Most healthcare organizations have never heard of the CJIS Security Policy, and most do not need to. But a meaningful number handle criminal justice information without realizing it, and those organizations are held to a security standard that is stricter than HIPAA in several specific ways. The usual way this gets discovered is uncomfortable: a state audit, a contract renewal, or a law enforcement partner asking for documentation nobody has.
The short version
- CJIS applies to any organization that accesses, stores, or transmits criminal justice information (CJI), including private contractors and vendors. Being a healthcare provider does not exempt you.
- The current standard is CJIS Security Policy version 6.1, effective June 25, 2026, which restructured the policy around NIST SP 800-53 Revision 5 control families.
- In healthcare, the organizations most often in scope are correctional and jail health providers, behavioral health programs tied to courts or drug courts, hospitals employing sworn officers, SANE and forensic nursing programs, and vendors serving any of these.
- CJIS requires several things HIPAA does not mandate outright: fingerprint-based background checks, multifactor authentication, FIPS-validated encryption, and long audit log retention.
- There is no such thing as CJIS certification, exactly as there is no HIPAA certification. Compliance is demonstrated through audits, agreements, and documentation.
What CJIS is, in plain terms
The FBI's Criminal Justice Information Services Division maintains the national systems that hold criminal history records, fingerprints, wanted-person files, and related data. The CJIS Security Policy is the rulebook for protecting that data, and it binds everyone who touches it: law enforcement agencies, the state agencies that connect to the FBI systems, and the private contractors and vendors those agencies rely on.
Criminal justice information, abbreviated CJI, is the regulated category. It includes criminal history record information, biometric data, identity history, and the contents of the FBI's databases. The policy follows that data through its whole lifecycle, from the moment it is created until it is destroyed.
Enforcement runs through the states. Each state has a CJIS Systems Agency, or CSA, that controls access and conducts audits, typically on a three-year cycle. A state may impose requirements stricter than the FBI baseline, which is why the answer to "what does CJIS require" always ends with "and check with your state."
Where healthcare organizations end up in scope
This is the part that catches people. None of the following are law enforcement agencies, and all of them routinely handle CJI.
Correctional and detention health services
Providers delivering medical or behavioral health care inside jails, prisons, and juvenile detention facilities frequently receive information about the people in their care that originates in criminal justice systems: charges, custody classification, court dates, warrant status, and identity records. If your intake process pulls from the facility's booking or jail management system, you are almost certainly touching CJI. Contracts with county sheriffs and state corrections departments usually carry CJIS obligations in the fine print.
Behavioral health programs connected to courts
Drug courts, mental health courts, court-ordered treatment, competency restoration, probation-linked counseling, and diversion programs all involve information flowing between a court or supervising agency and a clinical provider. When that flow includes criminal history or case data rather than just a referral, CJIS is in play.
Hospitals with sworn officers or law enforcement agreements
A hospital police department with commissioned officers has terminal access to state and federal systems. That access brings the hospital, including its IT department and its network, into CJIS scope. The same logic applies to facilities with formal data-sharing agreements with local law enforcement.
Forensic nursing and SANE programs
Sexual assault nurse examiner programs and forensic nursing units coordinate closely with investigators and evidence systems. Depending on how the program is structured and what systems it reaches, CJI may be involved.
Laboratories doing forensic work
Toxicology, DNA, and other testing performed for law enforcement or prosecutors often involves case identifiers and criminal justice records alongside clinical data.
Vendors and business associates serving any of the above
The policy reaches contractors explicitly. An EHR vendor serving a jail health program, a managed IT provider supporting a correctional clinic, a transcription service handling forensic reports, or a cloud host storing any of it can all be pulled into scope by the agreement their client signs. Version 6.0 of the policy expanded personnel security requirements to cover contractors directly.
A useful test
Ask two questions. First: does any information we receive, store, or transmit originate in a law enforcement, court, or corrections system? Second: do any of our contracts, with a sheriff, a corrections department, a court, or a law enforcement agency, reference the CJIS Security Policy or include a CJIS Security Addendum? If either answer is yes, you need a scoping conversation, not a reassurance.
What the policy requires
Version 6.1 organizes its requirements into 20 policy areas with roughly 178 controls. Eighteen of those areas map to NIST SP 800-53 Revision 5 control families; two are specific to CJIS, covering information exchange agreements and mobile devices. If your organization already works from a NIST-aligned framework, the structure will feel familiar. If you have only ever worked from the HIPAA Security Rule, it will not.
The areas where healthcare organizations most often fall short:
- Personnel screening. CJIS requires fingerprint-based state and national background checks for everyone with access to CJI, including IT staff and contractors, with rescreening on a defined cycle. HIPAA requires no such thing. This is frequently the single largest gap, and it takes the longest to close because it involves people, not technology.
- Multifactor authentication. Required for a broad range of access scenarios, including remote access, cloud environments, and privileged accounts. HIPAA treats authentication as addressable; CJIS does not.
- Encryption with validated modules. CJIS requires FIPS-validated cryptography, not merely "encryption." The distinction matters: a product can encrypt data and still fail the requirement if its cryptographic module is not validated. The policy states that FIPS 140-2 certificates are no longer acceptable after September 21, 2026, which means organizations relying on older validated products need to confirm their replacements.
- Audit logging and retention. CJIS sets specific expectations for what must be logged and how long records are kept, generally far longer than most clinical environments retain system logs by default.
- Physical security. Controlled areas where CJI is accessed, visitor management, and protection of devices and media, specified in more detail than HIPAA's physical safeguards.
- Training. Role-based security awareness training on a defined schedule, with records, for everyone with CJI access.
- Incident response and reporting. Defined timelines for reporting incidents involving CJI to the agencies you serve, which may be considerably shorter than HIPAA's 60-day breach notification window.
- Media handling and destruction. Specific requirements for sanitizing and destroying media that held CJI.
How CJIS and HIPAA differ, and where they collide
The two regimes share a goal and differ in method. HIPAA is risk-based and flexible: it tells you to assess your environment and implement what is reasonable and appropriate for your organization, and much of the Security Rule is addressable rather than required. CJIS is prescriptive: it names controls and expects them, and your state auditor checks against the list.
That difference has a practical consequence worth stating plainly. An organization can be fully defensible under HIPAA and fail a CJIS audit. A clinic that conducted a thorough security risk analysis, documented its decisions, and implemented reasonable safeguards has met the HIPAA standard. If it never ran fingerprint checks on its IT contractor, it has not met the CJIS standard, and no amount of HIPAA diligence substitutes.
The two also collide in places:
- Data segregation. CJI and protected health information often arrive about the same person in the same workflow. Keeping them appropriately separated, while making both available to the people who need them, is a design problem more than a policy problem.
- Retention conflicts. HIPAA, state medical records law, and CJIS set different retention expectations. When they disagree, you need a documented decision rather than a default.
- Disclosure rules. HIPAA governs when PHI may be disclosed to law enforcement. CJIS governs how CJI is protected once you have it. A request from an officer can implicate both, in opposite directions.
- Vendor agreements. A business associate agreement does not satisfy CJIS. Contractors handling CJI generally sign a CJIS Security Addendum, a separate instrument with its own obligations, and you may need both with the same vendor.
The certification question
There is no CJIS certification. No company can certify you, and any vendor claiming to be "CJIS certified" is describing something that does not exist. The parallel to HIPAA is exact, and we have written about the same problem in the HIPAA market.
What does exist: cloud providers and vendors can attest that their services are capable of supporting CJIS compliance, and many of the large ones do. That attestation describes their platform, not your configuration or your staff. Compliance is established through your agreements, your implemented controls, your documentation, and your state CSA's audit.
Where to start if you think you might be in scope
- Determine scope honestly. Map where criminal justice information actually enters, moves through, and leaves your organization. Include the systems nobody thinks about: email, shared drives, scanners, the laptop a case manager carries into the jail.
- Read your contracts. Pull every agreement with a law enforcement agency, sheriff, corrections department, or court. Look for references to the CJIS Security Policy and for a Security Addendum. The obligations are usually already there.
- Contact your state CSA. They set the local rules, run the audits, and will tell you what version of the policy they are auditing against. Several states are still auditing against version 5.9.5 during the transition to 6.x, so the answer matters.
- Assess against the policy, not against HIPAA. A gap assessment mapped to the 20 policy areas tells you where you stand. Your existing HIPAA work covers some of it, and you should get credit for that, but the overlap is partial.
- Start personnel screening early. It has the longest lead time of anything on the list, and it cannot be accelerated at the end.
- Document as you go. Audits are documentation exercises. Controls you implemented but cannot evidence will be treated as controls you do not have.
A closing thought
The organizations that get caught out here are rarely careless. They are usually providers who took on a jail contract or launched a court-linked program because a community needed it, and who reasonably assumed their HIPAA program covered them. It does not, and the gap tends to surface at the worst time: during a contract renewal, or in front of a state auditor.
If you handle criminal justice information, or suspect you might, the useful first step is a scoping conversation with someone who knows both frameworks. Determining that you are out of scope is a perfectly good outcome, and it is a much better one to reach deliberately than by assumption.