Nursing PC forced through validating resolvers
Floor workstations use only hospital validating resolvers; attempts to set 8.8.8.8 via local config are blocked by GPO/MDM, reducing DNS spoof paths to the EHR.
SC-21 requires recursive or caching resolvers to perform data origin authentication and integrity verification when resolving names (typically DNSSEC validation) and to handle validation failures in a defined way. Clinical endpoints that trust open or non-validating resolvers can be steered to malicious EHR lookalikes, rogue update servers, or attacker-controlled APIs.
Ensure organizational recursive/caching resolvers used by ePHI systems authenticate and integrity-check resolution data and fail closed per policy when validation fails.
How this control shows up in healthcare and HIPAA-covered environments.
Floor workstations use only hospital validating resolvers; attempts to set 8.8.8.8 via local config are blocked by GPO/MDM, reducing DNS spoof paths to the EHR.
A forged signed-looking response fails validation; SC-21 resolvers return failure instead of quietly resolving to an attacker IP hosting a credential harvester.
PACS modalities use approved recursive services so study send destinations resolve consistently and securely during overnight batches.
Ask where nursing stations resolve names. If the answer is \"whatever the ISP or public DNS returns,\" SC-21 is not operating for ePHI workstations.
How this NIST control supports HIPAA Security Rule expectations.
SC-20 secures authoritative sources; SC-21 secures recursive/caching resolvers that clients use.
Yes if it provides required authentication/integrity properties, is covered by BA/contract as needed, and clinical egress is forced through it.
Document exception, compensating controls, and remediation timeline—do not disable validation enterprise-wide.
Related controls that commonly accompany SC-21.
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.