Patient check-in kiosk
Kiosk OS boots a signed image; users cannot install software; malware writes do not persist across reboot.
SC-34 loads and executes organization-defined applications from hardware-enforced, write-protected storage or other non-modifiable forms. Clinical kiosks, appliance firewalls, and hardened jump hosts benefit when the executable set cannot be casually rewritten by malware.
Ensure defined executables for high-risk ePHI-supporting components execute from non-modifiable or hardware-protected storage as specified.
How this control shows up in healthcare and HIPAA-covered environments.
Kiosk OS boots a signed image; users cannot install software; malware writes do not persist across reboot.
Admin bastion uses immutable base image refreshed from trusted pipeline after each patch cycle.
Boundary firewall executes from vendor signed, non-user-writable partitions.
SC-34 is selective hardening. Show specific components and mechanisms rather than a blanket statement.
How this NIST control supports HIPAA Security Rule expectations.
No—apply to organization-defined components where non-modifiable execution is practical.
It helps but is not always hardware-enforced write protection; combine controls as needed.
CM-14 verifies signatures; SC-34 emphasizes execution from non-modifiable storage.
Related controls that commonly accompany SC-34.
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.