meet a control?

Document compensating controls and formal residual risk acceptance under your RA process.

References & Resources

  • NIST SP 800-53 Rev. 5 — SA-4
  • Related controls: SA-1, SA-5, SA-9, SR-3, CA-2

Need Help Implementing SA-4?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.