A covered entity must implement policies and procedures reasonably designed, given its size and the nature of its activities, to comply with the Privacy Rule, and must change them as necessary and appropriate to comply with changes in the law, documenting the change, per 164.530(i).
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.