SC-7 System and Communications Protection

Boundary Protection

High Risk Complex Medium Cost

SC-7 requires monitoring and controlling communications at external managed interfaces, implementing subnetworks for publicly accessible system components, connecting to external networks through managed interfaces with boundary protection devices, and denying-by-default where policy requires. Boundary protection keeps the internet, guest Wi-Fi, and partners from having free rein into systems that store ePHI.

Control Objective

Enforce controlled, monitored chokepoints between networks of different trust levels so ePHI environments are segmented and not directly reachable from untrusted zones.

Implementation Guidance

  1. Diagram trust zones: internet, guest, corporate, clinical, biomed, data center/cloud.
  2. Place firewalls/proxies at zone boundaries; deny by default, allow by business need.
  3. Put public web properties in a DMZ — not on the EHR VLAN.
  4. Limit partner/BA connections to managed interfaces with ACLs and monitoring.
  5. Restrict administrative access to jump hosts inside managed boundaries.
  6. Log and alert on boundary denies/anomalies (ties to SI-4/AU).
  7. Review firewall rules quarterly for shadow rules and expired projects.
  8. Extend the same mindset to cloud security groups and private endpoints.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Guest Wi-Fi reaches EHR

Flat network allowed visitors to scan clinical servers. SC-7 segmentation isolates guest SSID with no routes to ePHI VLANs.

Vendor VPN straight into clinical core

A support VPN dropped users onto the same segment as EHR. SC-7 redesign brokers access through a monitored jump zone with limited allow-lists.

Public website on internal VLAN

Marketing CMS sat beside file servers. Moving it to a DMZ reduced blast radius from web exploits.

Best Practices

  • Deny-by-default at boundaries.
  • Separate biomed and clinical where feasible.
  • Managed partner connections only.
  • Regular firewall rule reviews.
  • Monitor boundary telemetry.
  • Apply equivalent controls in cloud VPCs.

Common Gaps & Violations

  • Any-any firewall rules years old.
  • Public servers on internal networks.
  • Direct RDP/VPN into EHR subnet.
  • No distinction between guest and clinical.
  • Cloud security groups wide open (0.0.0.0/0).

Required Documentation

  • Boundary protection / network security standard
  • Network zone diagrams
  • Firewall rule review records
  • Partner connection inventory
  • Cloud network baseline configs

How to Test & Validate

  1. From guest network, attempt EHR ports; confirm deny.
  2. Verify public site is not on clinical VLAN.
  3. Sample firewall rules for business owner and expiry.
  4. Confirm admin access uses jump hosts.
  5. Review boundary alert coverage.

Audit Considerations

Assessors often test segmentation during onsite reviews. Flat networks with ePHI are a recurring high finding under HIPAA technical safeguards narratives.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.312(a)(1) Access Control — network boundaries support limiting access to authorized users/systems.
  • 164.312(e) Transmission Security — protecting ePHI in transit across boundaries.
  • 164.308(a)(1) Risk Analysis — internet exposure and flat networks are core risks.
  • 164.310(a) Facility Access — physical and logical boundaries often work together for clinics.

Compliance Tips

  • Make rule reviews a calendar event with application owners present.
  • Treat cloud security groups as firewalls under SC-7.
  • Document compensating controls for hard-to-segment medical devices.

Frequently Asked Questions

Is a single edge firewall enough for SC-7?

Edge protection helps, but internal segmentation between guest, clinical, and admin zones is usually needed for ePHI environments.

How does SC-7 relate to AC-4?

SC-7 focuses on boundary devices/interfaces; AC-4 is broader information flow policy enforcement (including app/DLP flows).

Do SaaS-only clinics need SC-7?

Yes for their offices, Wi-Fi, endpoints, and any hybrid connectors — plus cloud control-plane boundaries.

References & Resources

  • NIST SP 800-53 Rev. 5 — SC-7
  • NIST SP 800-41 Firewalls and Firewall Policy
  • HIPAA §§ 164.312(a), 164.312(e)
  • Related controls: AC-4, AC-17, AC-18, SI-4, SC-8

Need Help Implementing SC-7?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.