HBNR crosswalk to comprehensive security + privacy + health frameworks. NIST CSF 2.0 mapping: GOVERN (privacy officer + IR + records + TPSP) + IDENTIFY (PHR identifiable info inventory + 3rd-party SDK audit + affected individual identification) + PROTECT (encryption per NIST 800-111/52 + access controls + DLP) + DETECT (monitoring + alerting + 60-day discovery clock + SDK audit) + RESPOND (60-day individual notification + 10-day FTC + media + TPSP coordination) + RECOVER (records + lessons learned + annual log). NIST SP 800-66 IMPLEMENTING THE HIPAA SECURITY RULE: companion guidance for healthcare-related security practices - applicable to HBNR even though HBNR is not HIPAA - via best-practice safeguards. ISO/IEC 27001:2022 + ISO/IEC 27701:2019: ISMS + PIMS structure for HBNR program implementation. ISO/IEC 27799:2016: Health Informatics Information Security Management (sector-specific extension of ISO 27002 for health data). SOC 2 + SOC 3: service-organization controls for health-data processors + TPSPs. HIPAA SECURITY RULE: separate-but-similar framework for HIPAA-covered entities; HBNR-covered entities should consider voluntary alignment for best-practice + cross-jurisdictional clients. ENGAGEMENT: organisations should maintain HBNR + NIST CSF + ISO 27001 + HIPAA crosswalks + state-law overlays (WA MHMD + CT + NV + others).
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.