Next nurse sees prior chart PDF in temp
SC-4 cleanup policy clears user temp and browser cache on EHR logout for shared stations.
SC-4 requires preventing unauthorized and unintended information transfer via shared system resources. On shared nursing workstations, residual screenshots, temp files, print spools, and clipboard data can expose the prior patient's ePHI to the next user.
Prevent ePHI from leaking across users or processes through shared resources by clearing residue, isolating sessions, and hardening shared clinical platforms.
How this control shows up in healthcare and HIPAA-covered environments.
SC-4 cleanup policy clears user temp and browser cache on EHR logout for shared stations.
Kiosk policy blocks cross-session clipboard persistence.
Profile isolation prevents one coder's downloads from being visible to another.
Shared workstation residue is a frequent privacy walkthrough finding. SC-4 is practical and highly visible in clinical environments.
How this NIST control supports HIPAA Security Rule expectations.
No — isolation and cleanup on shared platforms can satisfy intent when designed well.
Yes for shared infrastructure that could leak ePHI between tenants/processes — apply accordingly.
PE-19 addresses emanation/observation; SC-4 addresses residual data in shared computing resources.
Related controls that commonly accompany SC-4.
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.