Rogue PC on the nursing VLAN
An unknown laptop plugs into a wall jack. 802.1X under IA-11 denies access until IT provisions a cert — EHR is unreachable to strangers.
IA-11 requires uniquely identifying and authenticating devices before establishing connections where organization policy requires device identity. In healthcare, unmanaged personal laptops, rogue IoT, and cloned biomedical hosts reaching EHR VLANs create ePHI exposure beyond user credentials alone.
Identify and authenticate devices that connect to ePHI networks or applications according to risk — so access depends on trusted device posture, not only a stolen password.
How this control shows up in healthcare and HIPAA-covered environments.
An unknown laptop plugs into a wall jack. 802.1X under IA-11 denies access until IT provisions a cert — EHR is unreachable to strangers.
Stolen clinician credentials work from any cafe PC. IA-11 adds device certificate or MDM compliance for VPN to ePHI apps.
New pumps require device identity in NAC profiling before clinical VLAN placement, reducing impersonation of trusted biomed assets.
Device identity gaps explain many lateral-movement incidents. Assessors look for more than user MFA when clinical networks are flat.
How this NIST control supports HIPAA Security Rule expectations.
Closely related in intent; implement the requirement your catalog assigns and map healthcare device types explicitly.
MAC spoofing is trivial; prefer cryptographic device identity where risk to ePHI is high.
If they access ePHI, apply MDM/container and device compliance as your device authentication model.
Related controls that commonly accompany IA-11.
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.