SC-13 System and Communications Protection

Cryptographic Protection

High Risk Moderate Medium Cost

SC-13 requires implementing cryptographic uses that comply with applicable federal laws, executive orders, directives, policies, regulations, and standards. In healthcare programs this means using approved, well-configured cryptography for ePHI — TLS, disk encryption, backup encryption, and key management — not home-grown ciphers or leftover weak protocols.

Control Objective

Apply standards-based cryptography with sound key management wherever ePHI or authenticators need confidentiality or integrity protection.

Implementation Guidance

  1. Inventory where crypto is required: disks, backups, databases, TLS endpoints, VPN, email/portal, API tokens, and secrets vaults.
  2. Allow only approved algorithms/protocol versions (e.g., AES-256, TLS 1.2+); ban weak ciphers and obsolete hashes for security uses.
  3. Prefer FIPS-validated modules where policy or contracts require them.
  4. Manage keys/certificates in a vault/HSM/KMS — not spreadsheets or shared drives.
  5. Separate key custody from data custody; rotate and revoke on personnel change or compromise.
  6. Document crypto exceptions with risk acceptance and expiry.
  7. Test restores of encrypted backups (keys must be available to authorized recoverers).
  8. Align SC-13 choices with SC-8 (transit) and CP-9/MP-5 (backup/media).

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Laptop full-disk encryption with recoverable keys

Clinical laptops use BitLocker with keys escrowed in the IdP/MDM. A lost device is wiped; ePHI remains protected and IT can still support legitimate unlocks.

Backup encryption without key chaos

Immutable backups are encrypted, but recovery keys live only with two senior admins in a vault — ransomware cannot both delete backups and possess keys via one compromised account.

API still offering TLS 1.0

Partner portal scan finds weak crypto. SC-13/SC-8 hardening disables legacy protocols before an assessment.

Best Practices

  • Standards-based algorithms only.
  • Central key/certificate management.
  • Dual control for root/key-escrow access.
  • Monitor certificate expiry.
  • Verify encrypted backup recoverability.
  • Document FIPS/module requirements when applicable.

Common Gaps & Violations

  • Proprietary or outdated crypto (RC4, SSL 3.0, SHA-1 signatures).
  • Encryption keys stored next to the ciphertext on the same share.
  • BitLocker without key escrow — bricked devices or shadow IT turn-off.
  • 'Encrypted ZIP' emails with passwords in the same thread.
  • Cloud KMS keys with overly broad IAM.

Required Documentation

  • Cryptographic protection standard (algorithms, protocols, key lifecycle)
  • Inventory of crypto use cases
  • Key/certificate management procedures
  • Exception register
  • Evidence of FIPS/module validation if claimed

How to Test & Validate

  1. TLS-scan critical portals for weak ciphers.
  2. Verify disk encryption compliance on a clinical laptop sample.
  3. Confirm backup encryption and authorized key access path.
  4. Review KMS/vault IAM for least privilege.
  5. Test certificate expiry alerting.

Audit Considerations

HIPAA encryption is addressable; assessors still expect a documented crypto approach. Weak protocols and unmanaged keys are easy findings.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.312(a)(2)(iv) Encryption and Decryption — addressable encryption of ePHI.
  • 164.312(e)(2)(ii) Encryption — addressable encryption for transmission.
  • 164.306 General rules — risk-based decisions must still be reasonable and documented.
  • 164.312(c) Integrity — cryptographic integrity mechanisms may support integrity controls.

Compliance Tips

  • Publish an allow-list of approved ciphers/protocols for vendors.
  • Put certificate expiry in NOC alerts.
  • Treat key escrow as a break-glass process with logging.

Frequently Asked Questions

Does SC-13 require FIPS 140 for every clinic?

Requirements depend on your baseline, contracts, and risk decisions. Many healthcare orgs still mandate strong, standards-based crypto and sound key management even when FIPS modules are not universally forced.

How does SC-13 relate to SC-8?

SC-8 requires protecting transmissions; SC-13 addresses the cryptographic mechanisms used for protection generally (including at rest).

Is encrypting a USB enough?

Encryption helps, but also control issuance, transport (MP-5), and sanitization (MP-6).

References & Resources

  • NIST SP 800-53 Rev. 5 — SC-13
  • FIPS 140 / NIST SP 800-175B crypto guidelines
  • Related controls: SC-8, SC-12, CP-9, IA-5

Need Help Implementing SC-13?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.