SI-12 System and Information Integrity

Information Output Handling and Retention

High Risk Moderate Low Cost

SI-12 requires handling and retaining both system and nonsystem outputs in accordance with applicable laws, regulations, standards, and policies. Uncontrolled EHR report dumps, lingering data marts, and unmanaged Excel extracts create sprawling ePHI beyond the system of record.

Control Objective

Control how ePHI outputs are created, distributed, retained, and disposed so secondary copies do not outlive policy or escape minimum-necessary handling.

Implementation Guidance

  1. Inventory significant ePHI output channels (reports, extracts, prints, exports, backups, data marts).
  2. Define retention schedules aligned to clinical, legal, and HIPAA documentation needs.
  3. Apply access control and encryption to retained outputs.
  4. Quotas/approvals for bulk exports.
  5. Dispose/sanitize outputs at end of retention (MP-6).
  6. Label sensitive outputs (MP-3).
  7. Train workforce on shadow Excel risks.
  8. Audit high-volume exporters periodically.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Unlimited CSV export from EHR

SI-12 approval workflow and monitoring flag a user pulling full panel lists nightly; access trimmed.

Data mart older than policy

Retention job retires obsolete identifiable tables under documented schedule.

Printed OR schedules left out

Output handling rules require secure print and same-day disposal in clinical areas.

Best Practices

  • Inventory ePHI outputs.
  • Retention schedules enforced.
  • Control bulk exports.
  • Secure disposal at end of life.
  • Label sensitive outputs.
  • Audit exporters.

Common Gaps & Violations

  • Shadow data warehouses forgotten.
  • Exports to personal cloud.
  • Retention forever for convenience.
  • No owner for report distribution lists.
  • Printed ePHI in open bins.

Required Documentation

  • Output handling and retention standard (SI-12)
  • Retention schedule for ePHI outputs
  • Export approval/monitoring evidence
  • Disposal records
  • Training materials on shadow copies

How to Test & Validate

  1. Sample bulk export logs for approvals.
  2. Verify retention jobs on a data mart.
  3. Tour clinical areas for output handling.
  4. Check disposal of retired report archives.
  5. Interview analytics team on identifiable extract controls.

Audit Considerations

Secondary ePHI copies cause many breaches. SI-12 evidence shows governance of outputs — not only the EHR database itself.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.530(j) Documentation — retain required documentation for six years; distinguish from clinical record retention.
  • 164.310(d) Device and Media Controls — handle electronic outputs/media containing ePHI.
  • 164.502(b) Minimum Necessary — limit outputs to minimum necessary.
  • 164.530(c) Safeguards — protect PHI in all forms of output.

Compliance Tips

  • Require tickets for novel bulk ePHI extracts.
  • Scan for open cloud shares with exports.
  • Align SI-12 retention with legal hold procedures.

Frequently Asked Questions

Does SI-12 set clinical medical record retention?

It requires handling/retention per applicable laws and policies — clinical retention may be defined elsewhere but must be applied to outputs.

Are backups in scope?

Yes as system outputs/copies — retain and protect per CP-9 and disposal rules.

How related to MP controls?

MP addresses media; SI-12 addresses broader output handling including logical reports and retention.

References & Resources

  • NIST SP 800-53 Rev. 5 — SI-12
  • Related controls: MP-6, MP-3, AC-3, CP-9, AU-11

Need Help Implementing SI-12?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.