SC-19 System and Communications Protection

Voice Over Internet Protocol

Medium Risk Moderate Medium Cost

SC-19 requires establishing usage restrictions and implementing security measures for VoIP technologies. Clinical VoIP, softphones, and call-center systems routinely discuss diagnoses and demographics — misconfigured trunks, unencrypted signaling, and voicemail left unmanaged become ePHI disclosure paths.

Control Objective

Establish and enforce security requirements for VoIP and related telephony so clinical voice communications involving ePHI are authenticated, protected in transit where feasible, and monitored for abuse.

Implementation Guidance

  1. Inventory VoIP systems used for care coordination, call centers, and telehealth audio.
  2. Define acceptable use and prohibited practices (forwarding to personal phones without controls).
  3. Encrypt signaling/media where supported; segment voice VLANs.
  4. Harden PBX admin interfaces (SC-2 style separation).
  5. Control voicemail retention and access; treat as potential ePHI store.
  6. Authenticate endpoints; prevent toll fraud and trunk abuse.
  7. Include softphones on mobile under MDM.
  8. Log admin changes and anomalous call patterns.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Call center voicemail full of PHI

Retention and access controls under SC-19 limit who can export voicemail boxes containing patient return calls.

Softphone on unmanaged phone

Policy requires MDM container for softphones used to discuss ePHI.

Flat voice VLAN bridged to EHR

Segmentation redesign isolates voice from data where architecture allows, reducing lateral movement risk.

Best Practices

  • VoIP acceptable use policy.
  • Encrypt/segment where feasible.
  • Harden PBX admin.
  • Voicemail as ePHI store.
  • MDM for softphones.
  • Monitor fraud/anomalies.

Common Gaps & Violations

  • Open PBX admin from internet.
  • Unmanaged softphones.
  • Voicemail never purged.
  • Voice and data flat network.
  • No logging of trunk changes.

Required Documentation

  • VoIP security standard (SC-19)
  • Inventory of voice systems
  • Encryption/segmentation evidence
  • Voicemail retention/access procedures
  • Softphone MDM requirements

How to Test & Validate

  1. Review PBX admin exposure and auth.
  2. Sample voicemail access controls.
  3. Verify softphone MDM enforcement.
  4. Check voice VLAN segmentation.
  5. Review anomalous call alerts.

Audit Considerations

Voice is often forgotten in HIPAA technical inventories. SC-19 brings telephony into the same discipline as other ePHI systems.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.312(e) Transmission Security — protect ePHI transmitted over electronic networks including voice systems when in scope.
  • 164.530(c) Safeguards — reasonable safeguards for oral PHI disclosures via telephony.
  • 164.310(d) Device and Media Controls — voicemail storage can be electronic media with PHI.
  • 164.312(a) Access Control — limit admin and mailbox access.

Compliance Tips

  • Add VoIP to the ePHI system inventory if not already.
  • Treat voicemail exports like file extracts.
  • Lock down PBX admin with MFA and allow-lists.

Frequently Asked Questions

Is analog phone out of SC-19?

SC-19 targets VoIP technologies; still apply privacy reasonable safeguards for oral PHI on any phone.

Must all calls be recorded encrypted?

If you record, protect recordings as ePHI; encryption and access control apply to stored call data.

How related to SC-15?

SC-15 covers collaborative devices (mics/cameras); SC-19 focuses on VoIP technology controls.

References & Resources

  • NIST SP 800-53 Rev. 5 — SC-19
  • Related controls: SC-8, SC-7, AC-19, AU-2, SC-15

Need Help Implementing SC-19?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.