OEM always-on VPN
Pump vendor had flat access. SR-5 redesign moves support to JIT jump host with session recording.
SR-5 requires employing controls to limit harm from potential adversaries using supply chain pathways via external connections — including denying unauthorized connections and isolating critical components. Vendor remote access and partner interconnects are primary healthcare supply-chain attack paths into ePHI.
Limit and tightly control external connections associated with suppliers and partners so supply-chain pathways cannot freely reach critical ePHI systems.
How this control shows up in healthcare and HIPAA-covered environments.
Pump vendor had flat access. SR-5 redesign moves support to JIT jump host with session recording.
Connection replaced with minimized API under SR-5 limitations.
Former affiliate still connected. Review cuts the external path and credentials.
Third-party remote access is a leading breach pattern in healthcare. SR-5 evidence should show constrained supplier pathways — not permanent tunnels.
How this NIST control supports HIPAA Security Rule expectations.
CA-3 authorizes and documents external connections; SR-5 emphasizes limiting supply-chain harm through those connections.
Patient access is usually AC/SC territory; SR-5 focuses on supplier/partner supply-chain pathways.
Persistent system connections are primary; apply commensurate controls for any automated vendor data paths.
Related controls that commonly accompany SR-5.
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.