HIPAA Security Rule
HIPAA covered entities (health plans, health care clearinghouses, health care providers that transmit health information electronically) and their business associates.
edition 45 CFR Part 164, Subpart C, from the eCFR text held. 11 requirements cited here. Every HIPAA Security Rule clause we hold.
Staff sign in to email and the online services that hold business data (office suite, accounting, practice or client software) with multi-factor authentication
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| 164.312(d) HIPAA Security Rule | Person or Entity Authentication (Standard) Implement procedures to verify that a person or entity seeking access to ePHI is the one claimed. NIST recommends multi-factor authentication and authenticator assurance levels per SP 800-63B. evidence an assessor asks for Authentication standard aligned to NIST SP 800-63B; MFA deployment report; Service account authentication design; Federation and SSO design |
Backups of data, applications and settings run on a schedule set by how critical each system is, and can be restored to a common point in time
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| 164.308(a)(7)(ii)(A) HIPAA Security Rule | Data Backup Plan (Required) Establish procedures to create and maintain retrievable exact copies of ePHI. NIST recommends offline or immutable backups, encryption, and regular restoration testing. evidence an assessor asks for Backup policy and schedule; Backup completion logs; Restoration test results; Immutable or offline backup evidence |
Restoring from backup is tested as part of a disaster recovery exercise
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| 164.308(a)(7)(ii)(D) HIPAA Security Rule | Testing and Revision Procedures (Addressable) Implement procedures for periodic testing and revision of contingency plans. NIST recommends annual tabletop, biennial functional, and post-incident lessons-learned updates. evidence an assessor asks for Test schedule; Test reports; After-action reports; Plan revision history |
Privileged access events and logs from internet-facing servers are collected centrally, protected from change, and reviewed in a timely manner
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| 164.312(b) HIPAA Security Rule | Audit Controls (Standard) Implement hardware, software, and procedural mechanisms that record and examine activity in information systems that contain or use ePHI. NIST recommends central log management aligned to SP 800-92. evidence an assessor asks for Logging standard; Central log management deployment; Log retention configuration; SIEM use case catalog |
There is a written cyber security incident response plan, it is enacted when an incident is identified, and incidents are reported internally and to the authority the rule names
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| 164.308(a)(6)(ii) HIPAA Security Rule | Response and Reporting (Required) Identify and respond to suspected or known incidents, mitigate harmful effects, and document incidents and their outcomes. NIST recommends linkage to HIPAA Breach Notification Rule timelines. evidence an assessor asks for Incident ticket log; Post-incident reports; Breach risk assessments per 164.402; Notification records (individuals, HHS, media) |
Every workstation and server runs centrally managed, behaviour-based anti-malware (often sold as endpoint detection and response)
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| 164.308(a)(5)(ii)(B) HIPAA Security Rule | Protection from Malicious Software (Addressable) Implement procedures for guarding against, detecting, and reporting malicious software. NIST recommends endpoint protection, email filtering, web filtering, and user reporting channels. evidence an assessor asks for Endpoint protection deployment report; Email gateway configuration; Malware incident records; User reporting procedure |
Staff are trained to recognise phishing and other social engineering, and to report a suspected incident
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| 164.308(a)(5)(i) HIPAA Security Rule | Security Awareness and Training (Standard) Implement a security awareness and training program for all workforce members. NIST recommends role-based content, onboarding plus annual refresh, and reinforcement reminders. evidence an assessor asks for Training curriculum; Completion records by workforce member; Role-based modules; Awareness campaigns calendar |
Laptops, phones and removable media that hold sensitive data are encrypted
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| 164.312(a)(2)(iv) HIPAA Security Rule | Encryption and Decryption (Addressable) Implement a mechanism to encrypt and decrypt ePHI. NIST recommends FIPS 140-validated cryptography, encryption at rest for all ePHI stores, and key management aligned to SP 800-57. evidence an assessor asks for Encryption standard; FIPS 140 validation references; Key management procedures; Database, file, and endpoint encryption coverage report |
IT and cloud providers with access to systems or data are listed, and their contracts carry security requirements
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| 164.314(a)(1) HIPAA Security Rule | Business Associate Contracts or Other Arrangements (Standard) The contract or other arrangement required by 164.308(b)(3) must meet the requirements of paragraph (a)(2)(i), (a)(2)(ii), or (a)(2)(iii) of this section, as applicable. evidence an assessor asks for BAA template addressing all required 164.314(a)(2) elements; Government arrangement documentation where applicable; Special arrangement records (group health plan, plan sponsor); Subcontractor BAAs flowing down requirements; Legal review records for BAAs; Inventory of BAAs by type (BA, subcontractor, government); Procedures for negotiating BAA exceptions; Termination provisions evidence |
A written information security program exists, owned by a named qualified individual or officer
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| 164.308(a)(1)(i) HIPAA Security Rule | Security Management Process (Standard) Implement policies and procedures to prevent, detect, contain, and correct security violations. NIST recommends establishing an enterprise security governance program with defined roles and risk-based decision making. evidence an assessor asks for Information security policy; Security program charter; Governance committee minutes; Risk management framework documentation |
A written risk assessment of the information systems is done and repeated periodically
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| 164.308(a)(1)(ii)(A) HIPAA Security Rule | Risk Analysis (Required) Conduct accurate and thorough assessment of potential risks and vulnerabilities to ePHI. NIST recommends the nine-step risk analysis methodology and integration with NIST SP 800-30 and the NIST RMF. evidence an assessor asks for Documented risk analysis report; Risk analysis methodology aligned to NIST SP 800-30; Periodic refresh schedule; Evidence of ePHI scoping |
Questions
- When does HIPAA Security Rule apply here?
- HIPAA covered entities (health plans, health care clearinghouses, health care providers that transmit health information electronically) and their business associates.
- Which edition is held?
- 45 CFR Part 164, Subpart C, from the eCFR text held
- Is a gap against it a finding about the business?
- No. A gap is a control the list marks partly, not in place or not sure; the page shows the requirement behind it and never rules on the business.