Physician installs consumer screen-sharing
A doctor adds a free remote tool to a laptop with cached clinic mail and VPN. CM-11 technical blocks stop the install; an approved telehealth/support tool is offered instead.
CM-11 requires establishing policies governing the installation of software by users; enforcing those policies through technical methods when supported; and monitoring policy compliance on a defined frequency. Clinicians installing remote-support tools, browser extensions, or personal cloud sync on ePHI workstations is a persistent healthcare threat path for ransomware and unauthorized disclosure.
Prevent unauthorized software from being installed or executed on systems that access ePHI — through policy, technical enforcement, and ongoing monitoring.
How this control shows up in healthcare and HIPAA-covered environments.
A doctor adds a free remote tool to a laptop with cached clinic mail and VPN. CM-11 technical blocks stop the install; an approved telehealth/support tool is offered instead.
Allowlisting and extension control under CM-11 prevent a malicious extension from riding on patient-portal admin browsers.
Monitoring finds a nursing station with a portable executable toolkit. Local admin rights are removed and the image is rebuilt — demonstrating CM-11 monitoring frequency.
Assessors ask how you stop unauthorized software on ePHI workstations. Policy without enforcement (local admin for all) fails CM-11 in practice.
How this NIST control supports HIPAA Security Rule expectations.
It requires a governing policy and enforcement. Some roles may install within approved catalogs; unmanaged free-for-all is out of bounds for ePHI endpoints.
CM-7 limits services/functions/components; CM-11 specifically governs user-driven software installation behavior and monitoring.
Offer a rapid vetted request path — friction that is too high drives dangerous workarounds.
Related controls that commonly accompany CM-11.
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.