Frameworks / HIPAA Security Rule / 164.308(a)(6)(ii) HIPAA Security Rule
Administrative
HIPAA Security Rule 164.308(a)(6)(ii): Response and Reporting (Required) Identify and respond to suspected or known incidents, mitigate harmful effects, and document incidents and their outcomes. NIST recommends linkage to HIPAA Breach Notification Rule timelines.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 104 controls across 31 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
NIST-CSF-DE.AE-04 The estimated impact and scope of adverse events are understood NIST-CSF-DE.AE-06 Information on adverse events is provided to authorized staff and tools NIST-CSF-DE.AE-07 Cyber threat intelligence and other contextual information are integrated into the analysis NIST-CSF-DE.AE-08 Incidents are declared when adverse events meet the defined incident criteria NIST-CSF-ID.IM-03 Improvements are identified from execution of operational processes, procedures, and activities NIST-CSF-RC.CO-04 Public updates on incident recovery are shared using approved methods and messaging NIST-CSF-RS.AN-03 Analysis is performed to establish what has taken place during an incident and the root cause of the incident NIST-CSF-RS.AN-06 Actions performed during an investigation are recorded, and the records' integrity and provenance are preserved NIST-CSF-RS.CO-02 Internal and external stakeholders are notified of incidents NIST-CSF-RS.CO-03 Information is shared with designated internal and external stakeholders NIST-CSF-RS.MA-01 The incident response plan is executed in coordination with relevant third parties once an incident is declared NIST-CSF-RS.MA-03 Incidents are categorized and prioritized NIST-CSF-RS.MA-04 Incidents are escalated or elevated as needed NIST-CSF-RS.MI-01 Incidents are contained NIST-CSF-RS.MI-02 Incidents are eradicated 5.24 Information security incident management planning and preparation 5.25 Assessment and decision on information security events 5.26 Response to information security incidents 5.27 Learning from information security incidents 5.28 Collection of evidence 5.7 Threat intelligence 6.8 Information security event reporting 5.24 Information security incident management planning and preparation 5.25 Assessment and decision on information security events 5.26 Response to information security incidents 5.27 Learning from information security incidents 5.28 Collection of evidence 6.8 Information security event reporting 8.8 Management of technical vulnerabilities CIS-1.2 Address Unauthorized Assets CIS-17.2 Establish and Maintain Contact Information for Reporting Security Incidents CIS-17.3 Establish and Maintain an Enterprise Process for Reporting Incidents CIS-17.4 Establish and Maintain an Incident Response Process CIS-17.6 Define Mechanisms for Communicating During Incident Response CIS-17.8 Conduct Post-Incident Reviews ASBv3-IR-2 Preparation - setup incident notification ASBv3-IR-4 Detection and analysis - investigate an incident ASBv3-IR-5 Detection and analysis - prioritize incidents ASBv3-IR-6 Containment, eradication and recovery - automate the incident handling ASBv3-IR-7 Post-incident activity - conduct lesson learned and retain evidence 10.4.3 10.4.3 Exceptions and anomalies from log review addressed 10.7.2 10.7.2 Detect and alert on critical security control failures 10.7.3 10.7.3 Respond promptly to critical security control failures 12.10.1 12.10.1 Incident response plan ready for activation 12.10.5 12.10.5 Plan covers alerts from security monitoring systems SOC2-CC6.8 CC6.8 Preventing and detecting unauthorised or malicious software SOC2-CC7.3 CC7.3 Evaluating security events to identify incidents SOC2-CC7.4 CC7.4 Responding to security incidents SOC2-P6.3 P6.3 Record of unauthorised disclosures and breaches SOC2-P6.6 P6.6 Notifying breaches and incidents IR-1 Policy and Procedures IR-4 Incident Handling IR-5 Incident Monitoring IR-6 Incident Reporting IR-1 Policy and Procedures IR-4 Incident Handling IR-5 Incident Monitoring IR-6 Incident Reporting CPS234-30 Detection and Response Mechanisms CPS234-35 APRA Notification of Material Incidents within 72 Hours CPS234-P25 Response Plan Content and Escalation Mechanisms SEC10-BP03 Prepare forensic capabilities SEC10-BP04 Develop and test security incident response playbooks SEC10-BP08 Establish a framework for learning from incidents C5-SIM-02 Processing of security incidents C5-SIM-03 Documentation and reporting of security incidents C5-SIM-05 Evaluation and learning process CPS220-19 APRA Notification of Framework Breach within 10 Business Days CPS220-P35 Required Content of Risk Management Policies and Procedures CPS230-27 Identification and Escalation of Incidents and Near Misses CPS230-P33 APRA Notification of Operational Risk Incidents within 72 Hours ASD37-28 Continuous incident detection and response (Excellent) ASD37-30 Endpoint detection and response (Very Good) CFTC-SS-16 Security Incident Response Plan and Testing CFTC-SS-19 Prompt Notification to the Commission 6.13.1 Management of information security incidents and improvements 6.9.6 Technical vulnerability management 03.06.01 Incident Handling 03.06.02 Incident Monitoring, Reporting, and Response Assistance E8-APP-ML3 Application Control (ML3) ANSSI-HYG-40 Define a Security Incident Management Procedure CBPR-PR-32 Detection, prevention and response measures APPI-A26 Report of Leakage to the Commission and Notification to the Person 8.4.3 Warning and communication 3.6.2e Establish and Maintain a Cyber Incident Response Team CE-SC.8 Process for Compromised Passwords Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in Administrative You are reading one control. How much of HIPAA Security Rule have you already done? HIPAA Security Rule 164.308(a)(6)(ii) is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of HIPAA Security Rule your existing evidence covers. Hold ISO 27001:2022 and 53 of 67 HIPAA Security Rule controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 64 were rejected on the ISO 27001:2022 pair alone.
Query this from an agent The graph holds this control, the 104 it maps to, and the evidence behind each claim, over MCP and REST.