SR-5 Supply Chain Risk Management

Limitations on External System Connections

High Risk Complex Medium Cost

SR-5 requires employing controls to limit harm from potential adversaries using supply chain pathways via external connections — including denying unauthorized connections and isolating critical components. Vendor remote access and partner interconnects are primary healthcare supply-chain attack paths into ePHI.

Control Objective

Limit and tightly control external connections associated with suppliers and partners so supply-chain pathways cannot freely reach critical ePHI systems.

Implementation Guidance

  1. Inventory external connections used by suppliers (OEM VPN, cloud admin, HIE, support RDP).
  2. Deny standing unrestricted vendor access; prefer JIT, monitored sessions.
  3. Segment supplier access away from broad EHR databases where possible.
  4. Broker file exchange instead of direct DB links for many BA workflows.
  5. Review connections on cadence; remove stale vendor paths.
  6. Align with CA-3 authorizations and AC-17 remote access.
  7. Monitor supplier sessions for anomalies.
  8. Document isolation of critical components from general partner networks.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

OEM always-on VPN

Pump vendor had flat access. SR-5 redesign moves support to JIT jump host with session recording.

Marketing BA direct EHR SQL

Connection replaced with minimized API under SR-5 limitations.

Stale clinic partner link

Former affiliate still connected. Review cuts the external path and credentials.

Best Practices

  • Inventory supplier external connections.
  • JIT over standing vendor access.
  • Segmentation/isolation.
  • Cadenced reviews.
  • Session monitoring.
  • Align to CA-3.

Common Gaps & Violations

  • Shared vendor VPN with no MFA.
  • Direct SQL from BAs.
  • Never reviewing partner links.
  • Critical EHR on same segment as guest vendor Wi-Fi.
  • No monitoring of OEM sessions.

Required Documentation

  • SR-5 external connection limitation procedure
  • Supplier connection inventory
  • JIT/monitoring configurations
  • Review records
  • Isolation architecture diagrams

How to Test & Validate

  1. Sample vendor remote access for JIT and monitoring.
  2. Compare inventory to live VPN/partner tunnels.
  3. Verify segmentation for critical ePHI stores.
  4. Confirm stale connections removed.
  5. Review CA-3 linkage for supplier links.

Audit Considerations

Third-party remote access is a leading breach pattern in healthcare. SR-5 evidence should show constrained supplier pathways — not permanent tunnels.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.312(a) Access Control — limit access to ePHI including via external connections.
  • 164.312(e) Transmission Security — protect ePHI on partner links.
  • 164.308(b) BA controls — operationalize least access for BAs.
  • 164.308(a)(4) Information Access Management — isolate healthcare clearinghouse functions and analogous separations.

Compliance Tips

  • Put supplier connections on a quarterly kill/keep review.
  • Require session recording for OEM access to clinical systems.
  • Prefer vendor access through your PAM, not theirs alone.

Frequently Asked Questions

How does SR-5 relate to CA-3?

CA-3 authorizes and documents external connections; SR-5 emphasizes limiting supply-chain harm through those connections.

Are patient portal connections SR-5?

Patient access is usually AC/SC territory; SR-5 focuses on supplier/partner supply-chain pathways.

Is email with a vendor an external connection?

Persistent system connections are primary; apply commensurate controls for any automated vendor data paths.

References & Resources

  • NIST SP 800-53 Rev. 5 — SR-5
  • Related controls: CA-3, AC-17, SC-7, AC-4, SA-9

Need Help Implementing SR-5?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.