Frameworks / HIPAA_SEC
HIPAA Security Rule
US HHS Office for Civil Rights · US · effective 2005-04-20 · HIPAA_SEC
Administrative, physical and technical safeguards for electronic protected health information, including audit controls and access management.
11 controls, mapped to the evidence that satisfies each
Every control links to the dimension whose evidence would satisfy it. That mapping is the working link between an obligation written in law or a standard and a document somebody has to produce. Each row has its own address: link to a single control.
| Control | Title | Requirement | Satisfied by |
|---|---|---|---|
| §164.308(a)(5) | Security awareness and training | All workforce members, including management, receive a security awareness and training program. | D1 |
| §164.308(a)(7) | Contingency plan | A contingency plan covers data backup, disaster recovery and emergency-mode operation for systems that hold electronic PHI. | D3 |
| §164.310(a)(1) | Facility access controls | Physical access to the facilities and systems that hold electronic PHI is limited to authorized individuals. | D5 |
| §164.310(d)(1) | Device and media controls | Policies govern the receipt, removal, reuse and disposal of hardware and electronic media that contain electronic PHI. | D5 |
| §164.312(a)(1) | Access control | Technical policies restrict access to electronic PHI to the persons or software granted access rights, such as through unique user identification. | D5 |
| §164.312(c)(1) | Integrity | Policies and procedures protect electronic PHI from improper alteration or destruction. | D5 |
| §164.312(e)(1) | Transmission security | Technical measures guard against unauthorized access to electronic PHI while it is transmitted over a network. | D5 |
| §164.308(a)(1) | Security management process | Policies and procedures prevent, detect, contain and correct security violations against electronic PHI, built on a documented risk analysis. | D6 |
| §164.308(a)(6) | Security incident procedures | Policies and procedures identify, respond to, and document security incidents involving electronic PHI. | D6 |
| §164.312(b) | Audit controls | Hardware, software or procedural mechanisms record and examine activity in systems that contain or use electronic PHI. | D6 |
| §164.316(b)(1) | Documentation retention | Security policies, procedures and required actions are documented in writing and retained for six years from creation or last effective date, whichever is later. | D6 |
What this mapping is, and what it is not
It is a reading of a published instrument, with each control cited to its source, mapped to the kind of evidence that would satisfy it. It is not legal advice, not a certification, and not a statement that any organisation complies with anything. Where an instrument is not yet in force, this page says so rather than selling urgency.
Talk to the person who built this
If you assess clients against this instrument, the mapping is the part you can check line by line. There is no sales team: this is founder-led, so it reaches the founder directly. Tenant access is $500 a month, and free early access to the method, the corpus and the router is on offer first if that is useful. If it is not a fit, saying so costs you one reply.