Unpatched VPN appliance
External scan finds a critical VPN CVE. RA-5 triage patches within 48 hours and verifies with a rescans — closing a common ransomware entry path.
RA-5 requires scanning for vulnerabilities in the system and hosted applications on a defined frequency and when new vulnerabilities potentially affecting the system are identified; employing scan tools that facilitate interoperability and automation; analyzing results; remediating legitimate vulnerabilities based on risk; and sharing results with designated personnel. Scans operationalize continuous discovery of weaknesses that threaten ePHI.
Discover, analyze, and drive remediation of technical vulnerabilities on systems that support ePHI before attackers exploit them.
How this control shows up in healthcare and HIPAA-covered environments.
External scan finds a critical VPN CVE. RA-5 triage patches within 48 hours and verifies with a rescans — closing a common ransomware entry path.
Authenticated discovery finds an old IIS host with ePHI reports. It is patched or decommissioned and added to CM inventory.
Monthly authenticated scans show recurring Java vulnerabilities on nursing PCs; SI-2 packaging remediates at scale.
Assessors look for ongoing scanning and closure evidence. A single annual scan without remediation fails RA-5 intent and weakens HIPAA risk management.
How this NIST control supports HIPAA Security Rule expectations.
RA-5 is vulnerability scanning. Penetration testing is often additional (e.g., CA-8) and valuable, but not a substitute for ongoing scanning.
Many need special handling; document compensating controls and vendor constraints — do not leave them invisible in the risk program.
RA-5 finds issues; SI-2 remediates flaws/patches on a controlled process.
Related controls that commonly accompany RA-5.
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.