HIPAA Security Rule controls
67 controls held for HIPAA Security Rule (HIPAA). Edition: the HIPAA Security Rule as it currently stands. Place a control statement and the reader picks the closest text here and the closest matches in the other frameworks. Open HIPAA Security Rule on the standards site.
| Code | Control | Domain | |
|---|---|---|---|
| 164.306 | Security Standards: General Rules | Administrative | open |
| 164.308(a)(1)(i) | Security Management Process (Standard) | Administrative | open |
| 164.308(a)(1)(ii)(A) | Risk Analysis (Required) | Administrative | open |
| 164.308(a)(1)(ii)(B) | Risk Management (Required) | Administrative | open |
| 164.308(a)(1)(ii)(C) | Sanction Policy (Required) | Administrative | open |
| 164.308(a)(1)(ii)(D) | Information System Activity Review (Required) | Administrative | open |
| 164.308(a)(2) | Assigned Security Responsibility (Standard) | Administrative | open |
| 164.308(a)(3)(i) | Workforce Security (Standard) | Administrative | open |
| 164.308(a)(3)(ii)(A) | Authorization and Supervision (Addressable) | Administrative | open |
| 164.308(a)(3)(ii)(B) | Workforce Clearance Procedure (Addressable) | Administrative | open |
| 164.308(a)(3)(ii)(C) | Termination Procedures (Addressable) | Administrative | open |
| 164.308(a)(4)(i) | Information Access Management (Standard) | Administrative | open |
| 164.308(a)(4)(ii)(A) | Isolating Health Care Clearinghouse Functions (Required if applicable) | Administrative | open |
| 164.308(a)(4)(ii)(B) | Access Authorization (Addressable) | Administrative | open |
| 164.308(a)(4)(ii)(C) | Access Establishment and Modification (Addressable) | Administrative | open |
| 164.308(a)(5)(i) | Security Awareness and Training (Standard) | Administrative | open |
| 164.308(a)(5)(ii)(A) | Security Reminders (Addressable) | Administrative | open |
| 164.308(a)(5)(ii)(B) | Protection from Malicious Software (Addressable) | Administrative | open |
| 164.308(a)(5)(ii)(C) | Log-in Monitoring (Addressable) | Administrative | open |
| 164.308(a)(5)(ii)(D) | Password Management (Addressable) | Administrative | open |
| 164.308(a)(6)(i) | Security Incident Procedures (Standard) | Administrative | open |
| 164.308(a)(6)(ii) | Response and Reporting (Required) | Administrative | open |
| 164.308(a)(7)(i) | Contingency Plan (Standard) | Administrative | open |
| 164.308(a)(7)(ii)(A) | Data Backup Plan (Required) | Administrative | open |
| 164.308(a)(7)(ii)(B) | Disaster Recovery Plan (Required) | Administrative | open |
| 164.308(a)(7)(ii)(C) | Emergency Mode Operation Plan (Required) | Administrative | open |
| 164.308(a)(7)(ii)(D) | Testing and Revision Procedures (Addressable) | Administrative | open |
| 164.308(a)(7)(ii)(E) | Applications and Data Criticality Analysis (Addressable) | Administrative | open |
| 164.308(a)(8) | Evaluation (Standard) | Administrative | open |
| 164.308(b)(1) | Business Associate Contracts and Other Arrangements (Standard) | Administrative | open |
| 164.308(b)(2) | Subcontractor Arrangements | Administrative | open |
| 164.308(b)(3) | Written Contract or Other Arrangement | Administrative | open |
| 164.310(a)(1) | Facility Access Controls (Standard) | Physical | open |
| 164.310(a)(2)(i) | Contingency Operations (Addressable) | Physical | open |
| 164.310(a)(2)(ii) | Facility Security Plan (Addressable) | Physical | open |
| 164.310(a)(2)(iii) | Access Control and Validation Procedures (Addressable) | Physical | open |
| 164.310(a)(2)(iv) | Maintenance Records (Addressable) | Physical | open |
| 164.310(b) | Workstation Use (Standard) | Physical | open |
| 164.310(c) | Workstation Security (Standard) | Physical | open |
| 164.310(d)(1) | Device and Media Controls (Standard) | Physical | open |
| 164.310(d)(2)(i) | Disposal (Required) | Physical | open |
| 164.310(d)(2)(ii) | Media Re-use (Required) | Physical | open |
| 164.310(d)(2)(iii) | Accountability (Addressable) | Physical | open |
| 164.310(d)(2)(iv) | Data Backup and Storage (Addressable) | Physical | open |
| 164.312(a)(1) | Access Control (Standard) | Technical | open |
| 164.312(a)(2)(i) | Unique User Identification (Required) | Technical | open |
| 164.312(a)(2)(ii) | Emergency Access Procedure (Required) | Technical | open |
| 164.312(a)(2)(iii) | Automatic Logoff (Addressable) | Technical | open |
| 164.312(a)(2)(iv) | Encryption and Decryption (Addressable) | Technical | open |
| 164.312(b) | Audit Controls (Standard) | Technical | open |
| 164.312(c)(1) | Integrity (Standard) | Technical | open |
| 164.312(c)(2) | Mechanism to Authenticate ePHI (Addressable) | Technical | open |
| 164.312(d) | Person or Entity Authentication (Standard) | Technical | open |
| 164.312(e)(1) | Transmission Security (Standard) | Technical | open |
| 164.312(e)(2)(i) | Integrity Controls for Transmission (Addressable) | Technical | open |
| 164.312(e)(2)(ii) | Encryption of Transmissions (Addressable) | Technical | open |
| 164.314(a)(1) | Business Associate Contracts or Other Arrangements (Standard) | Organizational | open |
| 164.314(a)(2)(i) | Business Associate Contract Required Provisions | Organizational | open |
| 164.314(a)(2)(ii) | Other Arrangements (Government) | Organizational | open |
| 164.314(a)(2)(iii) | Business Associate Contracts with Subcontractors | Organizational | open |
| 164.314(b)(1) | Requirements for Group Health Plans (Standard) | Organizational | open |
| 164.314(b)(2) | Implementation Specifications for Group Health Plans | Organizational | open |
| 164.316(a) | Policies and Procedures (Standard) | Policies and Procedures | open |
| 164.316(b)(1) | Documentation (Standard) | Policies and Procedures | open |
| 164.316(b)(2)(i) | Time Limit (Documentation Retention) | Policies and Procedures | open |
| 164.316(b)(2)(ii) | Availability (Documentation) | Policies and Procedures | open |
| 164.316(b)(2)(iii) | Updates (Documentation) | Policies and Procedures | open |