A covered entity must have in place appropriate administrative, technical and physical safeguards to protect the privacy of PHI, and reasonably safeguard PHI from any intentional or unintentional use or disclosure that would violate the Privacy Rule, and to limit incidental uses or disclosures, per 164.530(c).
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.