SI-1 System and Information Integrity

System and Information Integrity Policy and Procedures

High Risk Moderate Medium Cost

SI-1 requires system and information integrity policy and procedures addressing purpose, scope, roles, management commitment, coordination, and compliance, plus procedures to implement the SI family. Healthcare SI-1 governs antivirus/EDR, patching, integrity monitoring, spam/phishing controls, and flaw remediation so malware and unauthorized alteration do not compromise ePHI or clinical availability.

Control Objective

Establish policy and procedures that detect, prevent, and correct integrity failures and malicious code affecting systems that store, process, or transmit ePHI.

Implementation Guidance

  1. Publish SI-1 policy covering endpoints, servers, email, clinical devices (as feasible), and cloud workloads with ePHI impact.
  2. Require malware protection, timely flaw remediation, and security monitoring expectations.
  3. Define patch SLAs by severity and clinical criticality, including change windows.
  4. Address alert triage ownership and escalation to IR.
  5. Include email/web filtering standards for phishing that targets clinicians.
  6. Document compensating controls for unmanaged medical devices.
  7. Review annually and after major EDR/SIEM platform changes.
  8. Align with SI-2, SI-3, SI-4, SI-7, and RA vulnerability processes.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Zero-day affecting VPN appliances

SI-1 procedures drive emergency patching SLAs and compensating detection until EHR remote access gear is updated.

Malware on a registration PC

EDR alert escalates per policy; device is isolated before credential theft reaches billing ePHI exports.

Unpatchable ultrasound machine

Integrity policy requires network compensating controls and monitoring rather than ignoring the device.

Best Practices

  • EDR on all feasible endpoints handling ePHI.
  • Severity-based patch SLAs.
  • Medical device exception register.
  • Phishing controls tuned for clinical urgency.
  • Integrity monitoring on critical EHR hosts.
  • Metrics to leadership (patch latency, malware block rates).

Common Gaps & Violations

  • Antivirus definitions stale on clinic PCs.
  • Critical patches delayed indefinitely “for uptime.”
  • No integrity policy for cloud EHR admin actions.
  • Medical devices flatly excluded with no compensations.
  • Alerts ignored without IR escalation path.

Required Documentation

  • System and information integrity policy (SI-1)
  • Malware and patching procedures
  • Monitoring/alerting ownership
  • Medical device compensating control process
  • Policy review records

How to Test & Validate

  1. Confirm SI-1 policy is approved and current.
  2. Sample endpoints for malware protection compliance.
  3. Review patch SLA evidence for a critical CVE.
  4. Trace a malware alert to IR escalation.
  5. Inspect compensating controls for a sample clinical device.

Audit Considerations

Integrity and malware safeguards support HIPAA integrity and security management expectations. SI-1 shows enterprise rules behind tools and patch tickets.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.312(c) Integrity — protect ePHI from improper alteration or destruction.
  • 164.308(a)(5)(ii)(B) Protection from Malicious Software — procedures for guarding against, detecting, and reporting malicious software.
  • 164.308(a)(1) Risk Management — remediate flaws that create unacceptable risk to ePHI.
  • 164.316 Policies and procedures — document integrity policy.

Compliance Tips

  • Report patch compliance for EHR-adjacent servers monthly to the compliance committee.
  • Maintain a medical device SEG/VLAN standard referenced by SI-1.
  • Tune phishing simulations to clinical message patterns.

Frequently Asked Questions

Must every medical device run EDR under SI-1?

Often not feasible; policy should require risk-based protections and network compensations when agents cannot run.

How does SI-1 relate to SI-2?

SI-1 is policy; SI-2 is flaw remediation executed under that policy.

Does integrity include clinical data accuracy?

SI focuses on unauthorized system/information alteration; clinical documentation quality is related but primarily HIM/quality governance — still coordinate when system integrity events corrupt charts.

References & Resources

  • NIST SP 800-53 Rev. 5 — SI-1
  • HIPAA §§ 164.312(c), 164.308(a)(5)
  • Related controls: SI-2, SI-3, SI-4, SI-7, IR-4

Need Help Implementing SI-1?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.