Portal session cookie theft
Secure cookie flags and short idle timeout under SC-23 limit replay from a stolen laptop browser.
SC-23 requires protecting the authenticity of communications sessions. Stolen cookies, missing secure flags, and session fixation against patient portals or EHR web UIs enable account takeover without guessing passwords — directly exposing ePHI.
Ensure sessions that access ePHI are uniquely established, integrity-protected, and invalidated appropriately so attackers cannot hijack or replay authentic sessions.
How this control shows up in healthcare and HIPAA-covered environments.
Secure cookie flags and short idle timeout under SC-23 limit replay from a stolen laptop browser.
EHR admin elevation regenerates session ID to prevent fixation.
Token expiry and revocation stop a departed BA integration from reading ePHI.
Session attacks bypass password controls. Assessors and pen testers routinely check cookie flags and logout behavior on healthcare apps.
How this NIST control supports HIPAA Security Rule expectations.
MFA helps at login; session authenticity protects the post-login channel from hijack/replay.
Those terminate sessions/connections; SC-23 ensures the session that exists is authentic and protected.
Yes — protect client-server session tokens/keys similarly.
Related controls that commonly accompany SC-23.
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.