HIPAA Security Rule Security Controls
Version 2003
The HIPAA Security Rule (45 CFR Part 164) establishes national standards for protecting electronic Protected Health Information (ePHI). It requires covered entities and their business associates to implement administrative, physical, and technical safeguards that ensure the confidentiality, integrity, and availability of ePHI. Any healthcare provider, health plan, or healthcare clearinghouse that transmits health information electronically must comply.
21
Total controls
7
Critical priority
160h
Est. implementation
5
Trust service categories
The HIPAA Security Rule is United States federal law (45 CFR Parts 160 and 164) and is in the public domain. Control descriptions authored by AuditRubric.
Administrative Safeguards
9 controlsPolicies, procedures, and processes to manage the selection, development, implementation, and maintenance of security measures protecting ePHI and workforce conduct.
Security Management Process
Assigned Security Responsibility
Workforce Security
Information Access Management
Security Awareness and Training
Security Incident Procedures
Contingency Plan
Physical Safeguards
4 controlsPhysical measures, policies, and procedures to protect electronic information systems, buildings, and equipment from natural and environmental hazards and unauthorized intrusion.
Facility Access Controls
Workstation Security
Technical Safeguards
5 controlsTechnology and related policies and procedures that protect ePHI and control access to it.
Audit Controls
Person or Entity Authentication
Organizational Requirements
1 controlsRequirements for contracts and arrangements with business associates and group health plans that handle ePHI.
Business Associate Contract Requirements
Policies & Procedures
2 controlsRequirements to implement reasonable and appropriate policies and procedures and maintain documentation for six years.