Laptop full-disk encryption with recoverable keys
Clinical laptops use BitLocker with keys escrowed in the IdP/MDM. A lost device is wiped; ePHI remains protected and IT can still support legitimate unlocks.
SC-13 requires implementing cryptographic uses that comply with applicable federal laws, executive orders, directives, policies, regulations, and standards. In healthcare programs this means using approved, well-configured cryptography for ePHI — TLS, disk encryption, backup encryption, and key management — not home-grown ciphers or leftover weak protocols.
Apply standards-based cryptography with sound key management wherever ePHI or authenticators need confidentiality or integrity protection.
How this control shows up in healthcare and HIPAA-covered environments.
Clinical laptops use BitLocker with keys escrowed in the IdP/MDM. A lost device is wiped; ePHI remains protected and IT can still support legitimate unlocks.
Immutable backups are encrypted, but recovery keys live only with two senior admins in a vault — ransomware cannot both delete backups and possess keys via one compromised account.
Partner portal scan finds weak crypto. SC-13/SC-8 hardening disables legacy protocols before an assessment.
HIPAA encryption is addressable; assessors still expect a documented crypto approach. Weak protocols and unmanaged keys are easy findings.
How this NIST control supports HIPAA Security Rule expectations.
Requirements depend on your baseline, contracts, and risk decisions. Many healthcare orgs still mandate strong, standards-based crypto and sound key management even when FIPS modules are not universally forced.
SC-8 requires protecting transmissions; SC-13 addresses the cryptographic mechanisms used for protection generally (including at rest).
Encryption helps, but also control issuance, transport (MP-5), and sanitization (MP-6).
Related controls that commonly accompany SC-13.
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.