Control Objective
Ensure every wireless network is intentionally designed, authorized, and segmented so rogue or guest access cannot become a shortcut into clinical systems and ePHI.
Real-World Use Cases
How this control shows up in healthcare and HIPAA-covered environments.
Guest Wi-Fi bridged to clinic LAN
A small practice put guest and staff on one consumer router. A visitor could scan for EHR servers. AC-18 remediation creates an isolated guest SSID with client isolation and no corporate routes — patient convenience without network exposure.
Wireless ultrasound on clinical SSID
A new ultrasound unit needs Wi-Fi to archive studies. AC-18 puts it on a biomed SSID with ACL allow-list only to PACS, certificate-based join where supported, and inventory tagging — not the open staff password network.
Rogue AP in a waiting room
A well-meaning employee plugs in a travel router for 'better signal.' Wireless IDS / periodic surveys detect the rogue SSID; security removes it and retrains staff under the wireless authorization policy.
Audit Considerations
Assessors often walk the floor with a laptop. Be ready to show segmentation evidence and explain every SSID. Shared passwords for clinical Wi-Fi are a frequent finding.
HIPAA Mapping
How this NIST control supports HIPAA Security Rule expectations.
- 164.312(a)(1) Access Control — wireless entry must not bypass authorization to ePHI systems.
- 164.312(e) Transmission Security — protect ePHI transmitted over wireless media.
- 164.310(b)–(c) Workstation Use/Security — wireless workstations and mobile carts operate in open areas needing controlled connectivity.
- 164.308(a)(1) Risk Analysis — wireless and rogue AP risks belong in the organization-wide analysis.