SC-26 System and Communications Protection

Honeypots

Medium Risk Complex Medium Cost

SC-26 addresses employing honeypots (deception systems/components) to detect, deflect, or analyze adversary behavior. In healthcare, honeypots and canaries can reveal ransomware reconnaissance on clinical VLANs—but they must never contain real ePHI, and they must be isolated so attackers cannot pivot from the decoy into the EHR.

Control Objective

When selected, deploy honeypots/deception components that detect malicious activity targeting healthcare networks without storing real ePHI or weakening production clinical boundaries.

Implementation Guidance

  1. Decide selection based on risk—SC-26 is often not in low baselines; document if Not Selected.
  2. If used, place decoys on segments where lateral movement toward ePHI is likely; never load real PHI.
  3. Instrument high-fidelity alerts to SOC (SI-4 / IR-4) with clear playbooks.
  4. Isolate honeypots so compromise cannot reach EHR, PACS, or identity systems (SC-7).
  5. Use canary credentials/files cautiously; rotate and monitor.
  6. Legal/privacy review before any deception that could touch workforce monitoring expectations.
  7. Exclude honeypot noise from clinical availability metrics.
  8. Retire poorly maintained decoys that become unpatched attack platforms.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Ransomware SMB canary on clinical VLAN

A decoy file share named like a legacy imaging share triggers SOC alert when worm tooling enumerates it—no real studies stored on the honeypot.

Fake EHR admin account canary

A monitored decoy admin identity lights up when sprayed; responders reset real privileged creds and hunt—real break-glass accounts remain in PAM.

Explicit Not Selected

A critical-access hospital documents SC-26 Not Selected, relying on EDR/SIEM, due to staff size; assessors accept the risk-based rationale.

Best Practices

  • Never put real ePHI on decoys.
  • Strong isolation and monitoring.
  • Playbooks before deployment.
  • Privacy/legal sign-off.
  • Maintain or remove decoys.
  • Document Not Selected when appropriate.

Common Gaps & Violations

  • Honeypot with restored EHR database "for realism."
  • Decoy bridged onto production EHR VLAN without controls.
  • Alerts ignored as false positives.
  • No owner; honeypot unpatched for months.
  • Claiming SC-26 without any deception capability or rationale.

Required Documentation

  • SC-26 selection decision (Selected / Not Selected)
  • Honeypot architecture and isolation diagram
  • Data-handling attestation (no ePHI)
  • SOC alert and IR playbooks
  • Privacy/legal review (if Selected)

How to Test & Validate

  1. Confirm honeypot storage contains no ePHI samples.
  2. Verify network ACLs block pivot to EHR subnets.
  3. Trigger a test interaction; confirm SOC ticket.
  4. Review patch/owner for decoy infrastructure.
  5. If Not Selected, verify SSP rationale is current.

Audit Considerations

SC-26 is optional in many baselines. Auditors care that if selected, decoys are safe and monitored; if not selected, the rationale is explicit.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.308(a)(1) Risk Analysis — deception may reduce residual risk of undetected intrusion.
  • 164.308(a)(6) Security Incident Procedures — honeypot alerts must feed IR.
  • 164.312(b) Audit Controls — monitoring mechanisms include detection sensors.
  • 164.530(c) Safeguards (Privacy Rule adjacency) — do not expose PHI in decoy content.

Compliance Tips

  • Default to Not Selected unless SOC can operate deception well.
  • If selected, state "no ePHI on honeypots" in the SSP.
  • Tie alerts to IR-4 metrics.

Frequently Asked Questions

Is SC-26 required for HIPAA?

HIPAA does not mandate honeypots. Use risk analysis; many entities Not Select SC-26.

Are canary tokens enough?

They can support the deception intent if monitored and documented; map them clearly in the SSP.

Can we honeypot on the biomedical network?

Only with extreme care and clinical engineering buy-in—false positives and device risk must be managed.

References & Resources

  • NIST SP 800-53 Rev. 5 — SC-26
  • Related controls: SI-4, IR-4, SC-7, AU-6

Need Help Implementing SC-26?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.