Home coder on café Wi-Fi
Without AC-17(2), a weak VPN could expose claim screens. Enforced modern VPN crypto protects the ePHI session on untrusted networks.
AC-17(2) enhances base AC-17 by implementing cryptographic mechanisms to protect the confidentiality and integrity of remote access sessions. Healthcare remote paths — site-to-site and client VPN, HTTPS EHR, virtual desktops, and vendor support tunnels — must use strong, modern encryption so ePHI cannot be sniffed or altered on home Wi-Fi, hotel networks, or intermediate links.
Encrypt remote access sessions that carry or can reach ePHI so confidentiality and integrity are preserved end-to-end for authorized remote work and support.
How this control shows up in healthcare and HIPAA-covered environments.
Without AC-17(2), a weak VPN could expose claim screens. Enforced modern VPN crypto protects the ePHI session on untrusted networks.
Telehealth platform and embedded EHR launch use TLS only; outdated protocol versions are blocked at the reverse proxy.
Legacy open RDP is replaced with an encrypted PAM gateway — integrity and confidentiality of the admin session into the interface engine.
HIPAA transmission security assessors expect evidence of encryption in transit for remote ePHI access — cipher inventories and scan results beat marketing claims about “secure VPN.”
How this NIST control supports HIPAA Security Rule expectations.
It can satisfy encryption-in-transit if TLS is strong and access controls are sound; still address device and authorization risks under AC-17/AC-19.
No — it targets remote access session confidentiality/integrity. At-rest controls are elsewhere (e.g., SC-28, AC-19 encryption enhancements).
Yes when they provide remote/organizational connectivity carrying ePHI between sites or to cloud.
Related controls that commonly accompany AC-17(2).
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.