VPN URL on marketing site
‘Connect from home’ public page listed the exact VPN FQDN and realm. AC-17(6) moves instructions behind SSO intranet and MDM auto-config.
AC-17(6) enhances base AC-17 by protecting information about remote access mechanisms from unauthorized disclosure. Publishing VPN hostnames on public websites, leaving default portal banners with internal topology, or sharing gateway credentials in unprotected tickets helps adversaries target healthcare remote entry points that lead to ePHI.
Limit who can learn how remote access to ePHI environments works — endpoints, URLs, protocols, and configuration details — to authorized personnel and documented channels.
How this control shows up in healthcare and HIPAA-covered environments.
‘Connect from home’ public page listed the exact VPN FQDN and realm. AC-17(6) moves instructions behind SSO intranet and MDM auto-config.
SSL VPN showed ‘Hospital Clinical VLAN Gateway – AD.CORP.’ Hardened banner reduces mechanism fingerprinting.
Unencrypted email contained jump-host IPs and temporary passwords. Process shifts to time-limited PAM invites without topology dumps.
Assessors may simply Google your VPN hostname. Public connection kits and verbose portals are soft targets that undermine otherwise strong AC-17 crypto and MFA.
How this NIST control supports HIPAA Security Rule expectations.
Absolute secrecy is unrealistic; the goal is not to advertise and not to leak configs/credentials. Defense in depth still requires MFA and monitoring.
Yes via approved authenticated channels. Avoid public posts and unauthenticated distribution.
Patient portals are intentionally public endpoints — still minimize banner leakage and protect admin remote mechanisms separately.
Related controls that commonly accompany AC-17(6).
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.