A covered entity must have and apply appropriate sanctions against workforce members who fail to comply with its privacy policies and procedures or the Privacy Rule, and document the sanctions applied, per 164.530(e).
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.