Unauthorized webshell on patient portal jump host
SI-7 FIM alerts on new files under the web root; IR contains the host before broader ePHI exfiltration.
SI-7 requires employing integrity verification tools to detect unauthorized changes to software, firmware, and information; performing checks on defined frequency and events; integrating findings into organizational processes; and responding to detected anomalies. In healthcare, SI-7 protects EHR application servers, identity systems, boot chains, and critical configuration/information stores from silent tampering that could alter ePHI or plant ransomware precursors.
Detect and respond to unauthorized changes to software, firmware, and critical information on systems that process or protect ePHI before integrity failures cause clinical or privacy harm.
How this control shows up in healthcare and HIPAA-covered environments.
SI-7 FIM alerts on new files under the web root; IR contains the host before broader ePHI exfiltration.
Firmware integrity checks and signed updates under SI-7 reduce risk on servers hosting virtualized EHR components.
Integrity monitoring detects audit logging being disabled — preserving HIPAA audit control effectiveness.
Integrity mechanisms support HIPAA integrity safeguards and malware defense. Assessors look for real monitoring and response — not merely agent install counts.
How this NIST control supports HIPAA Security Rule expectations.
Focus on unauthorized changes to software/firmware and critical information/system files; application-level ePHI authentication mechanisms may be additional where feasible.
SI-4 is broader system monitoring; SI-7 specifically targets integrity verification of software, firmware, and information.
For SaaS, require vendor integrity/control attestations and apply SI-7 rigorously on your side of integrations, identity, and any self-hosted components.
Related controls that commonly accompany SI-7.
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.