HIPAA Security Rule
Administrative

HIPAA Security Rule 164.308(a)(4)(ii)(A): Isolating Health Care Clearinghouse Functions (Required if applicable)

If a clearinghouse is part of a larger organization, isolate ePHI from the larger organization. NIST recommends network segmentation and separate access domains.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 49 controls across 23 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

NIST SP 800-53 Rev 5 · 5 controls

  • NIST800-AC-4 Information flow enforcement
  • NIST800-SC-3 Security Function Isolation. Isolate security functions from nonsecurity functions
  • NIST800-SC-32 System Partitioning. Partition the system into [organization-defined] residing in separate [organization-defined] domains or environments based on [organization-defined]
  • NIST800-SC-46 Cross Domain Policy Enforcement. Implement a policy enforcement mechanism [organization-defined] between the physical and/or network interfaces for the connecting security domains
  • NIST800-SC-7 Boundary protection

CIS Controls v8 · 4 controls

  • CIS-12.2 Establish and Maintain a Secure Network Architecture
  • CIS-12.8 Establish and Maintain Dedicated Computing Resources for All Administrative Work
  • CIS-13.4 Perform Traffic Filtering Between Network Segments
  • CIS-3.12 Segment Data Processing and Storage Based on Sensitivity

ISO 27701:2019 · 4 controls

  • 6.10.1 Network security management
  • 6.3.1 Internal organization
  • 6.5.2 Information classification
  • 6.6.2 User access management

SOC 2 · 4 controls

  • SOC2-C1.1 Confidential information is identified and protected during receipt, processing, storage
  • SOC2-CC6.1 Implements logical access security software, infrastructure and architectures over protected information assets
  • SOC2-CC6.3 Role-based access and least privilege are enforced
  • SOC2-CC6.6 Measures against threats outside system boundaries are implemented

FedRAMP High · 3 controls

  • AC-4 Information Flow Enforcement
  • AC-4(21) Physical or Logical Separation of Information Flows
  • SC-7 Boundary Protection

FedRAMP Moderate · 3 controls

  • AC-4 Information Flow Enforcement
  • AC-4(21) Physical or Logical Separation of Information Flows
  • SC-7 Boundary Protection

NIST SP 800-171 Rev 3 · 3 controls

  • ASBv3-GS-2 Define and implement enterprise segmentation/separation of duties strategy
  • NS-1 Establish network segmentation boundaries

CMMC 2.0 · 2 controls

NIST SP 800-172 · 2 controls

  • 3.13.4e Physical and Logical Isolation Techniques
  • 3.14.3e Include Systems in Scope of Enhanced Requirements or Segregate into Purpose-Specific Networks
  • AC-4 Information Flow Enforcement
  • SC-7 Boundary Protection
  • AC-4 Information Flow Enforcement
  • SC-7 Boundary Protection

PCI DSS 4.0 · 2 controls

  • 1.4.1 NSCs between trusted and untrusted networks
  • 2.2.3 Primary functions isolated or secured to highest level
  • ASD37-22 Network segmentation (Excellent)
  • AUCDR-IS-STEP2 Step 2 - Define the boundaries of the CDR data environment

C5 (Germany) · 1 control

  • C5-OPS-24 Separation of Datasets in the Cloud Infrastructure

ISO 27001:2022 · 1 control

  • 8.22 Segregation of networks

ISO 27002:2022 · 1 control

  • 8.22 Segregation of networks
  • NIST-CSF-PR.IR-01 Networks and environments are protected from unauthorized logical access and usage
  • SC-7 Boundary Protection

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Administrative

You are reading one control. How much of HIPAA Security Rule have you already done?

HIPAA Security Rule 164.308(a)(4)(ii)(A) is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of HIPAA Security Rule your existing evidence covers. Hold ISO 27001:2022 and 53 of 67 HIPAA Security Rule controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 64 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 49 it maps to, and the evidence behind each claim, over MCP and REST.