HIPAA Security Rule
The HHS standards for protecting the confidentiality, integrity, and availability of electronic protected health information (ePHI), binding on covered entities and, since the 2013 Omnibus Rule, directly on business associates and their subcontractors. Required specifications must be implemented; for addressable ones the organization must assess whether the specification is reasonable and appropriate, implement it if so, and otherwise document why and adopt an equivalent alternative where reasonable (45 CFR 164.306(d)). HHS proposed in a January 2025 NPRM to remove the addressable distinction and make nearly all specifications required; that rule is not final, and this catalog tracks the rule currently in force.
Where we stand
40 of 50 clauses mapped to adopted controls
As of (just now)
Percentages are over clauses mapped to at least one adopted control. Unmapped clauses are listed below and never count as passing. A known gap is a clause that applies to us and that no control covers yet.
Clause-by-clause readiness
| Clause | Title | Controls | Evidence | Policies | Last tested |
|---|---|---|---|---|---|
| §164.308(a)(1)(i) Security management process | |||||
| §164.308(a)(1)(ii)(A) | Risk analysis (Required) Controls: BIZ-04 | Passing | Not current | Not approved | Not yet |
| §164.308(a)(1)(ii)(B) | Risk management (Required) Controls: BIZ-04, BIZ-05, BIZ-07 | Passing | Not current | Not approved | (4 mo ago) |
| §164.308(a)(1)(ii)(C) | Sanction policy (Required) Controls: PEOPLE-07 | Passing | Not current | Not approved | Not yet |
| §164.308(a)(1)(ii)(D) | Information system activity review (Required) Controls: BIZ-03, IAM-09, MON-03 | Not passing | Not current | Not approved | (8 h ago) |
| §164.308 Administrative safeguards | |||||
| §164.308(a)(2) | Assigned security responsibility (Required) Controls: BIZ-15 | Passing | Not current | Not approved | Not yet |
| §164.308(a)(3)(i) Workforce security | |||||
| §164.308(a)(3)(ii)(A) | Authorization and/or supervision (Addressable) Controls: IAM-05, IAM-07 | Not passing | Not current | Not approved | (29 d ago) |
| §164.308(a)(3)(ii)(B) | Workforce clearance procedure (Addressable) Controls: PEOPLE-01, PEOPLE-08 | Not passing | Not current | Not approved | (4 mo ago) |
| §164.308(a)(3)(ii)(C) | Termination procedures (Addressable) Controls: PEOPLE-03 | Passing | Current | Not approved | (8 h ago) |
| §164.308(a)(4)(i) Information access management | |||||
| §164.308(a)(4)(ii)(A) | Isolating health care clearinghouse functions (Required) | Unmapped | Unmapped | Unmapped | Not yet |
| §164.308(a)(4)(ii)(B) | Access authorization (Addressable) Controls: IAM-04, IAM-05, IAM-07 | Not passing | Not current | Not approved | (29 d ago) |
| §164.308(a)(4)(ii)(C) | Access establishment and modification (Addressable) Controls: IAM-05, IAM-07, IAM-09 | Not passing | Not current | Not approved | (29 d ago) |
| §164.308(a)(5)(i) Security awareness and training | |||||
| §164.308(a)(5)(ii)(A) | Security reminders (Addressable) Controls: PEOPLE-06 | Not passing | Current | Approved | (8 h ago) |
| §164.308(a)(5)(ii)(B) | Protection from malicious software (Addressable) | Unmapped | Unmapped | Unmapped | Not yet |
| §164.308(a)(5)(ii)(C) | Log-in monitoring (Addressable) Controls: MON-03 | Not passing | Not current | Not approved | (3 mo ago) |
| §164.308(a)(5)(ii)(D) | Password management (Addressable) Controls: IAM-03, IAM-08 | Passing | Not current | Not approved | (8 h ago) |
| §164.308(a)(6)(i) Security incident procedures | |||||
| §164.308(a)(6)(ii) | Response and reporting (Required) Controls: BIZ-02, BIZ-03 | Passing | Not current | Not approved | (8 h ago) |
| §164.308(a)(7)(i) Contingency plan | |||||
| §164.308(a)(7)(ii)(A) | Data backup plan (Required) Controls: DATA-12, DATA-13, DATA-14 | Passing | Not current | Not approved | (29 d ago) |
| §164.308(a)(7)(ii)(B) | Disaster recovery plan (Required) Controls: BIZ-01, DATA-15 | Passing | Not current | Not approved | (3 mo ago) |
| §164.308(a)(7)(ii)(C) | Emergency mode operation plan (Required) Controls: BIZ-01 | Passing | Not current | Not approved | (3 mo ago) |
| §164.308(a)(7)(ii)(D) | Testing and revision procedures (Addressable) Controls: BIZ-20, DATA-15 | Passing | Not current | Not approved | Not yet |
| §164.308(a)(7)(ii)(E) | Applications and data criticality analysis (Addressable) Controls: BIZ-01, IT-05 | Passing | Not current | Not approved | (3 mo ago) |
| §164.308(a)(8) | Evaluation (Required) Controls: BIZ-08, MON-04 | Not passing | Not current | Not approved | (8 h ago) |
| §164.308(b)(1) Business associate contracts and other arrangements | |||||
| §164.308(b)(3) | Written contract or other arrangement (Required) | Unmapped | Unmapped | Unmapped | Not yet |
| §164.310(a)(1) Facility access controls | |||||
| §164.310(a)(2)(i) | Contingency operations (Addressable) Controls: PHYS-01 | Passing | Not current | Not approved | Not yet |
| §164.310(a)(2)(ii) | Facility security plan (Addressable) Controls: PHYS-01 | Passing | Not current | Not approved | Not yet |
| §164.310(a)(2)(iii) | Access control and validation procedures (Addressable) Controls: PHYS-01 | Passing | Not current | Not approved | Not yet |
| §164.310(a)(2)(iv) | Maintenance records (Addressable) Controls: PHYS-01 | Passing | Not current | Not approved | Not yet |
| §164.310 Physical safeguards | |||||
| §164.310(b) | Workstation use (Required) Controls: IT-01 | Passing | Not current | Approved | Not yet |
| §164.310(c) | Workstation security (Required) Controls: IT-02 | Not passing | Not current | Approved | Not yet |
| §164.310(d)(1) Device and media controls | |||||
| §164.310(d)(2)(i) | Disposal (Required) Controls: DATA-05 | Passing | Not current | Not approved | Not yet |
| §164.310(d)(2)(ii) | Media re-use (Required) | Unmapped | Unmapped | Unmapped | Not yet |
| §164.310(d)(2)(iii) | Accountability (Addressable) Controls: IT-04 | Passing | Not current | Not approved | Not yet |
| §164.310(d)(2)(iv) | Data backup and storage (Addressable) Controls: DATA-12 | Passing | Not current | Not approved | (29 d ago) |
| §164.312(a)(1) Access control | |||||
| §164.312(a)(2)(i) | Unique user identification (Required) Controls: IAM-01 | Passing | Current | Not approved | (29 d ago) |
| §164.312(a)(2)(ii) | Emergency access procedure (Required) Controls: BIZ-01 | Passing | Not current | Not approved | (3 mo ago) |
| §164.312(a)(2)(iii) | Automatic logoff (Addressable) | Unmapped | Unmapped | Unmapped | Not yet |
| §164.312(a)(2)(iv) | Encryption and decryption (Addressable) Controls: DATA-02, DATA-06, IT-02 | Not passing | Not current | Not approved | Not yet |
| §164.312 Technical safeguards | |||||
| §164.312(b) | Audit controls (Required) Controls: MON-01, MON-02, MON-03 | Not passing | Not current | Not approved | (3 mo ago) |
| §164.312(c)(1) Integrity | |||||
| §164.312(c)(2) | Mechanism to authenticate electronic protected health information (Addressable) | Unmapped | Unmapped | Unmapped | Not yet |
| §164.312(d) | Person or entity authentication (Required) Controls: IAM-01, IAM-02 | Not passing | Not current | Not approved | (8 h ago) |
| §164.312(e)(1) Transmission security | |||||
| §164.312(e)(2)(i) | Integrity controls (Addressable) Controls: DATA-03 | Passing | Current | Not approved | (8 h ago) |
| §164.312(e)(2)(ii) | Encryption (Addressable) Controls: CLOUD-01, DATA-03, DATA-06 | Not passing | Not current | Not approved | (8 h ago) |
| §164.314(a)(1) Business associate contracts or other arrangements | |||||
| §164.314(a)(2)(i) | Business associate contracts (Required) | Unmapped | Unmapped | Unmapped | Not yet |
| §164.314(a)(2)(ii) | Other arrangements (Required) | Unmapped | Unmapped | Unmapped | Not yet |
| §164.314(a)(2)(iii) | Business associate contracts with subcontractors (Required) | Unmapped | Unmapped | Unmapped | Not yet |
| §164.314(b)(1) Requirements for group health plans | |||||
| §164.314(b)(2) | Implementation specifications (Required) | Unmapped | Unmapped | Unmapped | Not yet |
| §164.316 Policies and procedures and documentation requirements | |||||
| §164.316(a) | Policies and procedures (Required) Controls: BIZ-14 | Passing | Not current | Not approved | Not yet |
| §164.316(b)(1) Documentation | |||||
| §164.316(b)(2)(i) | Time limit (Required) Controls: DATA-04 | Passing | Not current | Not approved | Not yet |
| §164.316(b)(2)(ii) | Availability (Required) Controls: PEOPLE-04 | Passing | Current | Approved | (4 mo ago) |
| §164.316(b)(2)(iii) | Updates (Required) Controls: BIZ-14 | Passing | Not current | Not approved | Not yet |
