US
HIPAA Security Rule
HIPAA Security Rule (45 CFR Part 164, Subpart C)
45 CFR 164.302-318
18 controls · 3 domains
Mandatory for: US federal law
About this framework
The HIPAA Security Rule is the US standard for protecting electronic health information. It requires healthcare organisations and their partners to apply administrative, physical, and technical safeguards to keep patient data secure.
Who needs this
Mandatory for US healthcare providers, health plans, and the vendors that handle patient data.
Cross-framework coverage
Controls in HIPAA Security Rule also cover:
NIST CSF 14 shared
CIS Controls 14 shared
NCA ECC-2 14 shared
Qatar NIA 14 shared
UAE IA 14 shared
See how HIPAA Security Rule connects to the rest → the Security Universe
Control domains
administrative-safeguards · Administrative Safeguards 9
164.308(a)(1)
Security Management Process
164.308(a)(2)
Assigned Security Responsibility
164.308(a)(3)
Workforce Security
164.308(a)(4)
Information Access Management
164.308(a)(5)
Security Awareness and Training
164.308(a)(6)
Security Incident Procedures
164.308(a)(7)
Contingency Plan
164.308(a)(8)
Evaluation
164.308(b)(1)
Business Associate Contracts and Other Arrangement
physical-safeguards · Physical Safeguards 4
164.310(a)(1)
Facility Access Controls
164.310(b)
Workstation Use
164.310(c)
Workstation Security
164.310(d)(1)
Device and Media Controls
technical-safeguards · Technical Safeguards 5
164.312(a)(1)
Access Control
164.312(b)
Audit Controls
164.312(c)(1)
Integrity
164.312(d)
Person or Entity Authentication
164.312(e)(1)
Transmission Security
Ready to assess against HIPAA Security Rule?
Start free trial →