SC-11 System and Communications Protection

Trusted Path

High Risk Complex Medium Cost

SC-11 requires providing a trusted communications path between the user and security functions of the system. Phishing pages mimicking EHR login and untrusted kiosk browsers undermine assurance that clinicians are authenticating to the real security function protecting ePHI.

Control Objective

Provide trusted paths for authentication and security interactions with ePHI systems so users can distinguish genuine security functions from spoofed interfaces.

Implementation Guidance

  1. Use organization-managed devices/browsers for high-assurance EHR admin and clinical auth where feasible.
  2. Deploy phishing-resistant authenticators (FIDO2/smartcard) that bind to real services.
  3. Prefer IdP with clear TLS identity and certificate pinning in managed apps.
  4. Avoid embedding credentials in untrusted web views.
  5. Educate workforce on verifying URLs/certs for EHR login.
  6. For privileged tasks, require PAM tools that broker trusted paths.
  7. Harden kiosk browsers allow-lists to official auth endpoints.
  8. Monitor for lookalike domains targeting the health system.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Fake EHR login SMS

Users with FIDO2 under SC-11-aligned design cannot complete auth on the phishing site — credentials not reusable.

Admin password typed into helpdesk tool

Privileged auth moves to PAM trusted path; admins no longer enter EHR AD passwords into random remote tools.

Kiosk browser lockdown

ED kiosks only reach allow-listed IdP/EHR URLs, reducing spoofed login risk.

Best Practices

  • Phishing-resistant auth for high risk.
  • Managed devices for privileged auth.
  • PAM trusted paths for admins.
  • Kiosk URL allow-lists.
  • Lookalike domain monitoring.
  • User verification guidance.

Common Gaps & Violations

  • Password-only auth easily phished.
  • Privileged passwords entered into unknown tools.
  • Open kiosks with arbitrary browsing before EHR.
  • No brand/URL verification training.
  • Ignoring mobile deep-link phishing.

Required Documentation

  • Trusted path standard (SC-11)
  • Auth architecture for privileged/clinical access
  • PAM and FIDO deployment evidence
  • Kiosk allow-list configs
  • Anti-phishing monitoring samples

How to Test & Validate

  1. Review privileged auth path (PAM/FIDO).
  2. Test kiosk allow-list behavior.
  3. Confirm phishing-resistant MFA coverage for admins.
  4. Review lookalike domain alerts.
  5. Interview staff on how they verify EHR login authenticity.

Audit Considerations

Trusted path controls reduce credential phishing impact — a top healthcare breach vector. Evidence should show stronger paths for privileged and high-risk ePHI access.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.312(d) Person or Entity Authentication — verify identity via trustworthy mechanisms.
  • 164.312(a) Access Control — unique user identification depends on authentic auth channels.
  • 164.308(a)(5) Security Awareness — training supports recognition of fake login paths.
  • 164.308(a)(1) Risk Management — phishing risk requires technical and procedural treatment.

Compliance Tips

  • Prioritize FIDO/smartcards for admins and remote ePHI access.
  • Broker all privileged EHR admin through PAM.
  • Publish the only official login URLs prominently.

Frequently Asked Questions

Is HTTPS alone a trusted path?

Necessary but not sufficient against phishing; binding authenticators and managed paths strengthen SC-11.

Does every patient portal need SC-11 military-style trusted path?

Scale to risk; still use TLS, clear branding, and strong auth — deeper trusted path for privileged clinical/admin functions.

How related to IA-2?

IA-2 selects authenticator types; SC-11 ensures the communications path to security functions is trustworthy.

References & Resources

  • NIST SP 800-53 Rev. 5 — SC-11
  • Related controls: IA-2, IA-8, AC-6, SC-23, AT-2

Need Help Implementing SC-11?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.