SC-4 System and Communications Protection

Information in Shared Resources

High Risk Moderate Low Cost

SC-4 requires preventing unauthorized and unintended information transfer via shared system resources. On shared nursing workstations, residual screenshots, temp files, print spools, and clipboard data can expose the prior patient's ePHI to the next user.

Control Objective

Prevent ePHI from leaking across users or processes through shared resources by clearing residue, isolating sessions, and hardening shared clinical platforms.

Implementation Guidance

  1. Identify shared resources on clinical systems (temp dirs, clipboards, print queues, browser caches, shared memory).
  2. Configure session logout to clear or protect residue (AC-11 pairing).
  3. Use separate OS profiles or VDI where shared kiosks are common.
  4. Restrict shared scratch locations; clean on logout/reboot.
  5. Segregate processes handling ePHI from general utilities where feasible.
  6. Harden terminal services used by multiple billers.
  7. Test residual data after session switch.
  8. Include BA-hosted shared desktops in scope.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Next nurse sees prior chart PDF in temp

SC-4 cleanup policy clears user temp and browser cache on EHR logout for shared stations.

Clipboard paste between patients

Kiosk policy blocks cross-session clipboard persistence.

Shared Citrix for coding team

Profile isolation prevents one coder's downloads from being visible to another.

Best Practices

  • Clear residue on shared sessions.
  • Prefer VDI/profile isolation.
  • Protect print spools.
  • Test session-switch leakage.
  • Cover kiosks and Citrix.
  • Pair with auto-lock.

Common Gaps & Violations

  • Shared local Windows profiles with lingering ePHI files.
  • Common download folders for all users.
  • Print jobs readable by anyone.
  • No residual data testing.
  • Ignoring browser restore of PHI pages.

Required Documentation

  • Shared resource protection standard (SC-4)
  • Kiosk/VDI hardening baselines
  • Logout cleanup configurations
  • Residual data test results
  • BA shared-desktop requirements

How to Test & Validate

  1. Switch users on a shared clinical PC; hunt for residual ePHI files.
  2. Verify print spool permissions.
  3. Check VDI profile isolation.
  4. Review browser cache behavior on logout.
  5. Sample BA shared desktop controls.

Audit Considerations

Shared workstation residue is a frequent privacy walkthrough finding. SC-4 is practical and highly visible in clinical environments.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.310(b) Workstation Use — policies for shared workstation surroundings and use.
  • 164.310(c) Workstation Security — physical/technical safeguards for workstations accessing ePHI.
  • 164.530(c) Safeguards — prevent unintentional disclosure between users.
  • 164.312(a) Access Control — unique user sessions should not leak data across identities.

Compliance Tips

  • Enforce mandatory profile cleanup on nursing kiosks.
  • Disable persistent common download shares.
  • Add residual ePHI checks to clinic security rounds.

Frequently Asked Questions

Does SC-4 require separate hardware per user?

No — isolation and cleanup on shared platforms can satisfy intent when designed well.

Are server multi-tenant issues in scope?

Yes for shared infrastructure that could leak ePHI between tenants/processes — apply accordingly.

How related to PE-19?

PE-19 addresses emanation/observation; SC-4 addresses residual data in shared computing resources.

References & Resources

  • NIST SP 800-53 Rev. 5 — SC-4
  • Related controls: AC-11, AC-4, MP-7, SC-2, SI-12

Need Help Implementing SC-4?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.