A covered entity must mitigate, to the extent practicable, any harmful effect known to it of a use or disclosure of PHI in violation of its policies and procedures or the Privacy Rule, whether by the entity or its business associate, per 164.530(f).
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.