IA-11 Identification and Authentication

Device Identification and Authentication

High Risk Complex Medium Cost

IA-11 requires uniquely identifying and authenticating devices before establishing connections where organization policy requires device identity. In healthcare, unmanaged personal laptops, rogue IoT, and cloned biomedical hosts reaching EHR VLANs create ePHI exposure beyond user credentials alone.

Control Objective

Identify and authenticate devices that connect to ePHI networks or applications according to risk — so access depends on trusted device posture, not only a stolen password.

Implementation Guidance

  1. Define which networks/apps require device authentication (EHR VLANs, VPN to clinical systems, privileged admin paths).
  2. Deploy device identity via certificates, MDM enrollment, or 802.1X as appropriate.
  3. Inventory clinical devices (CM-8) and decide authentication methods that biomed can support.
  4. Block or quarantine unknown devices on sensitive segments.
  5. Prefer mutual TLS or device certs for service-to-service and high-risk endpoints.
  6. Integrate device compliance (patch, disk encryption) into auth decisions where feasible.
  7. Cover remote clinicians and BA support devices accessing ePHI.
  8. Review exceptions (legacy modalities) with compensating segmentation.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Rogue PC on the nursing VLAN

An unknown laptop plugs into a wall jack. 802.1X under IA-11 denies access until IT provisions a cert — EHR is unreachable to strangers.

VPN without device check

Stolen clinician credentials work from any cafe PC. IA-11 adds device certificate or MDM compliance for VPN to ePHI apps.

Infusion pump network join

New pumps require device identity in NAC profiling before clinical VLAN placement, reducing impersonation of trusted biomed assets.

Best Practices

  • Risk-based device authN requirements.
  • Certificates/MDM for endpoints accessing ePHI.
  • NAC on clinical VLANs.
  • Document legacy device exceptions.
  • Pair with IA-2 user MFA.
  • Include BA remote support paths.

Common Gaps & Violations

  • Open clinical jacks with no device auth.
  • VPN equals password only from any device.
  • Medical devices using shared generic identities without oversight.
  • Shadow IoT on the same VLAN as EHR.
  • No process for lost/stolen device cert revocation.

Required Documentation

  • Device identification and authentication policy (IA-11)
  • Scope of networks/apps requiring device authN
  • Certificate/MDM/NAC standards
  • Legacy exception register
  • Revocation procedures for lost devices

How to Test & Validate

  1. Attempt unknown device on a clinical jack (authorized test); confirm deny/quarantine.
  2. Verify VPN to ePHI requires device factor where policy says so.
  3. Sample device cert issuance and revocation.
  4. Review legacy modality exceptions and segmentation.
  5. Confirm BA support devices are in scope or isolated.

Audit Considerations

Device identity gaps explain many lateral-movement incidents. Assessors look for more than user MFA when clinical networks are flat.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.312(a) Access Control — limit access to authorized persons and software processes; device trust supports that limit.
  • 164.312(d) Person or Entity Authentication — entity can include devices establishing connections.
  • 164.308(a)(1) Risk Management — unmanaged device risk requires treatment.
  • 164.312(e) Transmission Security — authenticated devices reduce unauthorized network paths to ePHI.

Compliance Tips

  • Start IA-11 on EHR and privileged admin paths before low-risk guest networks.
  • Give clinical engineering a clear onboarding path for new networked devices.
  • Monitor for certificate expiry on critical clinical endpoints.

Frequently Asked Questions

Is IA-11 the same as IA-3?

Closely related in intent; implement the requirement your catalog assigns and map healthcare device types explicitly.

Can we rely only on MAC allow-lists?

MAC spoofing is trivial; prefer cryptographic device identity where risk to ePHI is high.

Do personal mobile devices need IA-11?

If they access ePHI, apply MDM/container and device compliance as your device authentication model.

References & Resources

  • NIST SP 800-53 Rev. 5 — IA-11
  • Related controls: IA-3, IA-4, AC-19, CM-8, SC-7

Need Help Implementing IA-11?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.