HIPAA Security Rule
Administrative

HIPAA Security Rule 164.306: Security Standards: General Rules

Covered entities and business associates must ensure the confidentiality, integrity, and availability of all electronic protected health information (ePHI) they create, receive, maintain, or transmit; protect against reasonably anticipated threats; protect against reasonably anticipated impermissible uses or disclosures; and ensure workforce compliance. Entities may use flexibility of approach considering size, complexity, capabilities, technical infrastructure, costs, and probability and criticality of risks to ePHI.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 94 controls across 27 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

SOC 2 · 10 controls

  • SOC2-C1.1 C1.1 Identifying and maintaining confidential information
  • SOC2-CC1.1 CC1.1 Commitment to integrity and ethical values (COSO principle 1)
  • SOC2-CC3.1 CC3.1 Objectives specified clearly enough to assess risk (COSO principle 6)
  • SOC2-CC3.2 CC3.2 Identifying and analysing risks to objectives (COSO principle 7)
  • SOC2-CC5.1 CC5.1 Selecting control activities that mitigate risk (COSO principle 10)
  • SOC2-CC5.2 CC5.2 General controls over technology (COSO principle 11)
  • SOC2-CC6.1 CC6.1 Logical access security over protected information assets
  • SOC2-CC6.3 CC6.3 Role-based access, least privilege and segregation of duties
  • SOC2-CC9.1 CC9.1 Mitigating risks of business disruption
  • SOC2-P6.3 P6.3 Record of unauthorised disclosures and breaches

CMMC 2.0 · 7 controls

ISO 27002:2022 · 7 controls

  • 5.1 Policies for information security
  • 5.31 Legal, statutory, regulatory and contractual requirements
  • 5.34 Privacy and protection of PII
  • 5.36 Compliance with policies, rules and standards for information security
  • 5.4 Management responsibilities
  • 6.3 Information security awareness, education and training
  • 8.27 Secure system architecture and engineering principles

NIST SP 800-53 Rev 5 · 7 controls

ISO 22301:2019 · 6 controls

  • 4.2.1 General
  • 4.2.2 Legal and regulatory requirements
  • 4.3.1 General
  • 5.1 Leadership and commitment
  • 6.1.2 Addressing risks and opportunities
  • 8.2.3 Risk assessment

ISO 27001:2022 · 6 controls

  • 5.15 Access control
  • 5.2 Information security roles and responsibilities
  • 5.31 Legal, statutory, regulatory and contractual requirements
  • 5.34 Privacy and protection of personal identifiable information (PII)
  • 5.4 Management responsibilities
  • 8.13 Information backup
  • NIST-CSF-GV.OC-03 Legal, regulatory, and contractual requirements regarding cybersecurity - including privacy and civil liberties obligations - are understood and managed
  • NIST-CSF-GV.PO-01 Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforced
  • NIST-CSF-GV.RM-01 Risk management objectives are established and agreed to by organizational stakeholders
  • NIST-CSF-PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind
  • NIST-CSF-PR.DS-01 The confidentiality, integrity, and availability of data-at-rest are protected
  • NIST-CSF-PR.DS-02 The confidentiality, integrity, and availability of data-in-transit are protected
  • CFTC-SS-1 Program of Risk Analysis and Oversight
  • CFTC-SS-12 Capacity and Performance Planning Category
  • CFTC-SS-3 Information Security Category
  • CFTC-SS-7 Generally Accepted Standards and Best Practices

ISO 27701:2019 · 4 controls

  • 5.3.1 Leadership and commitment
  • 5.4.1 Actions to address risks and opportunities
  • 6.15.1 Compliance with legal and contractual requirements
  • 6.4.2 During employment

PCI DSS 4.0 · 4 controls

  • 12.1.1 12.1.1 Overall information security policy established and disseminated
  • 12.1.2 12.1.2 Security policy reviewed annually and updated as needed
  • 12.6.3 12.6.3 Security awareness training on hire and annually with acknowledgment
  • 12.8.2 12.8.2 TPSP contracts acknowledging account data responsibility

APRA CPS 234 · 3 controls

  • CPS234-15 Information Security Capability
  • CPS234-19 Information Security Policy Framework
  • CPS234-21 Implementation of Information Security Controls

C5 (Germany) · 3 controls

  • C5-COM-01 Identification of applicable legal, regulatory, self-imposed or contractual requirements
  • C5-OIS-01 Information Security Management System (ISMS)
  • C5-OIS-02 Information Security Policy

APPI · 2 controls

  • APPI-A23 Security Control Measures
  • APPI-A46 Security and Proper Handling of Anonymized Personal Information
  • CPS220-P22 Framework Structure for Managing Each Material Risk
  • CPS220-P46 Scope of the Comprehensive Review
  • SEC01-BP03 Identify and validate control objectives
  • SEC07-BP02 Apply data protection controls based on data sensitivity
  • AUCDR-IS-STEP3 Step 3 - Have and maintain an information security capability
  • AUCDR-PS-12 Privacy Safeguard 12 - Security of CDR data and destruction or de-identification of redundant CDR data

FedRAMP High · 2 controls

  • PL-2 System Security and Privacy Plans
  • RA-3 Risk Assessment

FedRAMP Moderate · 2 controls

  • PL-2 System Security and Privacy Plans
  • RA-3 Risk Assessment

NIST SP 800-171 Rev 3 · 2 controls

  • CPS230-P25 Information and Technology Capability and Asset Health
  • APP-11 APP 11 - Security of personal information
  • ASBv3-GS-3 Define and implement data protection strategy

NIST SP 800-218 · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Administrative

You are reading one control. How much of HIPAA Security Rule have you already done?

HIPAA Security Rule 164.306 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of HIPAA Security Rule your existing evidence covers. Hold ISO 27001:2022 and 53 of 67 HIPAA Security Rule controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 64 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 94 it maps to, and the evidence behind each claim, over MCP and REST.