RA-6 Risk Assessment

Technical Surveillance Countermeasures Survey

Low Risk Moderate Medium Cost

RA-6 requires employing a technical surveillance countermeasures survey at organization-defined locations and frequencies. While not every clinic needs bug sweeps, executive health, behavioral health consult rooms, and board spaces discussing breach strategy may warrant TSCM as risk analysis indicates.

Control Objective

Conduct risk-based technical surveillance countermeasures surveys in defined sensitive locations so illicit listening/monitoring devices do not compromise highly sensitive ePHI or security discussions.

Implementation Guidance

  1. Define which locations warrant TSCM (executive clinic, certain behavioral health, SCIFs-equivalent, incident war rooms).
  2. Set survey frequency and event-driven triggers (before VIP clinics, after suspicious activity).
  3. Use qualified personnel/vendors; document methods and findings.
  4. Protect survey reports as sensitive.
  5. Remediate findings (remove devices, improve physical inspections).
  6. Coordinate with PE-5 monitoring and PE-19 leakage controls.
  7. Train staff on visual inspection for obvious rogue devices in scoped rooms.
  8. Reassess scope annually via RA-3.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

VIP executive physical week

RA-6 sweep of consult suites before a high-profile visit reduces planted device risk for sensitive diagnoses.

Post-incident war room

After a breach, leadership meeting room is surveyed before strategy sessions discussing patient impact details.

Suspicious USB finder in a therapy office

Event-driven TSCM and physical security review expand beyond one device to room integrity checks.

Best Practices

  • Risk-based location list.
  • Scheduled and event-driven surveys.
  • Qualified providers.
  • Protected reports.
  • Remediation tracking.
  • Pair with physical security inspections.

Common Gaps & Violations

  • Claiming TSCM for all closets with no prioritization.
  • Never surveying despite VIP/highly sensitive care.
  • Reports left world-readable.
  • Findings with no remediation.
  • Ignoring obvious rogue devices between formal sweeps.

Required Documentation

  • TSCM / RA-6 procedure
  • In-scope location inventory
  • Survey schedule and trigger criteria
  • Survey reports and remediation records
  • Vendor qualification evidence

How to Test & Validate

  1. Confirm in-scope locations are documented.
  2. Review last survey date vs schedule.
  3. Check remediation of any findings.
  4. Verify report access controls.
  5. Validate event-driven trigger was used when applicable.

Audit Considerations

RA-6 is often not universally applicable; assessors expect a risk-based story. Either scoped surveys with evidence or documented low applicability with rationale.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.530(c) Safeguards — protect PHI from intentional unauthorized disclosure including eavesdropping risks in sensitive care.
  • 164.308(a)(1) Risk Analysis — evaluate likelihood of surveillance threats in context.
  • 164.310(a) Facility Access Controls — physical environment integrity supports confidentiality.
  • 164.312(a) Access Control — technical and physical measures together protect ePHI discussions and displays.

Compliance Tips

  • Scope RA-6 tightly to truly sensitive spaces to keep it credible.
  • Combine with visitor control and room booking hygiene.
  • Store TSCM reports with PE evidence packs.

Frequently Asked Questions

Must every covered entity do bug sweeps?

No. Define locations based on risk; many organizations document limited applicability outside specialized environments.

How often?

Organization-defined — typically scheduled for highest-risk rooms plus event-driven surveys.

Does RA-6 replace PE-5?

No. PE-5 is monitoring physical access; RA-6 is specialized surveillance countermeasures surveying.

References & Resources

  • NIST SP 800-53 Rev. 5 — RA-6
  • Related controls: PE-5, PE-19, RA-3, AT-3

Need Help Implementing RA-6?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.