← All frameworks
US US · 8 Policy & Process · US

HIPAA Security Rule

HIPAA Security Rule (45 CFR Part 164, Subpart C)

45 CFR 164.302-318

18 controls · 3 domains · 36 sub-controls
Mandatory for: US federal law
Start assessment in platform →

About this framework

The HIPAA Security Rule is the US standard for protecting electronic health information. It requires healthcare organisations and their partners to apply administrative, physical, and technical safeguards to keep patient data secure.

Who needs this

Mandatory for US healthcare providers, health plans, and the vendors that handle patient data.

Cross-framework coverage

Controls in HIPAA Security Rule also cover:

ADHICS 14 shared
NCA ECC-2 14 shared
NCA OTCC 14 shared
NIST CSF 14 shared
Qatar NIA 14 shared

See how HIPAA Security Rule connects to the rest → the Security Universe

Control domains

administrative-safeguards · Administrative Safeguards 9
164.308(a)(1)
Security Management Process
4 sub-controls
  • 164.308(a)(1)#1 Risk Analysis
  • 164.308(a)(1)#2 Risk Management
  • 164.308(a)(1)#3 Sanction Policy
  • 164.308(a)(1)#4 Information System Activity Review
CJISCIS ControlsDORAGDPR (EU)ISO 27001NCA CCCNCA ECC-2NCA OTCCNIS2NIST CSFPDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPRADHICSPCI DSS 4.0.1
164.308(a)(2)
Assigned Security Responsibility
CJISCIS ControlsDORAGDPR (EU)ISO 27001NCA CCCNCA ECC-2NCA OTCCNIS2NIST CSFPDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPRADHICSPCI DSS 4.0.1
164.308(a)(3)
Workforce Security
3 sub-controls
  • 164.308(a)(3)#1 Authorization and/or Supervision
  • 164.308(a)(3)#2 Workforce Clearance Procedure
  • 164.308(a)(3)#3 Termination Procedures
ADHICSCJISCIS ControlsCyber EssentialsCyber Essentials PlusGDPR (EU)ISO 27001NCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPRNCA CCC
164.308(a)(4)
Information Access Management
3 sub-controls
  • 164.308(a)(4)#1 Isolating Health care Clearinghouse Function
  • 164.308(a)(4)#2 Access Authorization
  • 164.308(a)(4)#3 Access Establishment and Modification
ADHICSCJISCIS ControlsCyber EssentialsCyber Essentials PlusGDPR (EU)ISO 27001NCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPR
164.308(a)(5)
Security Awareness and Training
4 sub-controls
  • 164.308(a)(5)#1 Security Reminders
  • 164.308(a)(5)#2 Protection from Malicious Software
  • 164.308(a)(5)#3 Log-in Monitoring
  • 164.308(a)(5)#4 Password Management
CJISADHICSCIS ControlsGDPR (EU)ISO 27001NCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1Qatar NIASAMA CSFUAE IAUK GDPR
164.308(a)(6)
Security Incident Procedures
1 sub-control
  • 164.308(a)(6)#1 Response and Reporting
CJISADHICSCIS ControlsDORAGDPR (EU)ISO 27001NCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPR
164.308(a)(7)
Contingency Plan
5 sub-controls
  • 164.308(a)(7)#1 Data Backup Plan
  • 164.308(a)(7)#2 Disaster Recovery Plan
  • 164.308(a)(7)#3 Emergency Mode Operation Plan
  • 164.308(a)(7)#4 Testing and Revision Procedure
  • 164.308(a)(7)#5 Applications and Data Criticality Analysis
ADHICSCJISCIS ControlsDORAGDPR (EU)ISO 27001NCA CCCNCA ECC-2NCA OTCCNIS2NIST CSFPDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIAUAE IAUK GDPR
164.308(a)(8)
Evaluation
CJISCIS ControlsDORAGDPR (EU)ISO 27001NCA CCCNCA ECC-2NCA OTCCNIS2NIST CSFPDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPRADHICSPCI DSS 4.0.1
164.308(b)(1)
Business Associate Contracts and Other Arrangement
1 sub-control
  • 164.308(b)(1)#1 Written Contract or Other Arrangement
CJISADHICSCIS ControlsDORAGDPR (EU)ISO 27001NCA CCCNCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPR
physical-safeguards · Physical Safeguards 4
164.310(a)(1)
Facility Access Controls
4 sub-controls
  • 164.310(a)(1)#1 Contingency Operations
  • 164.310(a)(1)#2 Facility Security Plan
  • 164.310(a)(1)#3 Access Control and Validation Procedures
  • 164.310(a)(1)#4 Maintenance Records
ADHICSISO 27001NCA CCCNCA ECC-2NCA OTCCNIST CSFPCI DSS 4.0.1Qatar NIASAMA CSFUAE IA
164.310(b)
Workstation Use
ADHICSCJISCIS ControlsCyber EssentialsCyber Essentials PlusGDPR (EU)ISO 27001NCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPRNCA CCC
164.310(c)
Workstation Security
ADHICSISO 27001NCA CCCNCA ECC-2NCA OTCCNIST CSFPCI DSS 4.0.1Qatar NIASAMA CSFUAE IA
164.310(d)(1)
Device and Media Controls
4 sub-controls
  • 164.310(d)(1)#1 Disposal
  • 164.310(d)(1)#2 Media Re-use
  • 164.310(d)(1)#3 Accountability
  • 164.310(d)(1)#4 Data Backup and Storage
ADHICSCJISCIS ControlsCyber EssentialsCyber Essentials PlusDORAGDPR (EU)ISO 27001NCA CCCNCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPR
technical-safeguards · Technical Safeguards 5
164.312(a)(1)
Access Control
4 sub-controls
  • 164.312(a)(1)#1 Unique User Identification
  • 164.312(a)(1)#2 Emergency Access Procedure
  • 164.312(a)(1)#3 Automatic Logoff
  • 164.312(a)(1)#4 Encryption and Decryption
ADHICSCJISCIS ControlsCyber EssentialsCyber Essentials PlusGDPR (EU)ISO 27001NCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPR
164.312(b)
Audit Controls
ADHICSCJISCIS ControlsDORAGDPR (EU)ISO 27001NCA CCCNCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPR
164.312(c)(1)
Integrity
1 sub-control
  • 164.312(c)(1)#1 Mechanism to Authenticate Electronic Protected Health Information
UAE IACJISADHICSCIS ControlsGDPR (EU)ISO 27001NCA CCCNCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUK GDPR
164.312(d)
Person or Entity Authentication
ADHICSCJISCIS ControlsCyber EssentialsCyber Essentials PlusGDPR (EU)ISO 27001NCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUAE IAUK GDPR
164.312(e)(1)
Transmission Security
2 sub-controls
  • 164.312(e)(1)#1 Integrity Controls
  • 164.312(e)(1)#2 Encryption
UAE IACJISADHICSCIS ControlsGDPR (EU)ISO 27001NCA CCCNCA ECC-2NCA OTCCNIS2NIST CSFPCI DSS 4.0.1PDPLData-protection rulesPDPPLPDPL – Federal Decree-Law 45/2021Qatar NIASAMA CSFUK GDPR

Ready to assess against HIPAA Security Rule?

Start free trial →

Where to go next

See it priced

Map HIPAA Security Rule on any plan — active frameworks scale by tier.

Pricing →

Talk to us

Book a walkthrough with someone who knows the platform.

Book a walkthrough →