HIPAA Security Rule
Administrative

HIPAA Security Rule 164.308(a)(6)(ii): Response and Reporting (Required)

Identify and respond to suspected or known incidents, mitigate harmful effects, and document incidents and their outcomes. NIST recommends linkage to HIPAA Breach Notification Rule timelines.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 104 controls across 31 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • NIST-CSF-DE.AE-04 The estimated impact and scope of adverse events are understood
  • NIST-CSF-DE.AE-06 Information on adverse events is provided to authorized staff and tools
  • NIST-CSF-DE.AE-07 Cyber threat intelligence and other contextual information are integrated into the analysis
  • NIST-CSF-DE.AE-08 Incidents are declared when adverse events meet the defined incident criteria
  • NIST-CSF-ID.IM-03 Improvements are identified from execution of operational processes, procedures, and activities
  • NIST-CSF-RC.CO-04 Public updates on incident recovery are shared using approved methods and messaging
  • NIST-CSF-RS.AN-03 Analysis is performed to establish what has taken place during an incident and the root cause of the incident
  • NIST-CSF-RS.AN-06 Actions performed during an investigation are recorded, and the records' integrity and provenance are preserved
  • NIST-CSF-RS.CO-02 Internal and external stakeholders are notified of incidents
  • NIST-CSF-RS.CO-03 Information is shared with designated internal and external stakeholders
  • NIST-CSF-RS.MA-01 The incident response plan is executed in coordination with relevant third parties once an incident is declared
  • NIST-CSF-RS.MA-03 Incidents are categorized and prioritized
  • NIST-CSF-RS.MA-04 Incidents are escalated or elevated as needed
  • NIST-CSF-RS.MI-01 Incidents are contained
  • NIST-CSF-RS.MI-02 Incidents are eradicated

ISO 27001:2022 · 7 controls

  • 5.24 Information security incident management planning and preparation 
  • 5.25 Assessment and decision on information security events
  • 5.26 Response to information security incidents
  • 5.27 Learning from information security incidents
  • 5.28 Collection of evidence
  • 5.7 Threat intelligence
  • 6.8 Information security event reporting

ISO 27002:2022 · 7 controls

  • 5.24 Information security incident management planning and preparation
  • 5.25 Assessment and decision on information security events
  • 5.26 Response to information security incidents
  • 5.27 Learning from information security incidents
  • 5.28 Collection of evidence
  • 6.8 Information security event reporting
  • 8.8 Management of technical vulnerabilities

CIS Controls v8 · 6 controls

  • CIS-1.2 Address Unauthorized Assets
  • CIS-17.2 Establish and Maintain Contact Information for Reporting Security Incidents
  • CIS-17.3 Establish and Maintain an Enterprise Process for Reporting Incidents
  • CIS-17.4 Establish and Maintain an Incident Response Process
  • CIS-17.6 Define Mechanisms for Communicating During Incident Response
  • CIS-17.8 Conduct Post-Incident Reviews

NIST SP 800-53 Rev 5 · 6 controls

  • ASBv3-IR-2 Preparation - setup incident notification
  • ASBv3-IR-4 Detection and analysis - investigate an incident
  • ASBv3-IR-5 Detection and analysis - prioritize incidents
  • ASBv3-IR-6 Containment, eradication and recovery - automate the incident handling
  • ASBv3-IR-7 Post-incident activity - conduct lesson learned and retain evidence

PCI DSS 4.0 · 5 controls

  • 10.4.3 10.4.3 Exceptions and anomalies from log review addressed
  • 10.7.2 10.7.2 Detect and alert on critical security control failures
  • 10.7.3 10.7.3 Respond promptly to critical security control failures
  • 12.10.1 12.10.1 Incident response plan ready for activation
  • 12.10.5 12.10.5 Plan covers alerts from security monitoring systems

SOC 2 · 5 controls

  • SOC2-CC6.8 CC6.8 Preventing and detecting unauthorised or malicious software
  • SOC2-CC7.3 CC7.3 Evaluating security events to identify incidents
  • SOC2-CC7.4 CC7.4 Responding to security incidents
  • SOC2-P6.3 P6.3 Record of unauthorised disclosures and breaches
  • SOC2-P6.6 P6.6 Notifying breaches and incidents

FedRAMP High · 4 controls

  • IR-1 Policy and Procedures
  • IR-4 Incident Handling
  • IR-5 Incident Monitoring
  • IR-6 Incident Reporting

FedRAMP Moderate · 4 controls

  • IR-1 Policy and Procedures
  • IR-4 Incident Handling
  • IR-5 Incident Monitoring
  • IR-6 Incident Reporting

APRA CPS 234 · 3 controls

  • CPS234-30 Detection and Response Mechanisms
  • CPS234-35 APRA Notification of Material Incidents within 72 Hours
  • CPS234-P25 Response Plan Content and Escalation Mechanisms
  • SEC10-BP03 Prepare forensic capabilities
  • SEC10-BP04 Develop and test security incident response playbooks
  • SEC10-BP08 Establish a framework for learning from incidents

C5 (Germany) · 3 controls

  • C5-SIM-02 Processing of security incidents
  • C5-SIM-03 Documentation and reporting of security incidents
  • C5-SIM-05 Evaluation and learning process

CMMC 2.0 · 3 controls

NIST SP 800-161 Rev 1 · 3 controls

  • CPS220-19 APRA Notification of Framework Breach within 10 Business Days
  • CPS220-P35 Required Content of Risk Management Policies and Procedures
  • CPS230-27 Identification and Escalation of Incidents and Near Misses
  • CPS230-P33 APRA Notification of Operational Risk Incidents within 72 Hours
  • ASD37-28 Continuous incident detection and response (Excellent)
  • ASD37-30 Endpoint detection and response (Very Good)
  • CFTC-SS-16 Security Incident Response Plan and Testing
  • CFTC-SS-19 Prompt Notification to the Commission

ISO 27701:2019 · 2 controls

  • 6.13.1 Management of information security incidents and improvements
  • 6.9.6 Technical vulnerability management

NIST SP 800-171 Rev 3 · 2 controls

  • 03.06.01 Incident Handling
  • 03.06.02 Incident Monitoring, Reporting, and Response Assistance
  • E8-APP-ML3 Application Control (ML3)
  • ANSSI-HYG-40 Define a Security Incident Management Procedure
  • CBPR-PR-32 Detection, prevention and response measures

APPI · 1 control

  • APPI-A26 Report of Leakage to the Commission and Notification to the Person

ISO 22301:2019 · 1 control

  • 8.4.3 Warning and communication

NIST SP 800-172 · 1 control

  • 3.6.2e Establish and Maintain a Cyber Incident Response Team

UK Cyber Essentials · 1 control

  • CE-SC.8 Process for Compromised Passwords

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Administrative

You are reading one control. How much of HIPAA Security Rule have you already done?

HIPAA Security Rule 164.308(a)(6)(ii) is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of HIPAA Security Rule your existing evidence covers. Hold ISO 27001:2022 and 53 of 67 HIPAA Security Rule controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 64 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 104 it maps to, and the evidence behind each claim, over MCP and REST.