Hospital ransomware advisory
ISAC releases indicators for a new encryptor; SC-35 process pushes hashes to EDR within hours and hunts for footholds on clinical jump hosts.
SC-35 includes external indicators of malicious code from organization-defined sources and acts on them to eradicate or quarantine code and update protections. Healthcare SOCs consume ISACs, vendor intel, and national alerts to block ransomware families targeting hospitals before signatures hit every endpoint organically.
Ingest external malicious-code indicators from trusted sources and operationalize them to protect systems that create, receive, maintain, or transmit ePHI.
How this control shows up in healthcare and HIPAA-covered environments.
ISAC releases indicators for a new encryptor; SC-35 process pushes hashes to EDR within hours and hunts for footholds on clinical jump hosts.
External intel identifies credential-harvest domains; email and DNS controls block them before payroll-themed lures hit clinicians.
Alert on trojanized clinical software update drives CM-14 verification and temporary install freeze.
SC-35 is the intel-to-action loop. Assessors want sources plus evidence you acted—not unread PDF advisories.
How this NIST control supports HIPAA Security Rule expectations.
AV is SI-3 territory; SC-35 emphasizes incorporating external indicators and acting on them.
Organization-defined—healthcare ISAC plus vendor/CISA feeds are common.
SI-4 monitors systems; SC-35 feeds external malicious-code identification into protective actions.
Related controls that commonly accompany SC-35.
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.