← Framework library

HIPAA Security Rule (and selected Breach Notification Rule duties)

Administrative, physical and technical safeguards of the HIPAA Security Rule, plus the organisational requirements and the core Breach Notification Rule duties. Applies to covered entities and, since the HITECH Act, directly to business associates.

US Department of Health and Human Services, Office for Civil Rights · 45 CFR Part 164 Subparts C and D · United States · Official source

Each standard is marked Required (R) or Addressable (A). Addressable does not mean optional: the entity must implement the specification, or document why it is not reasonable and appropriate and implement an equivalent alternative. This tool records that documented-alternative path explicitly, because treating 'addressable' as 'skip' is the single most common HIPAA finding.
28 of 28 controls
164.308(a)(1)(ii)(A) Risk analysis (R) critical

Conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity and availability of electronic protected health information held by the entity.

Administrative safeguards risk-assessment
164.308(a)(1)(ii)(B) Risk management (R) critical

Implement security measures sufficient to reduce risks and vulnerabilities to a reasonable and appropriate level.

Administrative safeguards risk-assessment
164.308(a)(1)(ii)(C) Sanction policy (R) medium

Apply appropriate sanctions against workforce members who fail to comply with the security policies and procedures of the covered entity or business associate.

Administrative safeguards policy-governance
164.308(a)(1)(ii)(D) Information system activity review (R) high

Implement procedures to regularly review records of information system activity, such as audit logs, access reports and security incident tracking reports.

Administrative safeguards loggingauditmonitoring
164.308(a)(2) Assigned security responsibility (R) high

Identify the security official who is responsible for the development and implementation of the policies and procedures required by the Security Rule.

Administrative safeguards roles-responsibilities
164.308(a)(3)(ii)(A) Authorisation and supervision (A) high

Implement procedures for the authorisation and supervision of workforce members who work with electronic protected health information or in locations where it might be accessed.

Administrative safeguards access-controlprivileged-access
164.308(a)(3)(ii)(B) Workforce clearance procedure (A) medium

Implement procedures to determine that the access of a workforce member to electronic protected health information is appropriate.

Administrative safeguards hr-screeningonboarding
164.308(a)(3)(ii)(C) Termination procedures (A) critical

Implement procedures for terminating access to electronic protected health information when the employment of, or other arrangement with, a workforce member ends.

Administrative safeguards offboardingaccess-control
164.308(a)(4)(ii)(B) Access authorisation (A) critical

Implement policies and procedures for granting access to electronic protected health information, for example through access to a workstation, transaction, programme, process or other mechanism, on the minimum necessary standard.

Administrative safeguards access-control
164.308(a)(4)(ii)(C) Access establishment and modification (A) high

Implement policies and procedures that, based upon the entity's access authorisation policies, establish, document, review and modify a user's right of access to a workstation, transaction, programme or process.

Administrative safeguards access-reviewaccess-control
164.308(a)(5)(ii)(A-D) Security awareness and training (A) high

Implement a security awareness and training programme for all workforce members, including periodic security reminders, protection from malicious software, log-in monitoring and password management.

Administrative safeguards trainingawarenessmalwareauthentication
164.308(a)(6)(ii) Response and reporting (R) critical

Identify and respond to suspected or known security incidents; mitigate, to the extent practicable, harmful effects of security incidents that are known to the entity; and document security incidents and their outcomes.

Administrative safeguards incident-responsebreach-notification
164.308(a)(7)(ii)(A) Data backup plan (R) critical

Establish and implement procedures to create and maintain retrievable exact copies of electronic protected health information.

Administrative safeguards backup
164.308(a)(7)(ii)(B) Disaster recovery plan (R) high

Establish and implement procedures to restore any loss of data.

Administrative safeguards recoverybusiness-continuity
164.308(a)(7)(ii)(C) Emergency mode operation plan (R) medium

Establish and implement procedures to enable continuation of critical business processes for protection of the security of electronic protected health information while operating in emergency mode.

Administrative safeguards business-continuity
164.308(a)(7)(ii)(D) Testing and revision procedures (A) medium

Implement procedures for periodic testing and revision of contingency plans.

Administrative safeguards dr-testing
164.308(a)(8) Evaluation (R) high

Perform a periodic technical and non-technical evaluation of the extent to which the entity's security policies and procedures meet the requirements of the Security Rule.

Administrative safeguards audit
164.308(b)(1) Business associate contracts (R) critical

A covered entity may permit a business associate to create, receive, maintain or transmit electronic protected health information on its behalf only if it obtains satisfactory assurances, documented through a written business associate agreement, that the business associate will appropriately safeguard the information.

Organisational requirements vendor-managementthird-party
164.310(a)(1) Facility access controls (R) medium

Implement policies and procedures to limit physical access to electronic information systems and the facilities in which they are housed, while ensuring that properly authorised access is allowed.

Physical safeguards physical-security
164.310(b)-(c) Workstation use and security (R) medium

Specify the proper functions to be performed and the manner in which they are to be performed for workstations that access electronic protected health information, and implement physical safeguards to restrict access to authorised users.

Physical safeguards endpointphysical-security
164.310(d)(1) Device and media controls (R) high

Implement policies and procedures that govern the receipt and removal of hardware and electronic media that contain electronic protected health information into and out of a facility, and the movement of these items within the facility, including disposal, media re-use, accountability and data backup and storage.

Physical safeguards media-disposalasset-management
164.312(a)(1) Access control — unique identification and emergency access (R/A) critical

Implement technical policies and procedures for electronic information systems that maintain electronic protected health information to allow access only to authorised persons or software programmes, including unique user identification and emergency access procedures, with automatic logoff and encryption/decryption as addressable specifications.

Technical safeguards access-controlauthentication
164.312(b) Audit controls (R) critical

Implement hardware, software and procedural mechanisms that record and examine activity in information systems that contain or use electronic protected health information.

Technical safeguards loggingaudit
164.312(c)(1) Integrity (R/A) high

Implement policies and procedures to protect electronic protected health information from improper alteration or destruction, with mechanisms to authenticate ePHI as an addressable specification.

Technical safeguards integrity
164.312(d) Person or entity authentication (R) critical

Implement procedures to verify that a person or entity seeking access to electronic protected health information is the one claimed.

Technical safeguards authenticationmfa
164.312(e)(1) Transmission security (R/A) critical

Implement technical security measures to guard against unauthorised access to electronic protected health information that is being transmitted over an electronic communications network, with integrity controls and encryption as addressable specifications.

Technical safeguards encryption-in-transit
164.312(a)(2)(iv) Encryption and decryption at rest (A) critical

Implement a mechanism to encrypt and decrypt electronic protected health information. Where encryption is not implemented, the entity must document why it is not reasonable and appropriate and what equivalent alternative measure is in place.

Technical safeguards encryption-at-restkey-management
164.404-410 Breach notification to individuals, HHS and the media critical

Following the discovery of a breach of unsecured protected health information, notify each affected individual without unreasonable delay and no later than 60 days after discovery (§164.404); for a breach affecting more than 500 residents of a state or jurisdiction, also notify prominent media outlets (§164.406); notify HHS — within the same 60-day window for breaches affecting 500 or more individuals, and within 60 days of the end of the calendar year for smaller ones (§164.408). A business associate must notify the covered entity (§164.410).

Breach Notification Rule breach-notificationincident-response