HIPAA Security Rule
Administrative

HIPAA Security Rule 164.308(b)(1): Business Associate Contracts and Other Arrangements (Standard)

A covered entity may permit a business associate to handle ePHI only after obtaining satisfactory assurances via written contract. NIST recommends due diligence, security questionnaires, and ongoing monitoring of BAs.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 95 controls across 28 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

NIST SP 800-53 Rev 5 · 14 controls

ISO 27001:2022 · 8 controls

  • 5.19 Information security in supplier relationships
  • 5.20 Addressing information security within supplier agreements
  • 5.21 Managing information security in the information and communication technology (ICT) supply chain
  • 5.22 Monitoring, review and change management of supplier services
  • 5.23 Information security for use of cloud services
  • 5.31 Legal, statutory, regulatory and contractual requirements
  • 6.6 Confidentiality or non-disclosure agreements
  • 8.30 Outsourced development
  • NIST-CSF-DE.CM-06 External service provider activities and services are monitored to find potentially adverse events
  • NIST-CSF-GV.OC-02 Internal and external stakeholders are understood, and their needs and expectations regarding cybersecurity risk management are understood and considered
  • NIST-CSF-GV.SC-01 A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders
  • NIST-CSF-GV.SC-05 Requirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and other types of agreements with suppliers and other relevant third parties
  • NIST-CSF-GV.SC-06 Planning and due diligence are performed to reduce risks before entering into formal supplier or other third-party relationships
  • NIST-CSF-GV.SC-07 The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationship
  • NIST-CSF-ID.RA-10 Critical suppliers are assessed prior to acquisition

PCI DSS 4.0 · 7 controls

  • 12.8.1 12.8.1 List of third-party service providers
  • 12.8.2 12.8.2 TPSP contracts acknowledging account data responsibility
  • 12.8.3 12.8.3 Due diligence before engaging TPSPs
  • 12.8.4 12.8.4 Annual monitoring of TPSP compliance status
  • 12.8.5 12.8.5 Responsibility allocation between entity and TPSPs
  • 12.9.1 12.9.1 TPSP written acknowledgments to customers
  • 12.9.2 12.9.2 TPSP support for customer information requests

CIS Controls v8 · 6 controls

  • CIS-15.2 Establish and Maintain a Service Provider Management Policy
  • CIS-15.4 Ensure Service Provider Contracts Include Security Requirements
  • CIS-15.5 Assess Service Providers
  • CIS-15.6 Monitor Service Providers
  • CIS-16.4 Establish and Manage an Inventory of Third-Party Software Components
  • CIS-8.12 Collect Service Provider Logs

NIST SP 800-161 Rev 1 · 6 controls

  • CPS230-39 Register of Material Service Providers
  • CPS230-43 Due Diligence Before Entering or Modifying a Material Arrangement
  • CPS230-46 Ongoing Risk Management of Each Material Arrangement
  • CPS230-P15 Precondition for Reliance on a Service Provider

FedRAMP High · 4 controls

  • PS-7 External Personnel Security
  • SA-9 External System Services
  • SA-9(1) External System Services | Risk Assessments and Organizational Approvals (SA-9(1))
  • SR-1 Policy and Procedures (SR-1)

FedRAMP Moderate · 4 controls

  • PS-7 External Personnel Security
  • SA-9 External System Services
  • SA-9(1) External System Services | Risk Assessments and Organizational Approvals (SA-9(1))
  • SR-1 Policy and Procedures (SR-1)

ISO 27002:2022 · 4 controls

  • 5.19 Information security in supplier relationships
  • 5.20 Addressing information security within supplier agreements
  • 5.22 Monitoring, review and change management of supplier services
  • 5.23 Information security for use of cloud services

APRA CPS 234 · 3 controls

  • CPS234-16 Assessment of Related Party and Third Party Capability
  • CPS234-P22 Evaluation of Third Party Control Design
  • CPS234-P28 Assessment of Reliance on Third Party Control Testing

C5 (Germany) · 3 controls

  • C5-OIS-03 Interfaces and Dependencies
  • C5-SSO-01 Policies and instructions for controlling and monitoring third parties
  • C5-SSO-02 Risk assessment of service providers and suppliers

ISO 27701:2019 · 3 controls

  • 7.2.6 Contracts with PII processors
  • 7.2.7 Joint PII controller
  • 8.5.5 Legally binding PII disclosures

SOC 2 · 3 controls

  • SOC2-CC9.2 CC9.2 Assessing and managing vendor and business partner risk
  • SOC2-P6.4 P6.4 Privacy commitments from vendors and third parties
  • SOC2-P6.5 P6.5 Vendor commitments to report unauthorised disclosures
  • CBPR-PR-35 Processor protection obligations
  • CBPR-PR-46 Mechanisms with processors to meet obligations
  • CFTC-SS-30 Outsourcing with Retention of Complete Responsibility
  • CFTC-SS-5 Systems Development and Quality Assurance Category

NIST SP 800-172 · 2 controls

  • 3.11.6e Supply Chain Risk Assessment, Response, and Monitoring
  • 3.11.7e Supply Chain Risk Management Plan
  • ANSSI-HYG-03 Control the Risks of Outsourced Information System Management

APPI · 1 control

  • SEC03-BP09 Share resources securely with a third party
  • APP-8 APP 8 - Cross-border disclosure of personal information
  • ASBv3-PA-8 Determine access process for cloud provider support

ISO/IEC 42001:2023 · 1 control

UK Cyber Essentials · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Administrative

You are reading one control. How much of HIPAA Security Rule have you already done?

HIPAA Security Rule 164.308(b)(1) is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of HIPAA Security Rule your existing evidence covers. Hold ISO 27001:2022 and 53 of 67 HIPAA Security Rule controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 64 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 95 it maps to, and the evidence behind each claim, over MCP and REST.