← All frameworks

HIPAA

47 controls · Security Rule, 45 CFR Part 164 Subpart C

The rules for protecting health information. There is no certificate to earn - HIPAA is enforced by audit and by what happens after a breach, so what matters is being able to show what you do and why.

Administrative Safeguards

164.308(a)(1)(ii)(A)Risk Analysis

You have worked out where health information lives in your systems and what could go wrong with it, and written that down.

Conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information held by the organisation.

Required - there is no alternative route to satisfying this one.

164.308(a)(1)(ii)(B)Risk Management

You have acted on what the risk assessment found, rather than filing it and moving on.

Implement security measures sufficient to reduce risks and vulnerabilities to a reasonable and appropriate level.

Required - there is no alternative route to satisfying this one.

164.308(a)(1)(ii)(C)Sanction Policy

Your team knows what happens if someone ignores the security rules, and it is written down before it is needed.

Apply appropriate sanctions against workforce members who fail to comply with the security policies and procedures of the organisation.

Required - there is no alternative route to satisfying this one.

164.308(a)(1)(ii)(D)Information System Activity Review

Someone reads your access logs and security reports on a regular schedule, rather than only after something has gone wrong.

Implement procedures to regularly review records of information system activity, such as audit logs, access reports, and security incident tracking reports.

Required - there is no alternative route to satisfying this one.

164.308(a)(2)Assigned Security Responsibility

One named person is responsible for security here, and everyone knows who that is. It can be a part-time role, but it cannot be nobody.

Identify the security official who is responsible for the development and implementation of the policies and procedures required of the organisation by the Security Rule.

Required - there is no alternative route to satisfying this one.

164.308(a)(3)(ii)(A)Authorization and/or Supervision

Nobody starts working with health information without being approved for it, or supervised by someone who already is.

Implement procedures for the authorisation and/or supervision of workforce members who work with electronic protected health information or in locations where it might be accessed.

Addressable - you may implement an equivalent measure, and must document why.

164.308(a)(3)(ii)(B)Workforce Clearance Procedure

Before you give someone access to health records, you check that their job actually needs it.

Implement procedures to determine that the access of a workforce member to electronic protected health information is appropriate.

Addressable - you may implement an equivalent measure, and must document why.

164.308(a)(3)(ii)(C)Termination Procedures

When someone leaves, their access to health information goes the same day, and you work from a checklist so nothing is missed.

Implement procedures for terminating access to electronic protected health information when the employment of, or other arrangement with, a workforce member ends.

Addressable - you may implement an equivalent measure, and must document why.

164.308(a)(4)(ii)(A)Isolating Health Care Clearinghouse Functions

If part of your business is a health care clearinghouse, its health information is walled off from the rest of the company. Most organisations are not clearinghouses, and for them this one does not apply.

If a health care clearinghouse is part of a larger organisation, the clearinghouse must implement policies and procedures that protect its electronic protected health information from unauthorised access by the larger organisation.

Required - there is no alternative route to satisfying this one.

164.308(a)(4)(ii)(B)Access Authorization

Someone approves each person's access to health records before it is granted, and you can say who approved what.

Implement policies and procedures for granting access to electronic protected health information, for example through access to a workstation, transaction, program, process, or other mechanism.

Addressable - you may implement an equivalent measure, and must document why.

164.308(a)(4)(ii)(C)Access Establishment and Modification

You review who has access to health information from time to time, and you change it when someone's job changes.

Implement policies and procedures that, based upon the organisation's access authorisation policies, establish, document, review, and modify a user's right of access to a workstation, transaction, program, or process.

Addressable - you may implement an equivalent measure, and must document why.

164.308(a)(5)(ii)(A)Security Reminders

Your team hears about security more than once a year, in short reminders they actually read.

Provide periodic security updates to members of the workforce as part of the security awareness and training programme.

Addressable - you may implement an equivalent measure, and must document why.

164.308(a)(5)(ii)(B)Protection from Malicious Software

Your computers are protected against malware, and your team knows who to tell when something looks wrong.

Implement procedures for guarding against, detecting, and reporting malicious software.

Addressable - you may implement an equivalent measure, and must document why.

164.308(a)(5)(ii)(C)Log-in Monitoring

You would notice a run of failed log-in attempts on an account that reaches health information, and someone would look into it.

Implement procedures for monitoring log-in attempts and reporting discrepancies.

Addressable - you may implement an equivalent measure, and must document why.

164.308(a)(5)(ii)(D)Password Management

You have rules for how passwords are created and kept safe, and people are not sharing one login between them.

Implement procedures for creating, changing, and safeguarding passwords.

Addressable - you may implement an equivalent measure, and must document why.

164.308(a)(6)(ii)Response and Reporting

When something goes wrong you act on it, limit the damage, and write down what happened and what you did about it.

Identify and respond to suspected or known security incidents; mitigate, to the extent practicable, harmful effects of security incidents that are known to the organisation; and document security incidents and their outcomes.

Required - there is no alternative route to satisfying this one.

164.308(a)(7)(ii)(A)Data Backup Plan

You keep backups of your health information, and you could get an exact copy back if the original were lost.

Establish and implement procedures to create and maintain retrievable exact copies of electronic protected health information.

Required - there is no alternative route to satisfying this one.

164.308(a)(7)(ii)(B)Disaster Recovery Plan

You have written down how you would restore lost health information, so the steps are not being invented on a bad day.

Establish (and implement as needed) procedures to restore any loss of electronic protected health information data.

Required - there is no alternative route to satisfying this one.

164.308(a)(7)(ii)(C)Emergency Mode Operation Plan

You know how you would keep looking after people, and keep their information safe, while your main systems were down.

Establish (and implement as needed) procedures to enable continuation of critical business processes for protection of the security of electronic protected health information while operating in emergency mode.

Required - there is no alternative route to satisfying this one.

164.308(a)(7)(ii)(D)Testing and Revision Procedures

You have tested your recovery plan rather than assuming it works, and you updated it with what the test showed.

Implement procedures for periodic testing and revision of contingency plans.

Addressable - you may implement an equivalent measure, and must document why.

164.308(a)(7)(ii)(E)Applications and Data Criticality Analysis

You know which systems and records you would need back first, and which ones could wait a week.

Assess the relative criticality of specific applications and data in support of other contingency plan components.

Addressable - you may implement an equivalent measure, and must document why.

164.308(a)(8)Evaluation

You check on a regular schedule whether your safeguards still match how you work now, and you write down what you found.

Perform a periodic technical and nontechnical evaluation, based initially upon the standards implemented under the Security Rule and subsequently in response to environmental or operational changes affecting the security of electronic protected health information, that establishes the extent to which the organisation's security policies and procedures meet the requirements of the Security Rule.

Required - there is no alternative route to satisfying this one.

164.308(b)(3)Written Contract or Other Arrangement

Every outside company that touches your health information has signed a business associate agreement, and you can put your hands on the signed copy.

Document the satisfactory assurances required of a business associate, or of a subcontractor, through a written contract or other arrangement that meets the applicable requirements of 45 CFR 164.314(a). This is the single implementation specification of the business associate standard at 45 CFR 164.308(b)(1) and (b)(2).

Required - there is no alternative route to satisfying this one.

Physical Safeguards

164.310(a)(2)(i)Contingency Operations

You know who can get into the building, and how, when you need to restore systems after an emergency.

Establish (and implement as needed) procedures that allow facility access in support of restoration of lost data under the disaster recovery plan and emergency mode operations plan in the event of an emergency.

Addressable - you may implement an equivalent measure, and must document why.

164.310(a)(2)(ii)Facility Security Plan

Your premises and the equipment in them are protected from people walking in, and you have written down how.

Implement policies and procedures to safeguard the facility and the equipment therein from unauthorised physical access, tampering, and theft.

Addressable - you may implement an equivalent measure, and must document why.

164.310(a)(2)(iii)Access Control and Validation Procedures

Visitors and contractors are signed in and accompanied, and people can only get into the areas their job needs.

Implement procedures to control and validate a person's access to facilities based on their role or function, including visitor control, and control of access to software programs for testing and revision.

Addressable - you may implement an equivalent measure, and must document why.

164.310(a)(2)(iv)Maintenance Records

You keep a record when locks, doors, or alarms are repaired or changed, so you can show the building stayed secure.

Implement policies and procedures to document repairs and modifications to the physical components of a facility which are related to security, such as hardware, walls, doors, and locks.

Addressable - you may implement an equivalent measure, and must document why.

164.310(b)Workstation Use

You have written down how computers that reach health records may be used, including whether they can be taken home.

Implement policies and procedures that specify the proper functions to be performed, the manner in which those functions are to be performed, and the physical attributes of the surroundings of a specific workstation or class of workstation that can access electronic protected health information.

Required - there is no alternative route to satisfying this one.

164.310(c)Workstation Security

Screens showing health information cannot be read by people passing by, and devices are not left unlocked and unattended.

Implement physical safeguards for all workstations that access electronic protected health information, to restrict access to authorised users.

Required - there is no alternative route to satisfying this one.

164.310(d)(2)(i)Disposal

Old computers, drives, and phones are wiped or destroyed before they leave your hands, and you keep a record of it.

Implement policies and procedures to address the final disposition of electronic protected health information, and of the hardware or electronic media on which it is stored.

Required - there is no alternative route to satisfying this one.

164.310(d)(2)(ii)Media Re-use

Before a device is handed to someone else, the health information on it is properly removed rather than just deleted.

Implement procedures for removal of electronic protected health information from electronic media before the media are made available for re-use.

Required - there is no alternative route to satisfying this one.

164.310(d)(2)(iii)Accountability

You know where your laptops, drives, and backup media are, and who has each one.

Maintain a record of the movements of hardware and electronic media and of any person responsible therefor.

Addressable - you may implement an equivalent measure, and must document why.

164.310(d)(2)(iv)Data Backup and Storage

Before equipment holding health information is moved, you take a copy, so a drop or a theft does not lose the only version.

Create a retrievable, exact copy of electronic protected health information, when needed, before movement of equipment.

Addressable - you may implement an equivalent measure, and must document why.

Technical Safeguards

164.312(a)(2)(i)Unique User Identification

Every person has their own login, so you can tell who did what. A shared account does not meet this one.

Assign a unique name and/or number for identifying and tracking user identity.

Required - there is no alternative route to satisfying this one.

164.312(a)(2)(ii)Emergency Access Procedure

There is a way to reach health records in an emergency when the normal route is unavailable, and it is written down in advance.

Establish (and implement as needed) procedures for obtaining necessary electronic protected health information during an emergency.

Required - there is no alternative route to satisfying this one.

164.312(a)(2)(iii)Automatic Logoff

Computers lock themselves after a few minutes of inactivity, so an unattended screen does not stay open to health records.

Implement electronic procedures that terminate an electronic session after a predetermined time of inactivity.

Addressable - you may implement an equivalent measure, and must document why.

164.312(a)(2)(iv)Encryption and Decryption

Health information stored on your laptops, servers, and phones is encrypted, so a lost device does not become a breach.

Implement a mechanism to encrypt and decrypt electronic protected health information.

Addressable - you may implement an equivalent measure, and must document why.

164.312(b)Audit Controls

Your systems record who opened which health record and when, and those records are kept.

Implement hardware, software, and/or procedural mechanisms that record and examine activity in information systems that contain or use electronic protected health information.

Required - there is no alternative route to satisfying this one.

164.312(c)(1)Integrity

You have written down who is allowed to change or delete a health record, and your systems hold people to it.

Implement policies and procedures to protect electronic protected health information from improper alteration or destruction.

Required - there is no alternative route to satisfying this one.

164.312(c)(2)Mechanism to Authenticate Electronic Protected Health Information

You would be able to tell if a health record had been changed or deleted when it should not have been.

Implement electronic mechanisms to corroborate that electronic protected health information has not been altered or destroyed in an unauthorised manner. This is the single implementation specification of the Integrity standard at 45 CFR 164.312(c)(1).

Addressable - you may implement an equivalent measure, and must document why.

164.312(d)Person or Entity Authentication

Your systems check that people are who they say they are before letting them in. A password on its own is a weak check.

Implement procedures to verify that a person or entity seeking access to electronic protected health information is the one claimed.

Required - there is no alternative route to satisfying this one.

164.312(e)(2)(i)Integrity Controls

When health information is sent somewhere, you would know if it arrived changed or incomplete.

Implement security measures to ensure that electronically transmitted electronic protected health information is not improperly modified without detection until disposed of.

Addressable - you may implement an equivalent measure, and must document why.

164.312(e)(2)(ii)Encryption

Health information is encrypted while it travels - in email, in file transfers, and across your network.

Implement a mechanism to encrypt electronic protected health information whenever deemed appropriate.

Addressable - you may implement an equivalent measure, and must document why.

Policies, Procedures and Documentation

164.316(a)Policies and Procedures

Your security rules are written down and match how you actually work, rather than being a template someone downloaded.

Implement reasonable and appropriate policies and procedures to comply with the standards and other requirements of the Security Rule, taking into account the factors at 45 CFR 164.306(b)(2). The Documentation standard at 45 CFR 164.316(b)(1) further requires that they be kept in written, which may be electronic, form.

Required - there is no alternative route to satisfying this one.

164.316(b)(2)(i)Time Limit

You keep your security policies and records for six years, counting from when each one was written or last in force.

Retain the documentation required by 45 CFR 164.316(b)(1) - the written policies and procedures, and a written record of every action, activity or assessment the Security Rule requires to be documented - for six years from the date of its creation or the date when it last was in effect, whichever is later.

Required - there is no alternative route to satisfying this one.

164.316(b)(2)(ii)Availability

The people who have to follow a procedure can find it themselves, rather than it sitting on one person's laptop.

Make documentation available to those persons responsible for implementing the procedures to which the documentation pertains.

Required - there is no alternative route to satisfying this one.

164.316(b)(2)(iii)Updates

You revisit your security documents when something changes - a new system, a new site, a new way of working - and update them.

Review documentation periodically, and update as needed, in response to environmental or operational changes affecting the security of the electronic protected health information.

Required - there is no alternative route to satisfying this one.

What this page is

Our own summary of what each control area covers, written to be read by someone without a compliance background. It is not the text of the standard, and it is not a substitute for it - where a framework is a copyrighted document, you will need your own copy. Nothing here is legal advice or an assurance that following it satisfies an auditor.