CM-10 Configuration Management

Software Usage Restrictions

Medium Risk Moderate Medium Cost

CM-10 requires using software and associated documentation in accordance with contract agreements and copyright laws; tracking usage; and controlling/documenting copying/distribution. Healthcare environments also need restrictions against unapproved apps that become shadow ePHI stores — personal cloud sync, unlicensed remote tools, and cracked utilities on clinic PCs.

Control Objective

Restrict software on ePHI-capable systems to approved, properly licensed titles — and track usage so unlicensed or prohibited software cannot undermine HIPAA safeguards.

Implementation Guidance

  1. Publish an approved software catalog for clinical and corporate endpoints that can reach ePHI.
  2. Enforce via application allow-listing / MDM / endpoint management where feasible.
  3. Track licenses for EHR clients, imaging viewers, VPN, and security tools; remediate shortfalls.
  4. Prohibit high-risk categories: unauthorized file sync, consumer remote access, peer-to-peer, and unapproved AI upload tools.
  5. Document rules for copying/distribution of licensed clinical software and vendor documentation.
  6. Include servers and VDI images, not only laptops.
  7. Audit periodically for unauthorized installs; remove and educate.
  8. Address BYOD separately — containerization or denial of local ePHI storage.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Personal Dropbox on a nursing workstation

CM-10/MDM blocks consumer sync clients that could upload ePHI; staff use the approved ECM instead.

Unlicensed DICOM viewer sprawl

Departments install random viewers. CM-10 consolidates to licensed, approved viewers with security baselines.

Cracked “PDF tools” on registration PCs

Periodic software audit finds pirated utilities. Removal protects legal exposure and eliminates malware-laden installers near ePHI.

Best Practices

  • Approved catalog + allow-listing.
  • License true-ups tied to CM-8.
  • Explicit prohibited software list.
  • Regular unauthorized software scans.
  • Cover VDI golden images.
  • Train workforce on approved alternatives.

Common Gaps & Violations

  • Local admin rights enabling anything-goes installs.
  • No inventory of EHR-related licenses.
  • Shadow AI tools pasting PHI into public models.
  • Vendor demo software left permanently installed.
  • Documentation copyright ignored when sharing manuals externally.

Required Documentation

  • Software usage restrictions policy (CM-10)
  • Approved / prohibited software lists
  • License tracking records
  • Endpoint enforcement configuration evidence
  • Unauthorized software audit results

How to Test & Validate

  1. Sample endpoints for software not on the approved list.
  2. Verify allow-listing or equivalent controls on clinical workstations.
  3. Review license compliance for key clinical apps.
  4. Confirm prohibited categories are blocked.
  5. Check VDI image contents against the catalog.

Audit Considerations

Unapproved software is both a licensing and a security finding. Assessors correlate CM-10 with malware protection and access control effectiveness on clinical endpoints.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.308(a)(5)(ii)(B) Protection from Malicious Software — restricting software reduces malware introduction.
  • 164.312(a) Access Control — unapproved remote tools can bypass access safeguards.
  • 164.310(b) Workstation Use — procedures for workstation use should define allowed software behaviors.
  • 164.308(a)(1) Risk Management — shadow software that stores ePHI is an enterprise risk.

Compliance Tips

  • Offer fast request path for legitimate new clinical tools so staff do not sideload.
  • Monitor for new AI browser extensions on ePHI workstations.
  • Align CM-10 with CM-7 least functionality.

Frequently Asked Questions

Is CM-10 only about copyright compliance?

Contract/copyright compliance is core, but operationally it also restricts software usage — critical for keeping unapproved apps off ePHI systems.

Do we need allow-listing everywhere?

Risk-based: prioritize clinical workstations, EHR servers, and privileged jump hosts; document alternatives where allow-listing is not yet feasible.

How should we handle physician-preferred apps?

Route through approval, BAA/security review if ePHI is involved, licensing, and catalog onboarding — not silent local installs.

References & Resources

  • NIST SP 800-53 Rev. 5 — CM-10
  • Related controls: CM-7, CM-8, CM-11, SI-3, AC-20

Need Help Implementing CM-10?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.