164.314(b)(1) Requirements for Group Health Plans (Standard)
164.314(b)(1) in HIPAA Security Rule (the HIPAA Security Rule as it currently stands). All HIPAA Security Rule controls held. Open HIPAA Security Rule on the standards site.
The control as we hold it
Requirements for Group Health Plans (Standard). Except when the only ePHI disclosed to a plan sponsor is disclosed pursuant to 164.504(f)(1)(ii) or (iii), or as authorized under 164.508, a group health plan must ensure that its plan documents provide that the plan sponsor will reasonably and appropriately safeguard ePHI created, received, maintained, or transmitted to or by the plan sponsor on behalf of the group health plan.
Reviewed and closest counterparts in the other frameworks
Reviewed rows come from a released pair; a closest match is the nearest held text and is not a reviewed row.
SOC 2
- SOC2-C1.1 C1.1 Identifying and maintaining confidential information (closest match)
- SOC2-CC6.1 CC6.1 Logical access security over protected information assets (closest match)
- SOC2-CC6.3 CC6.3 Role-based access, least privilege and segregation of duties (closest match)
- SOC2-P6.4 P6.4 Privacy commitments from vendors and third parties (closest match)
- SOC2-P6.5 P6.5 Vendor commitments to report unauthorised disclosures (closest match)
NIST SP 800-53 Rev 5
- NIST800-AC-6 AC-6 Least Privilege (closest match)
- NIST800-MP-5 MP-5 Media Transport (closest match)
- NIST800-RA-8 RA-8 Privacy Impact Assessments (closest match)
- NIST800-SC-8 SC-8 Transmission Confidentiality and Integrity (closest match)
What an auditor commonly asks for
General guidance for this control area (domain: Organizational), in our words, not a statement of the standard and not binding on an assessor.
- the signed business-associate agreements
- the review and updated agreements with their record