Frameworks / HIPAA_SEC

HIPAA Security Rule

US HHS Office for Civil Rights · US · effective 2005-04-20 · HIPAA_SEC

Administrative, physical and technical safeguards for electronic protected health information, including audit controls and access management.

11 controls, mapped to the evidence that satisfies each

Every control links to the dimension whose evidence would satisfy it. That mapping is the working link between an obligation written in law or a standard and a document somebody has to produce. Each row has its own address: link to a single control.
ControlTitleRequirementSatisfied by
§164.308(a)(5)Security awareness and trainingAll workforce members, including management, receive a security awareness and training program.D1
§164.308(a)(7)Contingency planA contingency plan covers data backup, disaster recovery and emergency-mode operation for systems that hold electronic PHI.D3
§164.310(a)(1)Facility access controlsPhysical access to the facilities and systems that hold electronic PHI is limited to authorized individuals.D5
§164.310(d)(1)Device and media controlsPolicies govern the receipt, removal, reuse and disposal of hardware and electronic media that contain electronic PHI.D5
§164.312(a)(1)Access controlTechnical policies restrict access to electronic PHI to the persons or software granted access rights, such as through unique user identification.D5
§164.312(c)(1)IntegrityPolicies and procedures protect electronic PHI from improper alteration or destruction.D5
§164.312(e)(1)Transmission securityTechnical measures guard against unauthorized access to electronic PHI while it is transmitted over a network.D5
§164.308(a)(1)Security management processPolicies and procedures prevent, detect, contain and correct security violations against electronic PHI, built on a documented risk analysis.D6
§164.308(a)(6)Security incident proceduresPolicies and procedures identify, respond to, and document security incidents involving electronic PHI.D6
§164.312(b)Audit controlsHardware, software or procedural mechanisms record and examine activity in systems that contain or use electronic PHI.D6
§164.316(b)(1)Documentation retentionSecurity policies, procedures and required actions are documented in writing and retained for six years from creation or last effective date, whichever is later.D6

What this mapping is, and what it is not

It is a reading of a published instrument, with each control cited to its source, mapped to the kind of evidence that would satisfy it. It is not legal advice, not a certification, and not a statement that any organisation complies with anything. Where an instrument is not yet in force, this page says so rather than selling urgency.

Talk to the person who built this

If you assess clients against this instrument, the mapping is the part you can check line by line. There is no sales team: this is founder-led, so it reaches the founder directly. Tenant access is $500 a month, and free early access to the method, the corpus and the router is on offer first if that is useful. If it is not a fit, saying so costs you one reply.

Start a conversation

What are you trying to show, and to whom — an auditor, a client, a regulator, your own board?

Your address is used to reply and nothing else. It is not published, not sold, and not added to a mailing list.

HIPAA Security Rule: 11 controls, each cited