Counterfeit power supplies in IDF
Failures spike; authenticity checks reveal fakes. SR-11 removes them before they take down clinic access switches.
SR-11 requires developing anti-counterfeit policies, means to detect counterfeit components, and reporting mechanisms. Counterfeit optics, power supplies, and software installers remain a real path to instability and backdoors in healthcare networks carrying ePHI.
Detect, prevent, and report counterfeit or modified components through policy, authorized channels, verification tools, and intake inspection for ePHI-impacting systems.
How this control shows up in healthcare and HIPAA-covered environments.
Failures spike; authenticity checks reveal fakes. SR-11 removes them before they take down clinic access switches.
Unsigned utility blocked by authenticity rules for admin workstations.
Authorized-channel replacement restores stable links for EHR traffic.
Authenticity failures cause both outages and security incidents. SR-11 should be visible in purchasing and receiving — the front door for counterfeits.
How this NIST control supports HIPAA Security Rule expectations.
Largely overlapping authenticity goals; implement one anti-counterfeit program mapped to both IDs if present.
Not necessarily — require authorized refurb channels and verification.
Focus on information system components; clinical product authenticity has separate regulatory regimes.
Related controls that commonly accompany SR-11.
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.