SA-9 System Acquisition

External Information System Services

High Risk Moderate Low Cost

SA-9 requires requiring that providers of external system services comply with organizational security requirements, defining and documenting government/oversight roles, and monitoring provider compliance. For healthcare, external services include cloud EHR, claims clearinghouses, e-fax, transcription, patient engagement apps, and hosting — each needs security requirements, BAAs where applicable, and ongoing oversight, not a one-time procurement checkbox.

Control Objective

Ensure external services that create, receive, maintain, or transmit ePHI meet documented security requirements with assigned oversight and ongoing compliance monitoring.

Implementation Guidance

  1. Inventory external services touching ePHI (shadow IT discovery included).
  2. Define baseline security requirements: encryption, auth, logging, breach notice, subprocessors, data residency, and exit/return of data.
  3. Execute BAAs when the vendor is a business associate; attach security exhibits.
  4. Assign internal owners for each service (business + security oversight).
  5. Review SOC 2/HITRUST evidence, questionnaires, and POA&Ms on a defined cadence.
  6. Monitor for control drift: new features that export ePHI, changed auth, or subprocessor changes.
  7. Plan offboarding: revoke access, certify destruction/return, update interconnection register (CA-3).
  8. Include 'free' apps and AI tools that staff paste ePHI into — prohibit or bring under SA-9.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

New patient messaging SaaS

Security requirements checklist and BAA complete before go-live; internal product owner monitors quarterly SOC reports under SA-9 oversight.

Transcription vendor subprocessor change

Vendor notice triggers review; data flow diagram and risk acceptance updated before continued use.

Shadow AI note-summarizer found in a clinic

Service had no BAA; access blocked, alternatives evaluated under SA-9 procurement path.

Best Practices

  • Living external service inventory.
  • Written security requirements per service tier.
  • Named internal oversight owners.
  • Periodic evidence review.
  • Exit/destruction plans.
  • Shadow IT continuous discovery.

Common Gaps & Violations

  • BAAs signed without security requirements.
  • No owner after procurement.
  • Never review vendor attestations again.
  • Unknown subprocessors processing ePHI.
  • Staff-adopted apps with ePHI and no oversight.

Required Documentation

  • External services / cloud security standard
  • Service inventory with ePHI flag and owners
  • Security requirements / exhibit templates
  • Oversight review schedule and samples
  • Offboarding / data return checklists

How to Test & Validate

  1. Sample external ePHI services for BAA + security requirements.
  2. Verify each has an internal oversight owner.
  3. Confirm last compliance review date.
  4. Trace a terminated service to data return/destruction evidence.
  5. Spot-check shadow IT findings against the inventory.

Audit Considerations

Third-party and cloud use is central to modern HIPAA assessments. SA-9 evidence is requirements, contracts, and ongoing oversight — not logos on a vendor slide.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.308(b) Business Associate Contracts — satisfactory assurances from vendors handling ePHI.
  • 164.314 Organizational Requirements — BA contract content supporting safeguard obligations.
  • 164.308(a)(1) Risk Analysis — external services are in-scope risk surfaces.
  • 164.312 Technical Safeguards — require vendors to support access, audit, integrity, and transmission controls as applicable.

Compliance Tips

  • Maintain a single 'systems of record' list that marks external vs internal.
  • Re-review high-risk SaaS at least annually before contract auto-renew.
  • Train procurement to stop ePHI vendors that skip security review.

Frequently Asked Questions

Does a BAA satisfy SA-9 by itself?

No. SA-9 also needs defined requirements, oversight roles, and monitoring of continued compliance.

How does SA-9 relate to CA-3?

CA-3 focuses on interconnection authorization/documentation; SA-9 focuses on the external service relationship and security oversight.

Are purely internal on-prem tools in scope?

SA-9 targets external providers; internal systems are covered by other SA/CM controls — but hybrid hosted tools usually are external services.

References & Resources

  • NIST SP 800-53 Rev. 5 — SA-9
  • NIST SP 800-161 (supply chain context)
  • Related controls: CA-3, PS-7, SR-1, RA-3, AC-20

Need Help Implementing SA-9?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.