SC-17 System and Communications Protection

Public Key Infrastructure Certificates

High Risk Moderate Medium Cost

SC-17 requires issuing public key certificates under an appropriate certificate policy or obtaining certificates from an approved service provider. Expired portal certificates, unmanaged device certs, and shadow private CAs break encryption and trust for ePHI services.

Control Objective

Issue and manage PKI certificates used to protect ePHI under documented certificate policy — covering issuance, validation, revocation, and renewal so trust does not silently expire or go rogue.

Implementation Guidance

  1. Establish certificate policy/practices for TLS, VPN, device, and code-signing certs affecting ePHI.
  2. Inventory certificates and owners (pair SC-12).
  3. Automate renewal/monitoring to prevent expiry outages and insecure fallbacks.
  4. Define approved CAs (public and private).
  5. Implement revocation checking where applicable.
  6. Protect private keys (HSM/KMS/ACLs).
  7. Prohibit unmanaged self-signed certs on public ePHI services.
  8. Include partner certificates in interface inventories.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Patient portal cert expires

Monitoring under SC-17 alerts 30 days out; renewal prevents users bypassing warnings or falling back insecurely.

Shadow internal CA

Rogue CA discovered issuing intranet certs. SC-17 approved CA list and trust store hardening remove it.

Device certs for 802.1X

Clinical PCs receive managed certs with renewal aligned to IA-11 device auth.

Best Practices

  • Certificate policy and inventory.
  • Automated expiry monitoring.
  • Approved CA list.
  • Protected private keys.
  • Revocation process.
  • No unmanaged public self-signed for ePHI.

Common Gaps & Violations

  • Spreadsheet inventory outdated.
  • Surprise portal expiry.
  • Self-signed on public sites.
  • Private keys in ticket attachments.
  • Trusting all private CAs enterprise-wide.

Required Documentation

  • Certificate policy/practices (SC-17)
  • Certificate inventory with owners
  • Monitoring/renewal evidence
  • Approved CA list
  • Key protection standards

How to Test & Validate

  1. Review inventory completeness for public ePHI sites.
  2. Verify expiry monitoring alerts.
  3. Check approved CA enforcement.
  4. Sample private key storage controls.
  5. Confirm partner interface cert tracking.

Audit Considerations

Certificate failures cause both outages and security bypasses. SC-17 evidence should show managed life cycle — not heroic last-minute renewals.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.312(e)(2)(ii) Encryption — certificates enable transmission encryption for ePHI.
  • 164.312(a) Access Control — mutual TLS and device certs support access decisions.
  • 164.308(a)(7) Contingency — cert expiry can cause availability incidents.
  • 164.306 Confidentiality — PKI underpins confidentiality protections in transit.

Compliance Tips

  • Centralize certificates in a management platform.
  • Page owners 30/14/7 days before expiry.
  • Ban ad-hoc public self-signed via policy and scanning.

Frequently Asked Questions

Must we run our own CA?

Not required — using approved public CAs or managed PKI services can satisfy SC-17 if under documented policy.

Are Let's Encrypt certs acceptable?

If allowed by certificate policy and operationally managed — automation is a strength.

How related to SC-12?

SC-12 is broader key management; SC-17 focuses on public key certificates issuance/management under policy.

References & Resources

  • NIST SP 800-53 Rev. 5 — SC-17
  • Related controls: SC-12, SC-13, IA-5, CM-8, SC-8

Need Help Implementing SC-17?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.