HIPAA Controls Knowledge Base

Comprehensive guide to HIPAA Security Rule controls with implementation guidance, NIST references, and best practices

0 controls found
Security Officer
164.308(a)(1)
High

A covered entity must designate a security official who is responsible for developing and implementing its security policies and procedures....

Administrative Safeguards Moderate
17 views Read More
Workforce Security
164.308(a)(2)
High

Implement policies and procedures to ensure that all members of the workforce have appropriate access to electronic protected health information (ePHI...

Administrative Safeguards Moderate
13 views Read More
Information Access Management
164.308(a)(3)
High

Implement policies and procedures for authorizing access to ePHI that are consistent with the applicable requirements of the Security Rule....

Administrative Safeguards Complex
3 views Read More
Security Awareness and Training
164.308(a)(4)
High

Implement a security awareness and training program for all members of the workforce (including management)....

Administrative Safeguards Moderate
8 views Read More
Security Incident Procedures
164.308(a)(5)
Critical

Implement policies and procedures to address security incidents....

Administrative Safeguards Complex
4 views Read More
Contingency Plan
164.308(a)(6)
Critical

Establish (and implement as needed) policies and procedures for responding to an emergency or other occurrence (for example, fire, vandalism, system f...

Administrative Safeguards Complex
5 views Read More
Evaluation
164.308(a)(7)
High

Perform a periodic technical and non-technical evaluation, based initially upon the standards implemented under this rule and subsequently, in respons...

Administrative Safeguards Moderate
5 views Read More
Facility Access Controls
164.310(a)(1)
High

Implement policies and procedures to limit physical access to electronic information systems and the facility or facilities in which they are housed, ...

Physical Safeguards Moderate
5 views Read More
Workstation Use
164.310(a)(2)
Medium

Implement policies and procedures that specify the proper functions to be performed, the manner in which those functions are to be performed, and the ...

Physical Safeguards Moderate
5 views Read More
Workstation Controls
164.310(a)(2)(ii)
Medium

Implement physical safeguards for all workstations that access ePHI, to restrict access to authorized users....

Physical Safeguards Moderate
3 views Read More
Media Controls
164.310(b)
High

Implement policies and procedures that govern the receipt and removal of hardware and electronic media that contain ePHI into and out of a facility, a...

Physical Safeguards Moderate
5 views Read More
Device and Media Controls
164.310(c)
High

Implement policies and procedures to address the final disposition of ePHI, and/or the hardware or electronic media on which it is stored....

Physical Safeguards Moderate
4 views Read More
Access Control
164.312(a)(1)
Critical

Implement technical policies and procedures for electronic information systems that maintain ePHI to allow access only to those persons or software pr...

Technical Safeguards Complex
7 views Read More
Audit Controls
164.312(a)(2)
High

Implement hardware, software, and/or procedural mechanisms that record and examine activity in information systems that contain or use ePHI....

Technical Safeguards Moderate
12 views Read More
Integrity
164.312(b)
High

Implement policies and procedures to protect ePHI from improper alteration or destruction....

Technical Safeguards Moderate
4 views Read More
Person or Entity Authentication
164.312(c)
Critical

Implement procedures to verify that a person or entity seeking access to ePHI is the one claimed....

Technical Safeguards Moderate
4 views Read More
Transmission Security
164.312(e)
Critical

Implement technical security measures to guard against unauthorized access to ePHI that is being transmitted over an electronic communications network...

Technical Safeguards Moderate
4 views Read More
Business Associate Contracts or Other Arrangements
164.314(a)(1)
High

A covered entity may permit a business associate to create, receive, maintain, or transmit ePHI on the covered entity's behalf only if the covered ent...

Organizational Requirements Moderate
4 views Read More
Requirements for Group Health Plans
164.314(a)(2)
High

Except when the only ePHI disclosed to a plan sponsor is disclosed pursuant to 164.504(f)(1)(ii) or (iii), or as permitted under 164.508(a)(3)(i), a g...

Organizational Requirements Moderate
4 views Read More
Policies and Procedures
164.316(a)
High

Implement reasonable and appropriate policies and procedures to comply with the standards, implementation specifications, or other requirements of thi...

Policies and Procedures Complex
4 views Read More
Documentation
164.316(b)(1)
High

Maintain the policies and procedures implemented to comply with this subpart in written (which may be electronic) form....

Policies and Procedures Moderate
4 views Read More
Time Limit
164.316(b)(2)
Medium

Retain the documentation required by paragraph (b)(1) of this section for 6 years from the date of its creation or the date when it last was in effect...

Policies and Procedures Moderate
3 views Read More