164.308(b)(2) Subcontractor Arrangements
164.308(b)(2) in HIPAA Security Rule (the HIPAA Security Rule as it currently stands). All HIPAA Security Rule controls held. Open HIPAA Security Rule on the standards site.
The control as we hold it
Subcontractor Arrangements. A business associate may permit a business associate that is a subcontractor to create, receive, maintain, or transmit electronic protected health information on its behalf only if the business associate obtains satisfactory assurances, in accordance with 164.314(a), that the subcontractor will appropriately safeguard the information.
Reviewed and closest counterparts in the other frameworks
Reviewed rows come from a released pair; a closest match is the nearest held text and is not a reviewed row.
SOC 2
- SOC2-CC9.2 CC9.2 Assessing and managing vendor and business partner risk (closest match)
- SOC2-P6.4 P6.4 Privacy commitments from vendors and third parties (closest match)
- SOC2-P6.5 P6.5 Vendor commitments to report unauthorised disclosures (closest match)
NIST SP 800-53 Rev 5
- NIST800-PM-17 PM-17 Protecting Controlled Unclassified Information on External Systems (closest match)
- NIST800-SA-9 SA-9 External System Services (closest match)
- NIST800-SR-2 SR-2 Supply Chain Risk Management Plan (closest match)
- NIST800-SR-3 SR-3 Supply Chain Controls and Processes (closest match)
- NIST800-SR-6 SR-6 Supplier Assessments and Reviews (closest match)
What an auditor commonly asks for
General guidance for this control area (domain: Administrative), in our words, not a statement of the standard and not binding on an assessor.
- the risk analysis and risk-management records
- the workforce clearance, training and sanction records
- the access-authorisation and termination records
- the contingency-plan test and evaluation records