SI-2 System and Information Integrity

Flaw Remediation

High Risk Moderate Medium Cost

SI-2 requires identifying, reporting, and correcting system flaws; testing software updates related to flaw remediation; installing updates within organization-defined periods based on risk; and incorporating remediation into configuration management. Patching is how RA-5 findings and vendor advisories become closed risk.

Control Objective

Remediate security flaws in ePHI-related systems within risk-based timeframes after testing, so known exploits do not linger in clinical environments.

Implementation Guidance

  1. Establish patch sources and ownership for OS, EHR, network, biomed (vendor-guided), and cloud services.
  2. Define SLAs by severity and exposure (internet-facing critical vs internal workstation).
  3. Test patches in pre-prod when clinical risk is high; use phased rings.
  4. Track remediation in tickets linked to RA-5 findings.
  5. Include third-party apps on clinical workstations — not only Windows Update.
  6. Document delayed patches with risk acceptance and compensating controls.
  7. Verify installation (compliance reports), not only deployment attempts.
  8. Coordinate emergency out-of-band patches for actively exploited CVEs.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Critical VPN CVE exploited in the wild

SI-2 emergency process patches appliances within 48 hours after abbreviated testing — coordinated with change windows.

EHR vendor delayed patch

Vendor holds a fix for 60 days. Risk acceptance documents compensating WAF/segmentation while the flaw remains open in the register.

Workstation third-party browser plugins

Patch management expands beyond OS to browsers/Office, cutting drive-by risk on nursing stations.

Best Practices

  • Risk-based SLAs with verification.
  • Emergency patch path for active exploits.
  • Test clinically sensitive systems.
  • Cover third-party apps.
  • Link patches to vulnerability tickets.
  • Metrics: % systems patched within SLA.

Common Gaps & Violations

  • Patches deferred indefinitely without acceptance.
  • Only OS patched; apps ignored.
  • No verification of install success.
  • Biomed never addressed even with vendor patches.
  • Production patched Friday night with no rollback plan.

Required Documentation

  • Flaw remediation / patch management procedure
  • Severity SLAs
  • Patch compliance reports
  • Exception / risk-acceptance records
  • Emergency patch process

How to Test & Validate

  1. Sample critical CVE tickets for SLA met + verified install.
  2. Review compliance % for a critical cohort (VPN, EHR servers).
  3. Confirm emergency patch path exists and was tested/tabletopped.
  4. Check exceptions for expiry.
  5. Validate third-party app patch coverage on clinical images.

Audit Considerations

Unpatched internet-facing systems are high-severity findings. Show SLAs, compliance metrics, and exception handling.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.308(a)(1)(ii)(B) Risk Management — patching reduces risks to reasonable levels.
  • 164.308(a)(5)(ii)(B) Protection from Malicious Software — updates help protect against malware.
  • 164.308(a)(8) Evaluation — technical evaluations often include patch status.
  • 164.312(a)(1) Access Control — unpatched remote services undermine access control.

Compliance Tips

  • Publish patch SLA dashboards to leadership monthly.
  • Maintain a vendor contact matrix for EHR/biomed emergency fixes.
  • Never close a RA-5 ticket without SI-2 verification evidence.

Frequently Asked Questions

How fast must we patch?

Define risk-based periods in policy (e.g., critical internet-facing faster than low internal). Document and meet them.

What if a patch breaks clinical workflows?

Test, phase rollout, and use temporary compensating controls with formal risk acceptance — do not ignore the flaw.

How does SI-2 relate to RA-5?

RA-5 finds vulnerabilities; SI-2 remediates flaws including patches.

References & Resources

  • NIST SP 800-53 Rev. 5 — SI-2
  • NIST SP 800-40 Patch Management
  • Related controls: RA-5, CM-3, CM-6, IR-4

Need Help Implementing SI-2?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.