Shared med-surg workstation
Thin clients boot to non-persistent VDI; when the shift ends, local disk holds no chart cache—reducing ePHI exposure if the device is stolen from an unlocked alcove.
SC-25 calls for employing thin nodes (e.g., diskless workstations, thin clients, or equivalently minimized endpoints) for specific system components so little information is stored locally. In clinics and nursing units, fat PCs accumulate cached charts, downloads, and credentials; thin/VDI architectures reduce the blast radius of lost, stolen, or malware-ridden floor devices that touch ePHI.
Use thin or state-minimized endpoints for designated clinical and administrative access paths so ePHI and secrets are not persistently stored on local workstation disks.
How this control shows up in healthcare and HIPAA-covered environments.
Thin clients boot to non-persistent VDI; when the shift ends, local disk holds no chart cache—reducing ePHI exposure if the device is stolen from an unlocked alcove.
ROI staff work in streamed desktops; downloads land in controlled server shares with DLP, not on a fat PC under the desk.
Temporary reviewers receive thin/VDI only—no local EHR install—so contract end does not leave residual patient data on personal hardware.
SC-25 is about minimizing local residual data. Assessors may sample floor PCs for cached ePHI and compare to the stated thin-node architecture.
How this NIST control supports HIPAA Security Rule expectations.
No—diskless or highly minimized nodes qualify; the intent is minimal local retention of information.
SC-25 applies to organization-defined components. Scope thin nodes where shared/high-risk; document other endpoint strategies (encryption, MDM) elsewhere.
Thin nodes often sit behind stronger boundary and brokered access patterns that complement boundary protection.
Related controls that commonly accompany SC-25.
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.