Nursing SSO Wi-Fi
WOWs join the clinical SSID with machine certificates — AC-18(1) authentication and encryption — instead of a posted wall password.
AC-18(1) enhances base AC-18 by protecting wireless access using authentication and encryption. Open or PSK-only clinical SSIDs that route to EHR VLANs fail this enhancement. Hospitals and clinics should use enterprise authentication (802.1X) and strong wireless encryption so only authorized devices join networks that can reach ePHI, and traffic is not trivial to intercept in waiting rooms or parking lots.
Require authenticated, encrypted wireless associations for any SSID that can access or transit toward systems containing ePHI.
How this control shows up in healthcare and HIPAA-covered environments.
WOWs join the clinical SSID with machine certificates — AC-18(1) authentication and encryption — instead of a posted wall password.
Patients use encrypted guest Wi-Fi with no EHR routes; staff clinical SSID requires 802.1X.
Device authenticates and is encrypted on a restricted SSID allowed only to the archive — not the open ‘Staff’ PSK network.
Floor walkers look for posted Wi-Fi passwords and open SSIDs. Enterprise auth evidence and guest isolation proofs support AC-18(1).
How this NIST control supports HIPAA Security Rule expectations.
It encrypts frames but shared secrets scale poorly and are hard to revoke. Prefer enterprise auth for SSIDs that reach ePHI; document risk if PSK is unavoidable.
Not typically — isolate it and use strong modern encryption; never route it to ePHI.
AC-18(1) secures the wireless hop; AC-17(2) encrypts remote access sessions (often beyond the LAN).
Related controls that commonly accompany AC-18(1).
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.