Fake EHR login SMS
Users with FIDO2 under SC-11-aligned design cannot complete auth on the phishing site — credentials not reusable.
SC-11 requires providing a trusted communications path between the user and security functions of the system. Phishing pages mimicking EHR login and untrusted kiosk browsers undermine assurance that clinicians are authenticating to the real security function protecting ePHI.
Provide trusted paths for authentication and security interactions with ePHI systems so users can distinguish genuine security functions from spoofed interfaces.
How this control shows up in healthcare and HIPAA-covered environments.
Users with FIDO2 under SC-11-aligned design cannot complete auth on the phishing site — credentials not reusable.
Privileged auth moves to PAM trusted path; admins no longer enter EHR AD passwords into random remote tools.
ED kiosks only reach allow-listed IdP/EHR URLs, reducing spoofed login risk.
Trusted path controls reduce credential phishing impact — a top healthcare breach vector. Evidence should show stronger paths for privileged and high-risk ePHI access.
How this NIST control supports HIPAA Security Rule expectations.
Necessary but not sufficient against phishing; binding authenticators and managed paths strengthen SC-11.
Scale to risk; still use TLS, clear branding, and strong auth — deeper trusted path for privileged clinical/admin functions.
IA-2 selects authenticator types; SC-11 ensures the communications path to security functions is trustworthy.
Related controls that commonly accompany SC-11.
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.