Evil twin ‘ClinicGuest’
Attacker broadcasts a lookalike SSID outside the building. AC-18(2) detection and staff awareness reduce credential capture risk for users who might have clinical VPN profiles.
AC-18(2) enhances base AC-18 by monitoring for unauthorized wireless connections to organizational systems. Rogue access points in waiting rooms, evil-twin SSIDs mimicking the clinic name, and unsanctioned bridges from clinical devices create silent paths toward ePHI. Continuous or frequent wireless monitoring detects these before credentials or charts are intercepted.
Detect and respond to unauthorized wireless connections and rogue RF infrastructure that could expose or bypass controls protecting ePHI.
How this control shows up in healthcare and HIPAA-covered environments.
Attacker broadcasts a lookalike SSID outside the building. AC-18(2) detection and staff awareness reduce credential capture risk for users who might have clinical VPN profiles.
Employee plugs in a personal AP. WIPS flags the rogue; security removes it under wireless policy.
A workstation joins a neighboring office’s weak SSID. Monitoring detects the unauthorized connection path away from managed clinical Wi-Fi.
Assessors ask how you know there is no rogue Wi-Fi in clinical areas. WIPS evidence and recent survey reports demonstrate AC-18(2).
How this NIST control supports HIPAA Security Rule expectations.
For small single-floor clinics maybe with risk acceptance; larger campuses generally need continuous WIPS plus periodic surveys.
Yes when they create unauthorized wireless networks in clinical areas or lure managed devices.
AC-18(2) focuses on wireless unauthorized connections; AC-17(5)/SI-4 covers broader unauthorized remote connections.
Related controls that commonly accompany AC-18(2).
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.