DNS tunneling from compromised clinical PC
Analysis flags covert DNS tunnels as a channel; egress DNS restrictions (SC-21) and detection rules close the path used to stage ePHI theft.
SC-31 requires analysis of covert communications channels (timing, storage, or other unintended paths) that could violate security or privacy policy. In healthcare integrations, ePHI can leak through steganographic imaging fields, side-channel timing on shared hosts, misused printer metadata, or covert tunnels inside otherwise allowed protocols—beyond the obvious HL7/FHIR interfaces.
Analyze and mitigate organization-defined covert channels that could move ePHI or control signals outside authorized healthcare information flows.
How this control shows up in healthcare and HIPAA-covered environments.
Analysis flags covert DNS tunnels as a channel; egress DNS restrictions (SC-21) and detection rules close the path used to stage ePHI theft.
Two clinics’ sessions on one broker share temp space; SC-31-style review forces per-session isolation so charts cannot cross via leftover files.
A dual-zone research system handling limited PHI performs covert channel analysis on the gateway before go-live; timing channels documented and mitigated.
For most HIPAA mid-market entities, a reasoned Not Selected is common. High-assurance or cross-domain healthcare research systems should show real analysis artifacts.
How this NIST control supports HIPAA Security Rule expectations.
Usually not in moderate baselines—document selection. High-assurance environments take it seriously.
Uncommon but possible; schema controls and anomaly detection help.
AC-4 enforces authorized flows; SC-31 finds hidden flows that bypass those rules.
Related controls that commonly accompany SC-31.
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.