Patient portal cert expires
Monitoring under SC-17 alerts 30 days out; renewal prevents users bypassing warnings or falling back insecurely.
SC-17 requires issuing public key certificates under an appropriate certificate policy or obtaining certificates from an approved service provider. Expired portal certificates, unmanaged device certs, and shadow private CAs break encryption and trust for ePHI services.
Issue and manage PKI certificates used to protect ePHI under documented certificate policy — covering issuance, validation, revocation, and renewal so trust does not silently expire or go rogue.
How this control shows up in healthcare and HIPAA-covered environments.
Monitoring under SC-17 alerts 30 days out; renewal prevents users bypassing warnings or falling back insecurely.
Rogue CA discovered issuing intranet certs. SC-17 approved CA list and trust store hardening remove it.
Clinical PCs receive managed certs with renewal aligned to IA-11 device auth.
Certificate failures cause both outages and security bypasses. SC-17 evidence should show managed life cycle — not heroic last-minute renewals.
How this NIST control supports HIPAA Security Rule expectations.
Not required — using approved public CAs or managed PKI services can satisfy SC-17 if under documented policy.
If allowed by certificate policy and operationally managed — automation is a strength.
SC-12 is broader key management; SC-17 focuses on public key certificates issuance/management under policy.
Related controls that commonly accompany SC-17.
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.