Ransomware SMB canary on clinical VLAN
A decoy file share named like a legacy imaging share triggers SOC alert when worm tooling enumerates it—no real studies stored on the honeypot.
SC-26 addresses employing honeypots (deception systems/components) to detect, deflect, or analyze adversary behavior. In healthcare, honeypots and canaries can reveal ransomware reconnaissance on clinical VLANs—but they must never contain real ePHI, and they must be isolated so attackers cannot pivot from the decoy into the EHR.
When selected, deploy honeypots/deception components that detect malicious activity targeting healthcare networks without storing real ePHI or weakening production clinical boundaries.
How this control shows up in healthcare and HIPAA-covered environments.
A decoy file share named like a legacy imaging share triggers SOC alert when worm tooling enumerates it—no real studies stored on the honeypot.
A monitored decoy admin identity lights up when sprayed; responders reset real privileged creds and hunt—real break-glass accounts remain in PAM.
A critical-access hospital documents SC-26 Not Selected, relying on EDR/SIEM, due to staff size; assessors accept the risk-based rationale.
SC-26 is optional in many baselines. Auditors care that if selected, decoys are safe and monitored; if not selected, the rationale is explicit.
How this NIST control supports HIPAA Security Rule expectations.
HIPAA does not mandate honeypots. Use risk analysis; many entities Not Select SC-26.
They can support the deception intent if monitored and documented; map them clearly in the SSP.
Only with extreme care and clinical engineering buy-in—false positives and device risk must be managed.
Related controls that commonly accompany SC-26.
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.