SC-5 System and Communications Protection

Denial of Service Protection

High Risk Complex Medium Cost

SC-5 requires protecting against or limiting the effects of denial-of-service attacks. Patient portals, VPN gateways, DNS, and interface endpoints under flood become care and HIPAA availability incidents — even without data exfiltration.

Control Objective

Protect ePHI-related services from DoS conditions through capacity planning, filtering, rate limiting, and provider DDoS services appropriate to exposure and clinical criticality.

Implementation Guidance

  1. Identify internet-facing and critical internal services supporting ePHI (portals, VPN, APIs, DNS).
  2. Employ network filtering, WAF/rate limits, and cloud DDoS protections where exposed.
  3. Size infrastructure for surge; monitor for traffic anomalies.
  4. Define playbooks for DoS events including ISP/cloud provider engagement.
  5. Avoid single points of failure for critical auth and DNS.
  6. Test failover and filtering rules carefully to avoid self-DoS.
  7. Include BA-hosted portals in contractual availability expectations.
  8. Coordinate with CP contingency for prolonged outages.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Patient portal flood during open enrollment

Cloud DDoS/WAF under SC-5 absorbs volumetric attack; appointments remain bookable.

VPN concentrator exhaustion

Rate limits and secondary concentrator keep clinical remote access partially available.

Interface engine SYN flood from misconfigured partner

Boundary filtering limits impact while partner is contacted.

Best Practices

  • Protect internet-facing ePHI services.
  • Rate limits/WAF/DDoS services.
  • Anomaly monitoring.
  • Provider engagement playbooks.
  • Reduce SPOFs for auth/DNS.
  • BA availability clauses.

Common Gaps & Violations

  • Public EHR interfaces unprotected.
  • No DDoS retainer/playbook.
  • DNS single point of failure.
  • Filtering rules untested causing outages.
  • Ignoring BA portal resilience.

Required Documentation

  • DoS protection standard (SC-5)
  • Inventory of exposed critical services
  • Filtering/WAF/DDoS configurations
  • Incident playbooks
  • Test/review records

How to Test & Validate

  1. Review protections on patient portal/VPN.
  2. Verify monitoring/alerts for floods.
  3. Check playbook and provider contacts.
  4. Confirm DNS/auth redundancy for critical paths.
  5. Review BA portal availability terms.

Audit Considerations

Availability events harm care and trigger contingency obligations. SC-5 shows intentional DoS resilience for ePHI services — not only confidentiality focus.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.306 Ensure CIA — availability of ePHI is an explicit objective.
  • 164.308(a)(7) Contingency Plan — DoS is an emergency affecting system availability.
  • 164.312(a) Access Control — accessible systems for care depend on surviving floods.
  • 164.308(a)(1) Risk Management — treat DoS likelihood for exposed services.

Compliance Tips

  • Put portal/VPN under cloud DDoS where public.
  • Practice DoS playbooks with your ISP/cloud TAM.
  • Watch for application-layer floods, not only volumetric.

Frequently Asked Questions

Does SC-5 require absorbing any size attack?

Limit effects to organization-defined levels — document capacity and residual risk.

Are internal-only systems in scope?

Yes if DoS (including accidental partner floods) can impact ePHI availability.

How related to CP-2?

SC-5 is preventive/limitative technical protection; CP-2 covers broader contingency planning when availability fails.

References & Resources

  • NIST SP 800-53 Rev. 5 — SC-5
  • Related controls: SC-7, CP-2, SI-4, CP-8, IR-4

Need Help Implementing SC-5?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.