Insight · CJIS Readiness

CJIS compliance for healthcare organizations: who is actually in scope, and what it requires

By Thomas J. Johnson, Founder, EHR Resources LLC · October 9, 2026 · 10 min read

Most healthcare organizations have never heard of the CJIS Security Policy, and most do not need to. But a meaningful number handle criminal justice information without realizing it, and those organizations are held to a security standard that is stricter than HIPAA in several specific ways. The usual way this gets discovered is uncomfortable: a state audit, a contract renewal, or a law enforcement partner asking for documentation nobody has.

The short version

  • CJIS applies to any organization that accesses, stores, or transmits criminal justice information (CJI), including private contractors and vendors. Being a healthcare provider does not exempt you.
  • The current standard is CJIS Security Policy version 6.1, effective June 25, 2026, which restructured the policy around NIST SP 800-53 Revision 5 control families.
  • In healthcare, the organizations most often in scope are correctional and jail health providers, behavioral health programs tied to courts or drug courts, hospitals employing sworn officers, SANE and forensic nursing programs, and vendors serving any of these.
  • CJIS requires several things HIPAA does not mandate outright: fingerprint-based background checks, multifactor authentication, FIPS-validated encryption, and long audit log retention.
  • There is no such thing as CJIS certification, exactly as there is no HIPAA certification. Compliance is demonstrated through audits, agreements, and documentation.

What CJIS is, in plain terms

The FBI's Criminal Justice Information Services Division maintains the national systems that hold criminal history records, fingerprints, wanted-person files, and related data. The CJIS Security Policy is the rulebook for protecting that data, and it binds everyone who touches it: law enforcement agencies, the state agencies that connect to the FBI systems, and the private contractors and vendors those agencies rely on.

Criminal justice information, abbreviated CJI, is the regulated category. It includes criminal history record information, biometric data, identity history, and the contents of the FBI's databases. The policy follows that data through its whole lifecycle, from the moment it is created until it is destroyed.

Enforcement runs through the states. Each state has a CJIS Systems Agency, or CSA, that controls access and conducts audits, typically on a three-year cycle. A state may impose requirements stricter than the FBI baseline, which is why the answer to "what does CJIS require" always ends with "and check with your state."

Where healthcare organizations end up in scope

This is the part that catches people. None of the following are law enforcement agencies, and all of them routinely handle CJI.

Correctional and detention health services

Providers delivering medical or behavioral health care inside jails, prisons, and juvenile detention facilities frequently receive information about the people in their care that originates in criminal justice systems: charges, custody classification, court dates, warrant status, and identity records. If your intake process pulls from the facility's booking or jail management system, you are almost certainly touching CJI. Contracts with county sheriffs and state corrections departments usually carry CJIS obligations in the fine print.

Behavioral health programs connected to courts

Drug courts, mental health courts, court-ordered treatment, competency restoration, probation-linked counseling, and diversion programs all involve information flowing between a court or supervising agency and a clinical provider. When that flow includes criminal history or case data rather than just a referral, CJIS is in play.

Hospitals with sworn officers or law enforcement agreements

A hospital police department with commissioned officers has terminal access to state and federal systems. That access brings the hospital, including its IT department and its network, into CJIS scope. The same logic applies to facilities with formal data-sharing agreements with local law enforcement.

Forensic nursing and SANE programs

Sexual assault nurse examiner programs and forensic nursing units coordinate closely with investigators and evidence systems. Depending on how the program is structured and what systems it reaches, CJI may be involved.

Laboratories doing forensic work

Toxicology, DNA, and other testing performed for law enforcement or prosecutors often involves case identifiers and criminal justice records alongside clinical data.

Vendors and business associates serving any of the above

The policy reaches contractors explicitly. An EHR vendor serving a jail health program, a managed IT provider supporting a correctional clinic, a transcription service handling forensic reports, or a cloud host storing any of it can all be pulled into scope by the agreement their client signs. Version 6.0 of the policy expanded personnel security requirements to cover contractors directly.

A useful test

Ask two questions. First: does any information we receive, store, or transmit originate in a law enforcement, court, or corrections system? Second: do any of our contracts, with a sheriff, a corrections department, a court, or a law enforcement agency, reference the CJIS Security Policy or include a CJIS Security Addendum? If either answer is yes, you need a scoping conversation, not a reassurance.

What the policy requires

Version 6.1 organizes its requirements into 20 policy areas with roughly 178 controls. Eighteen of those areas map to NIST SP 800-53 Revision 5 control families; two are specific to CJIS, covering information exchange agreements and mobile devices. If your organization already works from a NIST-aligned framework, the structure will feel familiar. If you have only ever worked from the HIPAA Security Rule, it will not.

The areas where healthcare organizations most often fall short:

How CJIS and HIPAA differ, and where they collide

The two regimes share a goal and differ in method. HIPAA is risk-based and flexible: it tells you to assess your environment and implement what is reasonable and appropriate for your organization, and much of the Security Rule is addressable rather than required. CJIS is prescriptive: it names controls and expects them, and your state auditor checks against the list.

That difference has a practical consequence worth stating plainly. An organization can be fully defensible under HIPAA and fail a CJIS audit. A clinic that conducted a thorough security risk analysis, documented its decisions, and implemented reasonable safeguards has met the HIPAA standard. If it never ran fingerprint checks on its IT contractor, it has not met the CJIS standard, and no amount of HIPAA diligence substitutes.

The two also collide in places:

The certification question

There is no CJIS certification. No company can certify you, and any vendor claiming to be "CJIS certified" is describing something that does not exist. The parallel to HIPAA is exact, and we have written about the same problem in the HIPAA market.

What does exist: cloud providers and vendors can attest that their services are capable of supporting CJIS compliance, and many of the large ones do. That attestation describes their platform, not your configuration or your staff. Compliance is established through your agreements, your implemented controls, your documentation, and your state CSA's audit.

Where to start if you think you might be in scope

  1. Determine scope honestly. Map where criminal justice information actually enters, moves through, and leaves your organization. Include the systems nobody thinks about: email, shared drives, scanners, the laptop a case manager carries into the jail.
  2. Read your contracts. Pull every agreement with a law enforcement agency, sheriff, corrections department, or court. Look for references to the CJIS Security Policy and for a Security Addendum. The obligations are usually already there.
  3. Contact your state CSA. They set the local rules, run the audits, and will tell you what version of the policy they are auditing against. Several states are still auditing against version 5.9.5 during the transition to 6.x, so the answer matters.
  4. Assess against the policy, not against HIPAA. A gap assessment mapped to the 20 policy areas tells you where you stand. Your existing HIPAA work covers some of it, and you should get credit for that, but the overlap is partial.
  5. Start personnel screening early. It has the longest lead time of anything on the list, and it cannot be accelerated at the end.
  6. Document as you go. Audits are documentation exercises. Controls you implemented but cannot evidence will be treated as controls you do not have.

A closing thought

The organizations that get caught out here are rarely careless. They are usually providers who took on a jail contract or launched a court-linked program because a community needed it, and who reasonably assumed their HIPAA program covered them. It does not, and the gap tends to surface at the worst time: during a contract renewal, or in front of a state auditor.

If you handle criminal justice information, or suspect you might, the useful first step is a scoping conversation with someone who knows both frameworks. Determining that you are out of scope is a perfectly good outcome, and it is a much better one to reach deliberately than by assumption.

Not sure whether CJIS applies to you?

A short scoping conversation usually settles it. If you are out of scope, you will know why. If you are in scope, you will know what the gap looks like before anyone audits you.