logo

Database

HIPAA

Last updated: 2023/09/18
logo

The Health Insurance Portability and Accountability Act of 1996 required the Secretary of the U.S. Department of Health and Human Services (HHS) to develop regulations protecting the privacy and security of certain health information. The version used in this section is the HIPAA Rules 2013 update.

Control-Requirement Mapping

DefinitionRequirements
164_308_a_1_ii_D. Information system activity review (required)
164_308_a_3_i. Standard: workforce security
164_308_a_3_ii_A. Authorization or supervision (addressable)
164_310_a_2_iii. Access control and validation procedures (addressable)
164_310_d_2_i. Disposal (required)
164_312_a_1. Standard: access control
164_312_a_2_i. Unique user identification (required)
164_312_a_2_iii. Automatic logoff (addressable)
164_312_a_2_iv. Encryption and decryption (addressable)
164_312_b. Standard: audit controls
164_312_d. Standard: person or entity authentication
164_312_e_1. Standard: transmission security
164_312_e_2_i. Integrity controls (addressable)