SC-15 System and Communications Protection

Collaborative Computing Devices

Medium Risk Moderate Low Cost

SC-15 requires prohibiting or restricting remote activation of collaborative computing devices and providing physical/logical indicators of activation. Always-on webcams in nursing stations, smart speakers in clinics, and unnoticed open mics during EHR screen shares can disclose ePHI.

Control Objective

Control cameras, microphones, and collaborative devices so they cannot silently capture ePHI — with user-notice of activation and policy for clinical and remote work settings.

Implementation Guidance

  1. Inventory collaborative devices in clinical spaces (webcams, conference mics, smart displays, ambient AI scribes).
  2. Restrict remote activation; require local user consent where allowed.
  3. Provide clear indicators when mic/camera is on.
  4. Policy for telehealth and meeting tools when ePHI is discussed or shown.
  5. Disable or tightly control smart speakers in areas with PHI conversations.
  6. Cover BA ambient documentation devices under BAAs and configuration standards.
  7. Train workforce on mute/cover habits and screen-share hygiene.
  8. Monitor for unauthorized collaborative devices on networks (CM-8).

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Open mic during EHR huddle

Conference device auto-joined muted incorrectly. SC-15 indicators and default-mute policy prevent broadcasting patient names.

Ambient AI scribe rollout

Device inventory, BAA, retention limits, and physical indicators implemented before clinic-wide use.

Remote coder webcam

Policy requires lens covers and no recording of dual monitors showing ePHI during support calls.

Best Practices

  • Inventory collaborative devices.
  • Indicators of activation.
  • Restrict remote activation.
  • Telehealth/meeting hygiene rules.
  • Control ambient AI carefully.
  • Train mute/cover habits.

Common Gaps & Violations

  • Smart speakers in triage halls.
  • Always-on cams without indicators.
  • Unmanaged ambient scribes.
  • Screen sharing entire desktop with PHI inboxes.
  • No inventory of conference devices.

Required Documentation

  • Collaborative device standard (SC-15)
  • Device inventory in clinical areas
  • Configuration baselines (mute, indicators)
  • Telehealth/meeting procedures
  • BAA/config for ambient AI vendors

How to Test & Validate

  1. Tour clinics for unauthorized smart speakers/cams.
  2. Verify activation indicators on approved devices.
  3. Review ambient AI governance evidence.
  4. Observe meeting tool defaults (mute, share).
  5. Check remote work guidance for camera/mic.

Audit Considerations

Collaborative devices are a modern privacy hot spot. Assessors and privacy walkthroughs increasingly ask about cameras, mics, and ambient listening in care settings.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.530(c) Safeguards — reasonable safeguards against intentional/unintentional PHI disclosure.
  • 164.310(b) Workstation Use — physical surroundings of workstations and collaborative devices.
  • 164.308(b) BA requirements — ambient documentation vendors often are BAs.
  • 164.312(a) Access Control — remote activation control limits unauthorized access to audio/video of PHI.

Compliance Tips

  • Default mute cameras/mics on clinic conference devices.
  • Approve ambient AI through privacy + security gate.
  • Add collaborative devices to CM-8 inventory.

Frequently Asked Questions

Does SC-15 ban all webcams?

No — restrict remote activation and provide indicators; allow for telehealth with controls.

Are smartphones in scope?

When used as collaborative computing devices in clinical workflows, apply policy and MDM controls.

How related to PE-19?

PE-19 addresses leakage/emanations broadly; SC-15 focuses on collaborative computing devices specifically.

References & Resources

  • NIST SP 800-53 Rev. 5 — SC-15
  • Related controls: AC-19, CM-8, PE-19, AT-2, SA-9

Need Help Implementing SC-15?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.