HIPAA Security Rule
Administrative

HIPAA Security Rule 164.308(a)(5)(ii)(D): Password Management (Addressable)

Implement procedures for creating, changing, and safeguarding passwords. NIST recommends aligning to SP 800-63B authenticator assurance levels and considering multi-factor authentication for ePHI access.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 60 controls across 23 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

PCI DSS 4.0 · 10 controls

  • 2.2.2 2.2.2 Vendor default accounts managed
  • 2.2.6 2.2.6 System security parameters configured against misuse
  • 8.3.10 8.3.10 Service provider customer password guidance
  • 8.3.10.1 8.3.10.1 Service provider customer passwords 90 days or dynamic
  • 8.3.5 8.3.5 Initial and reset passwords unique and changed
  • 8.3.6 8.3.6 Password minimum length 12 and complexity
  • 8.3.7 8.3.7 No reuse of last four passwords
  • 8.3.8 8.3.8 Authentication policies communicated to users
  • 8.6.2 8.6.2 No hard-coded passwords for interactive system accounts
  • 8.6.3 8.6.3 System account passwords protected against misuse

UK Cyber Essentials · 5 controls

  • CE-FW.2 Change Default Firewall Passwords
  • CE-SC.2 Change Default Passwords on Devices and Software
  • CE-SC.5 Password-Based Authentication Quality
  • CE-SC.7 Educate Users on Strong Passwords
  • CE-SC.8 Process for Compromised Passwords

CMMC 2.0 · 4 controls

NIST SP 800-171 Rev 3 · 4 controls

  • ANSSI-HYG-10 Define and Verify Password Selection and Sizing Rules
  • ANSSI-HYG-11 Protect Passwords Stored on Systems
  • ANSSI-HYG-12 Change Default Authentication Elements on Equipment and Services

C5 (Germany) · 3 controls

  • C5-IDM-08 Confidentiality of authentication information
  • C5-IDM-09 Authentication mechanisms
  • C5-PSS-07 Confidentiality of Authentication Information

FedRAMP High · 3 controls

  • IA-5 Authenticator Management
  • IA-5(1) Password-Based Authentication
  • IA-5(6) Protection of Authenticators

FedRAMP Moderate · 3 controls

  • IA-5 Authenticator Management
  • IA-5(1) Password-Based Authentication
  • IA-5(6) Protection of Authenticators
  • ASD37-21 Disable local administrator accounts (Excellent)
  • ASD37-23 Protect authentication credentials (Excellent)
  • ASBv3-IM-8 Restrict the exposure of credential and secrets
  • IM-3 Manage application identities securely and automatically

CIS Controls v8 · 2 controls

  • CIS-14.3 Train Workforce Members on Authentication Best Practices
  • CIS-5.2 Use Unique Passwords

ISO 27001:2022 · 2 controls

  • 5.17 Authentication information
  • 8.5 Secure authentication
  • NIST-CSF-PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization
  • NIST-CSF-PR.AA-03 Users, services, and hardware are authenticated

SOC 2 · 2 controls

  • SOC2-CC6.1 CC6.1 Logical access security over protected information assets
  • SOC2-CC6.2 CC6.2 Registering and authorising users before issuing credentials
  • E8-ADMIN-ML2 Restrict Administrative Privileges (ML2)
  • AUCDR-IS-1 Limit risk of unauthorised access to the CDR data environment

ISO 27002:2022 · 1 control

  • 5.17 Authentication information

ISO 27701:2019 · 1 control

  • 6.6.2 User access management

NIST SP 800-172 · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Administrative

You are reading one control. How much of HIPAA Security Rule have you already done?

HIPAA Security Rule 164.308(a)(5)(ii)(D) is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of HIPAA Security Rule your existing evidence covers. Hold ISO 27001:2022 and 53 of 67 HIPAA Security Rule controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 64 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 60 it maps to, and the evidence behind each claim, over MCP and REST.