Ransomware attempt on a clinic workstation
EDR blocks execution, isolates the host, and opens an IR ticket; ePHI file encryption is prevented — SI-3 detection actioned.
SI-3 requires implementing malicious code protection at system entry and exit points and on system components, updating protections when new releases are available, configuring to perform periodic and real-time scans as defined, and addressing the results of malicious code protection detections. Ransomware and trojans remain primary threats to care delivery and ePHI confidentiality; SI-3 is the baseline malware defense layered with application allowlisting and EDR where risk warrants.
Detect, block, and respond to malicious code on ePHI-related endpoints and servers with current signatures/engines, defined scanning, and actioned alerts.
How this control shows up in healthcare and HIPAA-covered environments.
EDR blocks execution, isolates the host, and opens an IR ticket; ePHI file encryption is prevented — SI-3 detection actioned.
Health dashboard shows 14 days without updates; automated ticket forces remediation before audit sampling.
Gateway detonation + endpoint block stop the payload; awareness follow-up issued under AT-2.
Malware protection is table stakes in HIPAA technical evaluations. Missing agents on ePHI servers and unmanaged alerts are common findings.
How this NIST control supports HIPAA Security Rule expectations.
SI-3 requires malicious code protection; modern EDR often best meets detection/response needs, but configure whatever you deploy to update, scan, and alert.
SI-2 is flaw remediation/patching; SI-3 is malware defense. Ransomware often needs both.
Segment them, control media/USB, scan upstream, and monitor — document why agents cannot run.
Related controls that commonly accompany SI-3.
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.