SC-28 System and Communications Protection

Protection of Information at Rest

High Risk Complex High Cost

SC-28 requires protecting the confidentiality and integrity of information at rest. For healthcare, that means full-disk or volume encryption on endpoints and servers, database/storage encryption for EHR data stores, encrypted backups, and controlled key management — reducing breach impact when devices or media are lost and supporting HIPAA addressable encryption decisions with clear implementation.

Control Objective

Ensure ePHI and critical security information are protected at rest through encryption and/or equivalent strong access controls commensurate with risk across systems, endpoints, and backups.

Implementation Guidance

  1. Inventory where ePHI rests: EHR databases, file shares, backups, laptops, removable media, cloud buckets, device caches.
  2. Apply FDE on portable endpoints and encrypt servers/storage hosting ePHI where feasible.
  3. Enable transparent data encryption or equivalent for database platforms; protect cloud storage with provider encryption plus access controls.
  4. Encrypt backup datasets and secure key/escrow processes.
  5. Separate key management duties; restrict recovery key access.
  6. Document risk-based exceptions (e.g., certain medical devices) with compensating controls.
  7. Test recovery with keys so encryption does not become a ransomware single point of failure without DR planning.
  8. Monitor for unencrypted shadow repositories (exports, dumps, BI landing zones).

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Stolen clinician laptop

Disk encryption under SC-28 plus remote wipe procedures greatly reduces breach notification likelihood for cached EHR data.

Cloud data lake for quality analytics

Buckets holding limited data sets use encryption at rest, tight IAM, and key policies before ePHI elements are landed.

Offline backup tapes

Tape encryption and key custody prevent a courier loss from exposing years of EHR backups.

Best Practices

  • FDE mandatory on portable devices with ePHI access.
  • Encrypt backups end-to-end.
  • Managed keys with rotation and dual control.
  • Discover and eliminate clear-text exports.
  • Document device exceptions.
  • Validate restore from encrypted media.

Common Gaps & Violations

  • Laptops without encryption joined to EHR.
  • Unencrypted SQL backups on open shares.
  • Cloud storage public or broadly readable despite “encrypted” checkbox.
  • Recovery keys stored in the same laptop bag.
  • BI extracts of ePHI left clear-text indefinitely.

Required Documentation

  • At-rest protection standard (SC-28)
  • Encryption coverage inventory
  • Key management procedures
  • Exception register with compensations
  • Backup encryption evidence

How to Test & Validate

  1. Sample laptops for encryption enforcement.
  2. Verify EHR database/storage encryption settings.
  3. Inspect backup encryption configuration and key access.
  4. Review cloud bucket encryption and IAM.
  5. Confirm exceptions are documented and approved.

Audit Considerations

Encryption at rest is a primary mitigator in HIPAA breach assessments. SC-28 evidence should show coverage for endpoints, primary stores, and backups — not only a policy statement.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.312(a)(2)(iv) Encryption and Decryption — addressable specification to encrypt ePHI.
  • 164.312(c) Integrity — protect ePHI from improper alteration or destruction at rest.
  • 164.310(d) Device and Media Controls — encryption complements media controls for devices storing ePHI.
  • 164.402 Breach definition — encryption can render PHI “secure” when properly implemented per guidance.

Compliance Tips

  • Track encryption coverage as a KPI for all endpoints with EHR clients.
  • Include SC-28 checks in backup job audits quarterly.
  • Treat “exported CSV folders” as first-class data stores in the inventory.

Frequently Asked Questions

Is provider-managed cloud encryption enough?

It helps, but pair it with strong IAM, possibly customer-managed keys for sensitive stores, and configuration hardening.

Does SC-28 replace SC-8?

No. SC-28 protects data at rest; SC-8 protects data in transit.

What about medical devices that cannot encrypt storage?

Segment, minimize stored ePHI, control physical access, and document residual risk.

References & Resources

  • NIST SP 800-53 Rev. 5 — SC-28
  • NIST SP 800-111 / 800-57 key management references
  • HIPAA § 164.312(a)(2)(iv)
  • Related controls: SC-1, SC-12, SC-13, MP-5, AU-9

Need Help Implementing SC-28?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.