SR-10 Supply Chain Risk Management

Inspection of Systems or Components

Medium Risk Moderate Low Cost

SR-10 requires inspecting systems or system components at random or organization-defined frequencies/locations to detect tampering and counterfeit. Blind trust that a new clinic switch or server is pristine is an unnecessary ePHI risk.

Control Objective

Inspect critical systems and components — randomly and at defined points — to detect tampering, counterfeits, or anomalies before and during use in ePHI environments.

Implementation Guidance

  1. Define inspection points (receipt, pre-install, periodic in-place, pre-redeploy).
  2. Define what to inspect (seals, ports, firmware hashes, unexpected devices).
  3. Use random sampling for volume purchases plus 100% for highest criticality.
  4. Document inspection results; quarantine failures.
  5. Train inspectors (dock, data center, biomed).
  6. Include inspection after vendor maintenance when risk warrants.
  7. Correlate with SR-9/SR-11 findings.
  8. Retain records for audit and investigations.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Random sample of clinic routers

SR-10 inspection finds an unexpected USB serial device attached; unit quarantined.

Pre-install server check

Firmware version and seal inspection pass before EHR VM host enters production.

Post-OEM maintenance inspection

After storage vendor visit, inspection confirms no unknown media left attached.

Best Practices

  • Defined inspection points and checklists.
  • Random plus criticality-based sampling.
  • Quarantine on failure.
  • Trained inspectors.
  • Post-maintenance inspections.
  • Retained records.

Common Gaps & Violations

  • Never opening boxes until install panic.
  • No random inspections.
  • Checklists unused.
  • Failures installed anyway.
  • No post-vendor-visit checks.

Required Documentation

  • Inspection procedure (SR-10)
  • Checklists by component type
  • Sampling plan
  • Inspection records and quarantine logs
  • Training evidence

How to Test & Validate

  1. Review sampling plan and recent inspection records.
  2. Trace a failed inspection to quarantine.
  3. Verify pre-install inspections for a critical server.
  4. Check post-maintenance inspection samples.
  5. Interview dock staff on checklist use.

Audit Considerations

Inspection is the practical detection layer for supply-chain issues. Assessors want records of inspections performed — not only a policy stating inspect as needed.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.312(c) Integrity — inspection helps prevent compromised components from altering ePHI systems.
  • 164.310(d) Device and Media Controls — control hardware entering environments with ePHI.
  • 164.308(a)(1) Risk Management — inspection is a detection control for supply risk.
  • 164.310(a) Facility Access — physical inspection complements facility controls.

Compliance Tips

  • Keep inspection checklists one page so staff use them.
  • Photograph anomalies.
  • Feed inspection failures into SR-11 counterfeit reporting.

Frequently Asked Questions

Must every keyboard be inspected?

Use organizational frequencies and criticality — focus on components that can change trust in ePHI systems.

Is remote attestation an inspection?

Logical integrity checks can complement physical inspection for capable platforms.

Who performs SR-10?

Trained receiving, DC, or biomed personnel — not only security staff.

References & Resources

  • NIST SP 800-53 Rev. 5 — SR-10
  • Related controls: SR-9, SR-11, PE-16, MA-2, SI-7

Need Help Implementing SR-10?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.