Windows imaging workstation EOL
Radiology PCs running an unsupported OS still open studies with ePHI. SA-22 drives segmented VLAN, application allow-listing, and a funded replacement schedule.
SA-22 requires replacing system components when support for the components is no longer available from the developer, vendor, or manufacturer — or providing alternative sources for continued support. Unsupported operating systems under imaging modalities, abandoned interface engines, and EOL antivirus on clinic PCs are classic ePHI risk concentrators.
Identify components that lack vendor support and replace them, or formally provide compensating support and isolation so unsupported technology does not silently undermine ePHI safeguards.
How this control shows up in healthcare and HIPAA-covered environments.
Radiology PCs running an unsupported OS still open studies with ePHI. SA-22 drives segmented VLAN, application allow-listing, and a funded replacement schedule.
Vendor bankrupt; engine still routes lab results. Alternative support agreement with a specialist firm is documented while migration to a supported broker proceeds.
Device ships with obsolete embedded OS and no patch path. SA-22 acquisition gate blocks network connection until risk review and isolating controls are approved.
Unsupported systems are a favorite assessor finding because patch and vendor response obligations cannot be met. Documented isolation and replacement plans are expected when clinical constraints delay upgrades.
How this NIST control supports HIPAA Security Rule expectations.
Possibly with documented alternative support and compensating controls — air-gap claims must be verified, and removable media risks addressed.
It requires replace or alternative support. Delayed replacement needs formal alternative support and risk treatment, not indefinite neglect.
Yes when the provider ends a product/version you still rely on — migrate or obtain continued support terms before security updates stop.
Related controls that commonly accompany SA-22.
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.