Portal 500 shows SQL with MRN
SI-11 fix returns generic apology page; detailed error stays in restricted logs without full PHI where possible.
SI-11 requires generating error messages that provide information necessary for corrective actions without revealing information that could be exploited, and revealing error messages only to authorized personnel. Stack traces with SQL and patient identifiers on patient portals are a classic ePHI disclosure.
Ensure applications and services handling ePHI handle errors securely — user-facing messages stay generic while detailed diagnostics go only to authorized operators under protection.
How this control shows up in healthcare and HIPAA-covered environments.
SI-11 fix returns generic apology page; detailed error stays in restricted logs without full PHI where possible.
Admin console errors sanitized; full payloads only in access-controlled logs.
Process change redacts ePHI before storing tickets in lower-trust systems.
Verbose errors are both an information disclosure and HIPAA risk. SI-11 is easy to demonstrate with a few controlled tests on public-facing apps.
How this NIST control supports HIPAA Security Rule expectations.
Minimize; when needed for diagnostics, protect logs as ePHI stores with access control and retention limits.
Yes where error displays could show ePHI to bystanders — apply PE-19 awareness too.
SI-10 is information input validation; SI-11 is how errors are handled and revealed.
Related controls that commonly accompany SI-11.
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.