Patient portal flood during open enrollment
Cloud DDoS/WAF under SC-5 absorbs volumetric attack; appointments remain bookable.
SC-5 requires protecting against or limiting the effects of denial-of-service attacks. Patient portals, VPN gateways, DNS, and interface endpoints under flood become care and HIPAA availability incidents — even without data exfiltration.
Protect ePHI-related services from DoS conditions through capacity planning, filtering, rate limiting, and provider DDoS services appropriate to exposure and clinical criticality.
How this control shows up in healthcare and HIPAA-covered environments.
Cloud DDoS/WAF under SC-5 absorbs volumetric attack; appointments remain bookable.
Rate limits and secondary concentrator keep clinical remote access partially available.
Boundary filtering limits impact while partner is contacted.
Availability events harm care and trigger contingency obligations. SC-5 shows intentional DoS resilience for ePHI services — not only confidentiality focus.
How this NIST control supports HIPAA Security Rule expectations.
Limit effects to organization-defined levels — document capacity and residual risk.
Yes if DoS (including accidental partner floods) can impact ePHI availability.
SC-5 is preventive/limitative technical protection; CP-2 covers broader contingency planning when availability fails.
Related controls that commonly accompany SC-5.
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.