SI-7 System and Information Integrity

Software, Firmware, and Information Integrity

High Risk Complex Medium Cost

SI-7 requires employing integrity verification tools to detect unauthorized changes to software, firmware, and information; performing checks on defined frequency and events; integrating findings into organizational processes; and responding to detected anomalies. In healthcare, SI-7 protects EHR application servers, identity systems, boot chains, and critical configuration/information stores from silent tampering that could alter ePHI or plant ransomware precursors.

Control Objective

Detect and respond to unauthorized changes to software, firmware, and critical information on systems that process or protect ePHI before integrity failures cause clinical or privacy harm.

Implementation Guidance

  1. Identify integrity-critical assets: EHR app/DB hosts, domain controllers/IdP, HIE gateways, backup servers, and select medical device managers.
  2. Deploy file integrity monitoring (FIM) or equivalent platform controls on those assets.
  3. Monitor boot/firmware integrity where hardware allows (secure boot, measured boot).
  4. Baseline after authorized changes; alert on unexpected drift.
  5. Integrate alerts into SIEM/IR with severity for production clinical systems.
  6. Protect FIM tooling itself from tampering and unauthorized disablement.
  7. Define response playbooks for integrity alerts (isolate, preserve, investigate).
  8. Review coverage when new ePHI systems are authorized.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Unauthorized webshell on patient portal jump host

SI-7 FIM alerts on new files under the web root; IR contains the host before broader ePHI exfiltration.

Firmware implant concern on management interfaces

Firmware integrity checks and signed updates under SI-7 reduce risk on servers hosting virtualized EHR components.

Silent change to audit configuration files

Integrity monitoring detects audit logging being disabled — preserving HIPAA audit control effectiveness.

Best Practices

  • FIM on tier-1 ePHI and identity hosts.
  • Baselines tied to change tickets.
  • Firmware signing/secure boot where supported.
  • Alert tuning to reduce ignored noise.
  • Protect integrity agents and consoles.
  • Include integrity events in IR tabletop scenarios.

Common Gaps & Violations

  • FIM installed then left in learning mode forever.
  • Only workstations covered; servers ignored.
  • No response process for integrity alerts.
  • Authorized changes not fed to baselines (alert fatigue).
  • Backup infrastructure excluded despite ransomware risk.

Required Documentation

  • SI-7 integrity monitoring standard
  • Coverage list of critical systems
  • Baseline and alert response procedures
  • Sample alert-to-IR evidence
  • Firmware/secure boot requirements where applicable

How to Test & Validate

  1. Verify integrity monitoring is active on sample EHR-related hosts.
  2. Confirm alerts fire on a controlled test change in non-prod.
  3. Review recent integrity alerts for triage evidence.
  4. Check that authorized changes update baselines.
  5. Inspect admin access restrictions on FIM consoles.

Audit Considerations

Integrity mechanisms support HIPAA integrity safeguards and malware defense. Assessors look for real monitoring and response — not merely agent install counts.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.312(c) Integrity — protect ePHI from improper alteration or destruction; implement mechanisms to authenticate ePHI where reasonable.
  • 164.308(a)(5)(ii)(B) Protection from Malicious Software — detecting unauthorized software changes supports malware defense.
  • 164.312(b) Audit Controls — integrity events complement activity audit trails.
  • 164.308(a)(1) Risk Management — integrity monitoring treats high-impact tampering risks.

Compliance Tips

  • Start SI-7 on identity + EHR + backup before expanding broadly.
  • Feed CAB-approved changes into FIM allowlists automatically where tools allow.
  • Report integrity alert MTTA alongside SOC metrics.

Frequently Asked Questions

Does SI-7 require hashing every patient record?

Focus on unauthorized changes to software/firmware and critical information/system files; application-level ePHI authentication mechanisms may be additional where feasible.

How does SI-7 relate to SI-4 monitoring?

SI-4 is broader system monitoring; SI-7 specifically targets integrity verification of software, firmware, and information.

Can SaaS EHR provide SI-7?

For SaaS, require vendor integrity/control attestations and apply SI-7 rigorously on your side of integrations, identity, and any self-hosted components.

References & Resources

  • NIST SP 800-53 Rev. 5 — SI-7
  • Related controls: SI-1, SI-2, SI-4, CM-3, AU-2, IR-4

Need Help Implementing SI-7?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.