SC-18 System and Communications Protection

Mobile Code

High Risk Moderate Low Cost

SC-18 requires defining acceptable mobile code, authorizing usage, and monitoring usage of mobile code technologies. Clinical workstations that run arbitrary browser macros, outdated Java, or office macros are recurring malware entry points to ePHI environments.

Control Objective

Define, authorize, and monitor mobile code technologies on ePHI-capable systems so only accepted active content runs — reducing malware and data-exfil pathways.

Implementation Guidance

  1. Inventory mobile code technologies in use (browser scripts, macros, Java, Flash legacy, email active content).
  2. Publish accept/deny policy for clinical vs admin systems.
  3. Harden browsers and office macro settings via enterprise policy.
  4. Block unnecessary plugins on EHR workstations.
  5. Prefer curated enterprise apps over random downloaded active content.
  6. Monitor detections of blocked mobile code/malware loaders.
  7. Exception process for legacy clinical apps needing special runtimes.
  8. Align with SI-3 malicious code protections.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Macro malware in billing email

Office macro blocks under SC-18 stop the loader on revenue-cycle PCs with ePHI access.

Legacy Java for a PACS viewer

Documented exception isolates the viewer and blocks Java elsewhere on the clinical image.

Browser drive-by on nursing station

Hardened browser and allow-listed extensions reduce drive-by mobile code execution.

Best Practices

  • Written acceptable mobile code policy.
  • Enterprise hardening baselines.
  • Block macros by default.
  • Monitor blocks/detections.
  • Time-boxed legacy exceptions.
  • Pair with SI-3.

Common Gaps & Violations

  • Macros enabled org-wide.
  • Random browser plugins on EHR PCs.
  • Java installed everywhere for one app.
  • No monitoring of blocks.
  • Exceptions without expiry.

Required Documentation

  • Mobile code policy (SC-18)
  • Hardening baselines for OS/office/browser
  • Exception register
  • Monitoring/report samples
  • Legacy isolation designs

How to Test & Validate

  1. Review macro and browser policy settings on clinical images.
  2. Sample exceptions for isolation and expiry.
  3. Check monitoring of blocked content.
  4. Verify Java/plugin footprint minimized.
  5. Correlate with recent malware incidents involving mobile code.

Audit Considerations

Mobile code remains a top initial access method. SC-18 should show deliberate allow/deny governance on systems that can reach ePHI.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.308(a)(5)(ii)(B) Protection from Malicious Software — procedures for guarding against malware including via active content.
  • 164.312(a) Access Control — malware can subvert access controls to ePHI.
  • 164.308(a)(1) Risk Management — mobile code risk requires treatment.
  • 164.306 Integrity and availability — malicious mobile code threatens both.

Compliance Tips

  • Default-deny office macros on ePHI workstations.
  • Isolate legacy clinical runtimes.
  • Review browser extension allow-lists quarterly.

Frequently Asked Questions

Is JavaScript banned under SC-18?

No — define acceptable use; modern web EHR needs scripts, but harden and limit risky sources/plugins.

Do mobile apps count as mobile code?

SC-18 historically targets downloadable active content; manage mobile apps primarily under AC-19/MDM while still restricting risky active content.

How related to CM-7?

CM-7 least functionality complements SC-18 by removing unneeded code frameworks.

References & Resources

  • NIST SP 800-53 Rev. 5 — SC-18
  • Related controls: SI-3, CM-7, AC-19, SC-7, SI-8

Need Help Implementing SC-18?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.