Primary DNS VM dies at 07:00
Secondary recursive resolvers on another host/AZ continue serving nursing stations; EHR open is delayed seconds, not hours—SC-22 redundancy earns its keep.
SC-22 requires that name/address resolution services be architected and provisioned to be fault-tolerant and to implement role separation (commonly separating authoritative and recursive functions) as appropriate. Healthcare outages often cascade when DNS is a single point of failure: EHR login, badge door integrations, lab instruments, and cloud connectors all stop when resolution fails.
Design and provision DNS/name services supporting ePHI operations with redundancy, capacity, and logical separation of authoritative vs recursive roles.
How this control shows up in healthcare and HIPAA-covered environments.
Secondary recursive resolvers on another host/AZ continue serving nursing stations; EHR open is delayed seconds, not hours—SC-22 redundancy earns its keep.
Compromise attempt against a recursive node does not automatically grant zone-signing keys hosted only on hardened authoritative primaries.
DR runbook includes bringing up resolution services before EHR database mount so clinicians are not pointed at stale production IPs.
SC-22 is architecture evidence: diagrams, dual nodes, and DR steps—not a single checkbox for \"DNSSEC on.\"
How this NIST control supports HIPAA Security Rule expectations.
It can be, if provisioned with fault tolerance, clear failure modes, and clinical path testing—document it as the architecture.
SC-20/21 secure the data; SC-22 ensures the service is resilient and properly structured.
Yes—most EHR hostnames live on internal resolution services.
Related controls that commonly accompany SC-22.
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.