← Frameworks / Healthcare Regulation

HIPAA Security Rule (45 CFR Part 160 and Part 164, Subparts A and C)

US federal regulation establishing national standards for protecting electronic protected health information (ePHI). 63 specifications across administrative safeguards (security management, workforce security, information access, awareness training, security incident procedures, contingency planning), physical safeguards (facility access, workstation use, device controls), and technical safeguards (access control, audit controls, integrity, authentication, transmission security). Covers all HIPAA covered entities and business associates.

Clause Title SP 800-53 Controls
§164.308(a)(1)(i) Security Management Process (Standard)
§164.308(a)(1)(ii)(A) Risk Analysis (Required)
§164.308(a)(1)(ii)(B) Risk Management (Required)
§164.308(a)(1)(ii)(C) Sanction Policy (Required)
§164.308(a)(1)(ii)(D) Information System Activity Review (Required)
§164.308(a)(2) Assigned Security Responsibility (Standard, Required)
§164.308(a)(3)(i) Workforce Security (Standard)
§164.308(a)(3)(ii)(A) Authorization and/or Supervision (Addressable)
§164.308(a)(3)(ii)(B) Workforce Clearance Procedure (Addressable)
§164.308(a)(3)(ii)(C) Termination Procedures (Addressable)
§164.308(a)(4)(i) Information Access Management (Standard)
§164.308(a)(4)(ii)(A) Isolating Healthcare Clearinghouse Functions (Required)
§164.308(a)(4)(ii)(B) Access Authorization (Addressable)
§164.308(a)(4)(ii)(C) Access Establishment and Modification (Addressable)
§164.308(a)(5)(i) Security Awareness and Training (Standard)
§164.308(a)(5)(ii)(A) Security Reminders (Addressable)
§164.308(a)(5)(ii)(B) Protection from Malicious Software (Addressable)
§164.308(a)(5)(ii)(C) Log-in Monitoring (Addressable)
§164.308(a)(5)(ii)(D) Password Management (Addressable)
§164.308(a)(6)(i) Security Incident Procedures (Standard)
§164.308(a)(6)(ii) Response and Reporting (Required)
§164.308(a)(7)(i) Contingency Plan (Standard)
§164.308(a)(7)(ii)(A) Data Backup Plan (Required)
§164.308(a)(7)(ii)(B) Disaster Recovery Plan (Required)
§164.308(a)(7)(ii)(C) Emergency Mode Operation Plan (Required)
§164.308(a)(7)(ii)(D) Testing and Revision Procedures (Addressable)
§164.308(a)(7)(ii)(E) Applications and Data Criticality Analysis (Addressable)
§164.308(a)(8) Evaluation (Standard, Required)
§164.308(b)(1) Business Associate Contracts and Other Arrangements (Standard)
§164.308(b)(3) Written Contract or Other Arrangement (Required)
§164.310(a)(1) Facility Access Controls (Standard)
§164.310(a)(2)(i) Contingency Operations (Addressable)
§164.310(a)(2)(ii) Facility Security Plan (Addressable)
§164.310(a)(2)(iii) Access Control and Validation Procedures (Addressable)
§164.310(a)(2)(iv) Maintenance Records (Addressable)
§164.310(b) Workstation Use (Standard, Required)
§164.310(c) Workstation Security (Standard, Required)
§164.310(d)(1) Device and Media Controls (Standard)
§164.310(d)(2)(i) Disposal (Required)
§164.310(d)(2)(ii) Media Re-use (Required)
§164.310(d)(2)(iii) Accountability (Addressable)
§164.310(d)(2)(iv) Data Backup and Storage (Addressable)
§164.312(a)(1) Access Control (Standard)
§164.312(a)(2)(i) Unique User Identification (Required)
§164.312(a)(2)(ii) Emergency Access Procedure (Required)
§164.312(a)(2)(iii) Automatic Logoff (Addressable)
§164.312(a)(2)(iv) Encryption and Decryption (Addressable)
§164.312(b) Audit Controls (Standard, Required)
§164.312(c)(1) Integrity (Standard)
§164.312(c)(2) Mechanism to Authenticate Electronic Protected Health Information (Addressable)
§164.312(d) Person or Entity Authentication (Standard, Required)
§164.312(e)(1) Transmission Security (Standard)
§164.312(e)(2)(i) Integrity Controls (Addressable)
§164.312(e)(2)(ii) Encryption (Addressable)
§164.314(a)(1) Business Associate Contracts or Other Arrangements (Standard)
§164.314(a)(2) Business Associate Contract Requirements (Required)
§164.314(b)(1) Requirements for Group Health Plans (Standard)
§164.314(b)(2) Group Health Plan Implementation Specifications (Required)
§164.316(a) Policies and Procedures (Standard, Required)
§164.316(b)(1) Documentation (Standard)
§164.316(b)(2)(i) Time Limit (Required)
§164.316(b)(2)(ii) Availability (Required)
§164.316(b)(2)(iii) Updates (Required)