FintastIQTrust Center
LoginBook a Consultation
Framework

HIPAA Security Rule

Version: 45 CFR Part 164 Subpart C (as amended 2013)

The HHS standards for protecting the confidentiality, integrity, and availability of electronic protected health information (ePHI), binding on covered entities and, since the 2013 Omnibus Rule, directly on business associates and their subcontractors. Required specifications must be implemented; for addressable ones the organization must assess whether the specification is reasonable and appropriate, implement it if so, and otherwise document why and adopt an equivalent alternative where reasonable (45 CFR 164.306(d)). HHS proposed in a January 2025 NPRM to remove the addressable distinction and make nearly all specifications required; that rule is not final, and this catalog tracks the rule currently in force.

Official source

Summary

Where we stand

Controls
67%
Evidence
12%
Policies
10%

40 of 50 clauses mapped to adopted controls

As of (just now)

Percentages are over clauses mapped to at least one adopted control. Unmapped clauses are listed below and never count as passing. A known gap is a clause that applies to us and that no control covers yet.

Clauses

Clause-by-clause readiness

ClauseTitleControlsEvidencePoliciesLast tested
§164.308(a)(1)(i) Security management process
§164.308(a)(1)(ii)(A)Risk analysis (Required)
Controls: BIZ-04
PassingNot currentNot approvedNot yet
§164.308(a)(1)(ii)(B)Risk management (Required)
Controls: BIZ-04, BIZ-05, BIZ-07
PassingNot currentNot approved(4 mo ago)
§164.308(a)(1)(ii)(C)Sanction policy (Required)
Controls: PEOPLE-07
PassingNot currentNot approvedNot yet
§164.308(a)(1)(ii)(D)Information system activity review (Required)
Controls: BIZ-03, IAM-09, MON-03
Not passingNot currentNot approved(8 h ago)
§164.308 Administrative safeguards
§164.308(a)(2)Assigned security responsibility (Required)
Controls: BIZ-15
PassingNot currentNot approvedNot yet
§164.308(a)(3)(i) Workforce security
§164.308(a)(3)(ii)(A)Authorization and/or supervision (Addressable)
Controls: IAM-05, IAM-07
Not passingNot currentNot approved(29 d ago)
§164.308(a)(3)(ii)(B)Workforce clearance procedure (Addressable)
Controls: PEOPLE-01, PEOPLE-08
Not passingNot currentNot approved(4 mo ago)
§164.308(a)(3)(ii)(C)Termination procedures (Addressable)
Controls: PEOPLE-03
PassingCurrentNot approved(8 h ago)
§164.308(a)(4)(i) Information access management
§164.308(a)(4)(ii)(A)Isolating health care clearinghouse functions (Required)UnmappedUnmappedUnmappedNot yet
§164.308(a)(4)(ii)(B)Access authorization (Addressable)
Controls: IAM-04, IAM-05, IAM-07
Not passingNot currentNot approved(29 d ago)
§164.308(a)(4)(ii)(C)Access establishment and modification (Addressable)
Controls: IAM-05, IAM-07, IAM-09
Not passingNot currentNot approved(29 d ago)
§164.308(a)(5)(i) Security awareness and training
§164.308(a)(5)(ii)(A)Security reminders (Addressable)
Controls: PEOPLE-06
Not passingCurrentApproved(8 h ago)
§164.308(a)(5)(ii)(B)Protection from malicious software (Addressable)UnmappedUnmappedUnmappedNot yet
§164.308(a)(5)(ii)(C)Log-in monitoring (Addressable)
Controls: MON-03
Not passingNot currentNot approved(3 mo ago)
§164.308(a)(5)(ii)(D)Password management (Addressable)
Controls: IAM-03, IAM-08
PassingNot currentNot approved(8 h ago)
§164.308(a)(6)(i) Security incident procedures
§164.308(a)(6)(ii)Response and reporting (Required)
Controls: BIZ-02, BIZ-03
PassingNot currentNot approved(8 h ago)
§164.308(a)(7)(i) Contingency plan
§164.308(a)(7)(ii)(A)Data backup plan (Required)
Controls: DATA-12, DATA-13, DATA-14
PassingNot currentNot approved(29 d ago)
§164.308(a)(7)(ii)(B)Disaster recovery plan (Required)
Controls: BIZ-01, DATA-15
PassingNot currentNot approved(3 mo ago)
§164.308(a)(7)(ii)(C)Emergency mode operation plan (Required)
Controls: BIZ-01
PassingNot currentNot approved(3 mo ago)
§164.308(a)(7)(ii)(D)Testing and revision procedures (Addressable)
Controls: BIZ-20, DATA-15
PassingNot currentNot approvedNot yet
§164.308(a)(7)(ii)(E)Applications and data criticality analysis (Addressable)
Controls: BIZ-01, IT-05
PassingNot currentNot approved(3 mo ago)
§164.308(a)(8)Evaluation (Required)
Controls: BIZ-08, MON-04
Not passingNot currentNot approved(8 h ago)
§164.308(b)(1) Business associate contracts and other arrangements
§164.308(b)(3)Written contract or other arrangement (Required)UnmappedUnmappedUnmappedNot yet
§164.310(a)(1) Facility access controls
§164.310(a)(2)(i)Contingency operations (Addressable)
Controls: PHYS-01
PassingNot currentNot approvedNot yet
§164.310(a)(2)(ii)Facility security plan (Addressable)
Controls: PHYS-01
PassingNot currentNot approvedNot yet
§164.310(a)(2)(iii)Access control and validation procedures (Addressable)
Controls: PHYS-01
PassingNot currentNot approvedNot yet
§164.310(a)(2)(iv)Maintenance records (Addressable)
Controls: PHYS-01
PassingNot currentNot approvedNot yet
§164.310 Physical safeguards
§164.310(b)Workstation use (Required)
Controls: IT-01
PassingNot currentApprovedNot yet
§164.310(c)Workstation security (Required)
Controls: IT-02
Not passingNot currentApprovedNot yet
§164.310(d)(1) Device and media controls
§164.310(d)(2)(i)Disposal (Required)
Controls: DATA-05
PassingNot currentNot approvedNot yet
§164.310(d)(2)(ii)Media re-use (Required)UnmappedUnmappedUnmappedNot yet
§164.310(d)(2)(iii)Accountability (Addressable)
Controls: IT-04
PassingNot currentNot approvedNot yet
§164.310(d)(2)(iv)Data backup and storage (Addressable)
Controls: DATA-12
PassingNot currentNot approved(29 d ago)
§164.312(a)(1) Access control
§164.312(a)(2)(i)Unique user identification (Required)
Controls: IAM-01
PassingCurrentNot approved(29 d ago)
§164.312(a)(2)(ii)Emergency access procedure (Required)
Controls: BIZ-01
PassingNot currentNot approved(3 mo ago)
§164.312(a)(2)(iii)Automatic logoff (Addressable)UnmappedUnmappedUnmappedNot yet
§164.312(a)(2)(iv)Encryption and decryption (Addressable)
Controls: DATA-02, DATA-06, IT-02
Not passingNot currentNot approvedNot yet
§164.312 Technical safeguards
§164.312(b)Audit controls (Required)
Controls: MON-01, MON-02, MON-03
Not passingNot currentNot approved(3 mo ago)
§164.312(c)(1) Integrity
§164.312(c)(2)Mechanism to authenticate electronic protected health information (Addressable)UnmappedUnmappedUnmappedNot yet
§164.312(d)Person or entity authentication (Required)
Controls: IAM-01, IAM-02
Not passingNot currentNot approved(8 h ago)
§164.312(e)(1) Transmission security
§164.312(e)(2)(i)Integrity controls (Addressable)
Controls: DATA-03
PassingCurrentNot approved(8 h ago)
§164.312(e)(2)(ii)Encryption (Addressable)
Controls: CLOUD-01, DATA-03, DATA-06
Not passingNot currentNot approved(8 h ago)
§164.314(a)(1) Business associate contracts or other arrangements
§164.314(a)(2)(i)Business associate contracts (Required)UnmappedUnmappedUnmappedNot yet
§164.314(a)(2)(ii)Other arrangements (Required)UnmappedUnmappedUnmappedNot yet
§164.314(a)(2)(iii)Business associate contracts with subcontractors (Required)UnmappedUnmappedUnmappedNot yet
§164.314(b)(1) Requirements for group health plans
§164.314(b)(2)Implementation specifications (Required)UnmappedUnmappedUnmappedNot yet
§164.316 Policies and procedures and documentation requirements
§164.316(a)Policies and procedures (Required)
Controls: BIZ-14
PassingNot currentNot approvedNot yet
§164.316(b)(1) Documentation
§164.316(b)(2)(i)Time limit (Required)
Controls: DATA-04
PassingNot currentNot approvedNot yet
§164.316(b)(2)(ii)Availability (Required)
Controls: PEOPLE-04
PassingCurrentApproved(4 mo ago)
§164.316(b)(2)(iii)Updates (Required)
Controls: BIZ-14
PassingNot currentNot approvedNot yet
HIPAA Security Rule readiness · FintastIQ Trust Center