Backup encryption key on the same NAS
Nightly EHR dumps are “encrypted,” but the key file sits next to the tarballs. SC-12 moves keys to a vault with audited access and offline recovery escrow.
SC-12 requires establishing and managing cryptographic keys when cryptography is employed within the system in accordance with organization-defined requirements for key generation, distribution, storage, access, and destruction. Healthcare often encrypts EHR databases, backups, and VPN tunnels — then stores keys beside the data or shares them in ticket comments.
Manage the full life cycle of cryptographic keys that protect ePHI so keys are generated, stored, rotated, accessed, and destroyed with least privilege and recoverable custody.
How this control shows up in healthcare and HIPAA-covered environments.
Nightly EHR dumps are “encrypted,” but the key file sits next to the tarballs. SC-12 moves keys to a vault with audited access and offline recovery escrow.
No inventory or rotation calendar. SC-12 establishes cert life-cycle ownership so portal availability and encrypted transit do not fail together.
Security selects customer-managed keys for a analytics warehouse holding limited data sets derived from ePHI, with rotation and IAM boundaries documented under SC-12.
HIPAA addressable encryption is weak if keys are unmanaged. Assessors increasingly ask where keys live, who can export them, and how recovery works without single-person dependency.
How this NIST control supports HIPAA Security Rule expectations.
It can be part of the model, but you must still define how access to decrypt, key policy, and organizational responsibilities are managed and documented.
Follow your crypto standard and risk — define frequencies per key type (TLS certs, data-encryption keys, VPN) and always rotate on compromise.
Not universally; use risk-based protection (HSM/KMS/vault). High-value master keys protecting large ePHI stores warrant stronger custody.
Related controls that commonly accompany SC-12.
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.