SC-25 System and Communications Protection

Thin Nodes

Medium Risk Moderate High Cost

SC-25 calls for employing thin nodes (e.g., diskless workstations, thin clients, or equivalently minimized endpoints) for specific system components so little information is stored locally. In clinics and nursing units, fat PCs accumulate cached charts, downloads, and credentials; thin/VDI architectures reduce the blast radius of lost, stolen, or malware-ridden floor devices that touch ePHI.

Control Objective

Use thin or state-minimized endpoints for designated clinical and administrative access paths so ePHI and secrets are not persistently stored on local workstation disks.

Implementation Guidance

  1. Identify roles/locations suited to thin clients or VDI (shared nursing stations, HIM, registration, business office).
  2. Prefer non-persistent VDI/desktop sessions for ePHI access; redirect profiles carefully.
  3. Disable local admin and USB mass storage where thin nodes are used (pair with MP-7).
  4. Keep EHR and imaging viewers server-side or streamed; avoid local PST/export caches.
  5. Monitor endpoint compliance (EDR) even on thin devices.
  6. Document exceptions for specialized clinical devices that cannot be thin.
  7. Train staff that "thin" does not mean "no privacy"—shoulder surfing still applies.
  8. Include thin-node images in CM baselines.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Shared med-surg workstation

Thin clients boot to non-persistent VDI; when the shift ends, local disk holds no chart cache—reducing ePHI exposure if the device is stolen from an unlocked alcove.

HIM release desk

ROI staff work in streamed desktops; downloads land in controlled server shares with DLP, not on a fat PC under the desk.

Contractor chart review

Temporary reviewers receive thin/VDI only—no local EHR install—so contract end does not leave residual patient data on personal hardware.

Best Practices

  • Non-persistent sessions for shared clinical seats.
  • Pair with USB and print controls.
  • Exception list for fat clinical specialty devices.
  • Golden images under CM.
  • Still enforce screen lock / AC-2(5).
  • Assess GPU/specialty needs early (PACS).

Common Gaps & Violations

  • Calling any PC "thin" while users save PHI to D:\.
  • Persistent VDI disks full of exports.
  • No plan for PACS diagnostic workstations.
  • Local admin enabled on thin endpoints.
  • Ignoring offline/clinic downtime UX.

Required Documentation

  • Thin node / VDI standard (SC-25)
  • Scope of roles/locations using thin nodes
  • Image and persistence configuration
  • Exception register with risk acceptance
  • Related media and endpoint controls

How to Test & Validate

  1. Inspect a sample thin endpoint for local ePHI files after a session.
  2. Verify non-persistence reset behavior.
  3. Review USB/device control on thin fleet.
  4. Confirm exceptions are approved and limited.
  5. Observe nursing workflow usability to catch shadow IT fat PCs.

Audit Considerations

SC-25 is about minimizing local residual data. Assessors may sample floor PCs for cached ePHI and compare to the stated thin-node architecture.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.310(c) Workstation Security — physical and technical safeguards on workstations that access ePHI.
  • 164.310(b) Workstation Use — policies for proper use; thin architectures support policy.
  • 164.312(a) Access Control — limit access pathways; centralized desktops aid control.
  • 164.310(d) Device and Media Controls — less local media reduces custody burden.

Compliance Tips

  • Map SC-25 to your VDI/thin-client program explicitly in the SSP.
  • Do not claim SC-25 if most clinicians still use unmanaged fat laptops for ePHI.
  • Combine with encryption (SC-28) for any remaining local residual risk.

Frequently Asked Questions

Is VDI the only way to meet SC-25?

No—diskless or highly minimized nodes qualify; the intent is minimal local retention of information.

Do physicians’ fat laptops fail SC-25?

SC-25 applies to organization-defined components. Scope thin nodes where shared/high-risk; document other endpoint strategies (encryption, MDM) elsewhere.

How does this relate to SC-7?

Thin nodes often sit behind stronger boundary and brokered access patterns that complement boundary protection.

References & Resources

  • NIST SP 800-53 Rev. 5 — SC-25
  • Related controls: AC-6, CM-7, MP-7, SC-28, SI-4

Need Help Implementing SC-25?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.