Partner still on FTP
Claims files with ePHI move via clear FTP. SC-9 project migrates to SFTP with key auth and retires FTP.
SC-9 requires protecting the confidentiality of transmitted information. Cleartext HL7 on VLANs, unencrypted partner FTP, and legacy radio/Wi-Fi without modern crypto still appear in healthcare and undermine HIPAA transmission security expectations.
Protect confidentiality of ePHI in transit using encryption and architectural protections appropriate to the path — including internal high-risk segments and external partner links.
How this control shows up in healthcare and HIPAA-covered environments.
Claims files with ePHI move via clear FTP. SC-9 project migrates to SFTP with key auth and retires FTP.
Segmentation plus TLS wrapping on the interface engine protects against casual sniffing.
Certificate process fixes prevent opportunistic cleartext during portal outages.
Transmission encryption is among the most tested HIPAA technical areas. SC-9 evidence should show encryption in practice across interfaces — not only VPN for remote users.
How this NIST control supports HIPAA Security Rule expectations.
SC-8 focuses transmission integrity; SC-9 focuses confidentiality — implement both for ePHI paths.
Sometimes cited as compensation; prefer encryption for ePHI and document any exception rigorously.
Prefer TLS for application sessions; risk-base additional network crypto for sensitive segments.
Related controls that commonly accompany SC-9.
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.