Stolen clinician laptop
Disk encryption under SC-28 plus remote wipe procedures greatly reduces breach notification likelihood for cached EHR data.
SC-28 requires protecting the confidentiality and integrity of information at rest. For healthcare, that means full-disk or volume encryption on endpoints and servers, database/storage encryption for EHR data stores, encrypted backups, and controlled key management — reducing breach impact when devices or media are lost and supporting HIPAA addressable encryption decisions with clear implementation.
Ensure ePHI and critical security information are protected at rest through encryption and/or equivalent strong access controls commensurate with risk across systems, endpoints, and backups.
How this control shows up in healthcare and HIPAA-covered environments.
Disk encryption under SC-28 plus remote wipe procedures greatly reduces breach notification likelihood for cached EHR data.
Buckets holding limited data sets use encryption at rest, tight IAM, and key policies before ePHI elements are landed.
Tape encryption and key custody prevent a courier loss from exposing years of EHR backups.
Encryption at rest is a primary mitigator in HIPAA breach assessments. SC-28 evidence should show coverage for endpoints, primary stores, and backups — not only a policy statement.
How this NIST control supports HIPAA Security Rule expectations.
It helps, but pair it with strong IAM, possibly customer-managed keys for sensitive stores, and configuration hardening.
No. SC-28 protects data at rest; SC-8 protects data in transit.
Segment, minimize stored ePHI, control physical access, and document residual risk.
Related controls that commonly accompany SC-28.
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.