Container image for patient API
CI records signed provenance attestations for images deployed to the ePHI API cluster.
SR-4 requires documenting, retaining, and auditing the provenance of systems and components. Knowing where EHR appliances, containers, and device firmware came from enables authenticity checks, vulnerability response, and investigation when ePHI environments are compromised.
Capture and retain provenance information for critical ePHI system components — including origin, modifiers, and supply path — so integrity and authenticity can be verified over time.
How this control shows up in healthcare and HIPAA-covered environments.
CI records signed provenance attestations for images deployed to the ePHI API cluster.
Provenance records identify which clinics received a suspect firmware batch for rapid isolation.
Procurement holds go-live until vendor provides component inventory for the bot runtime.
Provenance is foundational to authenticity and vulnerability response. Assessors ask whether you can identify affected components quickly after a supplier advisory.
How this NIST control supports HIPAA Security Rule expectations.
Not always available, but document provenance to the extent obtainable and prioritize vendors who provide it for critical ePHI software.
Capture what you can (provider, region, major version, subprocessors) as provenance of the service components you rely on.
Align to asset life plus investigation/HIPAA documentation needs.
Related controls that commonly accompany SR-4.
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.