Telnet to legacy lab analyzer gateway
Cleartext remote management replaced with SSH jump access under CM-7/AC-17(8) intent; credentials no longer traverse the clinic VLAN in the clear.
AC-17(8) historically required disabling nonsecure remote access protocols (e.g., cleartext or obsolete remote services). In Rev. 5 it is withdrawn and incorporated into CM-7 (Least Functionality). Healthcare IT must still remove Telnet, unencrypted remote admin, legacy SSL VPN ciphers, insecure management protocols on clinical devices, and similar paths that could expose ePHI credentials or sessions — tracked under CM-7 with AC-17 policy context.
Ensure nonsecure protocols usable for remote access to ePHI environments are disabled or blocked, documenting Rev. 5 inheritance from AC-17(8) into CM-7.
How this control shows up in healthcare and HIPAA-covered environments.
Cleartext remote management replaced with SSH jump access under CM-7/AC-17(8) intent; credentials no longer traverse the clinic VLAN in the clear.
Old PPTP concentrator still online for one specialty clinic. Decommission forces modern VPN — nonsecure remote protocol removed.
Internal RDP without NLA/TLS to a charting server is hardened or brokered via gateway.
Assessors may still ask about AC-17(8). Show CM-7 least-functionality evidence that nonsecure remote protocols are disabled in ePHI environments.
How this NIST control supports HIPAA Security Rule expectations.
Withdrawn and incorporated into CM-7 Least Functionality.
No — document exceptions, segment, and compensate; plan replacement when vendors lack secure management.
Prefer disable. Monitoring does not encrypt cleartext Telnet credentials.
Related controls that commonly accompany AC-17(8).
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.