EHR cutover CNAME hijack risk
During an Epic/Cerner cutover, only PAM-approved DNS admins can publish the new EHR aliases; SC-20 integrity controls and change tickets prevent an unauthorized CNAME from diverting clinicians to a lookalike host.
SC-20 requires that authoritative name/address resolution services provide data origin authentication and integrity verification (commonly via DNSSEC or equivalent trusted resolution controls) so clients can trust answers from organizational authoritative sources. In healthcare, poisoned or rogue authoritative data can silently redirect EHR, VPN, telehealth, and partner interface traffic carrying ePHI.
Protect authoritative DNS (and equivalent name/address services) that publish healthcare zones so resolved names for ePHI systems are authentic and integrity-protected.
How this control shows up in healthcare and HIPAA-covered environments.
During an Epic/Cerner cutover, only PAM-approved DNS admins can publish the new EHR aliases; SC-20 integrity controls and change tickets prevent an unauthorized CNAME from diverting clinicians to a lookalike host.
A clearinghouse SFTP hostname is served from the health system’s authoritative zone with DNSSEC so billing interfaces do not accept silently altered address data.
Patient-facing telehealth names remain under signed authoritative control so phishing sites cannot easily ride on unauthorized zone edits from a compromised DNS console.
Assessors look for whether name services that steer ePHI traffic are integrity-protected and tightly administered—not only whether \"DNS exists.\"
How this NIST control supports HIPAA Security Rule expectations.
NIST emphasizes origin authentication and integrity for authoritative sources; DNSSEC is the common mechanism—document equivalents if used.
SC-20 focuses on authoritative sources; SC-21 addresses recursive/caching resolvers.
Yes, when they publish names for systems that create, receive, maintain, or transmit ePHI.
Related controls that commonly accompany SC-20.
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.