SC-10 System and Communications Protection

Network Disconnect

Medium Risk Easy Low Cost

SC-10 requires terminating the network connection associated with a communications session at the end of the session or after organization-defined inactivity/conditions. Idle VPN tunnels and lingering partner connections keep pathways open to ePHI longer than needed.

Control Objective

Disconnect network sessions supporting access to ePHI when sessions end or inactivity/conditions are met — reducing lingering remote and partner exposure.

Implementation Guidance

  1. Define disconnect timers for VPN, admin SSH/RDP, and partner tunnels to ePHI environments.
  2. Configure concentrators and firewalls to drop idle sessions.
  3. Align application session timeout (AC-12) with network disconnect policies.
  4. Apply stricter timers for privileged and vendor sessions.
  5. Log disconnect events for audit correlation.
  6. Exempt only carefully justified clinical real-time links with monitoring.
  7. Test that disconnects do not unsafely interrupt life-critical persistent device sessions — scope carefully.
  8. Review timers annually.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Idle vendor VPN overnight

SC-10 idle timeout drops OEM tunnel; morning JIT reapproval required — no standing overnight path to pumps/EHR.

Clinician VPN left connected at cafe

Inactivity disconnect limits exposure from a forgotten laptop session.

Partner SFTP session hang

Firewall idle policy closes stale file-transfer sessions carrying claim files.

Best Practices

  • Idle disconnect on VPN/admin paths.
  • Stricter for vendors/privileged.
  • Align with app timeouts.
  • Log disconnects.
  • Careful exceptions for clinical devices.
  • Annual timer review.

Common Gaps & Violations

  • VPN never times out.
  • Vendor tunnels permanent.
  • App timeout without network disconnect.
  • No logs of session ends.
  • Blanket exceptions for convenience.

Required Documentation

  • Network disconnect standard (SC-10)
  • Timer settings by connection type
  • Configuration evidence from VPN/firewalls
  • Exception register
  • Log samples

How to Test & Validate

  1. Verify VPN idle timers on production concentrators.
  2. Confirm vendor sessions disconnect.
  3. Correlate AC-12 app timeouts with SC-10.
  4. Review exceptions for clinical persistence.
  5. Sample disconnect logs.

Audit Considerations

Lingering network sessions are easy wins for attackers with stolen credentials. SC-10 is straightforward to test on VPN and partner links.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.312(a)(2)(iii) Automatic Logoff — pair network disconnect with session logoff for ePHI access.
  • 164.312(a) Access Control — limit the window of access to ePHI.
  • 164.312(e) Transmission Security — reduce unauthorized use of open transmission paths.
  • 164.308(a)(1) Risk Management — idle remote access is a known risk.

Compliance Tips

  • Set vendor VPN idle timers aggressively.
  • Monitor for sessions that never disconnect (misconfig).
  • Document clinical device exceptions with owners.

Frequently Asked Questions

How is SC-10 different from AC-12?

AC-12 is session termination at the application/logical session; SC-10 terminates the network connection associated with communications sessions.

Will SC-10 break HL7 interfaces?

Persistent interfaces need designed keepalives/exceptions — do not blindly apply end-user VPN timers to message engines.

What timeout value?

Organization-defined based on risk; privileged/vendor usually shorter than general workforce.

References & Resources

  • NIST SP 800-53 Rev. 5 — SC-10
  • Related controls: AC-12, AC-17, AC-11, SC-23, IA-11

Need Help Implementing SC-10?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.