HIPAA Security Rule
Organizational

HIPAA Security Rule 164.314(a)(1): Business Associate Contracts or Other Arrangements (Standard)

The contract or other arrangement required by 164.308(b)(3) must meet the requirements of paragraph (a)(2)(i), (a)(2)(ii), or (a)(2)(iii) of this section, as applicable.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 52 controls across 17 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

NIST SP 800-53 Rev 5 · 9 controls

ISO 27001:2022 · 7 controls

  • 5.19 Information security in supplier relationships
  • 5.20 Addressing information security within supplier agreements
  • 5.21 Managing information security in the information and communication technology (ICT) supply chain
  • 5.23 Information security for use of cloud services
  • 5.34 Privacy and protection of personal identifiable information (PII)
  • 6.6 Confidentiality or non-disclosure agreements
  • 8.30 Outsourced development

PCI DSS 4.0 · 6 controls

  • 12.8.1 12.8.1 List of third-party service providers
  • 12.8.3 12.8.3 Due diligence before engaging TPSPs
  • 12.8.4 12.8.4 Annual monitoring of TPSP compliance status
  • 12.8.5 12.8.5 Responsibility allocation between entity and TPSPs
  • 12.9.1 12.9.1 TPSP written acknowledgments to customers
  • 12.9.2 12.9.2 TPSP support for customer information requests
  • NIST-CSF-GV.OC-02 Internal and external stakeholders are understood, and their needs and expectations regarding cybersecurity risk management are understood and considered
  • NIST-CSF-GV.SC-05 Requirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and other types of agreements with suppliers and other relevant third parties
  • NIST-CSF-ID.RA-10 Critical suppliers are assessed prior to acquisition
  • NIST-CSF-RS.CO-03 Information is shared with designated internal and external stakeholders

FedRAMP High · 3 controls

  • SA-4 Acquisition Process
  • SA-9 External System Services
  • SR-2 Supply Chain Risk Management Plan (SR-2)

FedRAMP Moderate · 3 controls

  • SA-4 Acquisition Process
  • SA-9 External System Services
  • SR-2 Supply Chain Risk Management Plan (SR-2)

ISO 27002:2022 · 3 controls

  • 5.20 Addressing information security within supplier agreements
  • 5.34 Privacy and protection of PII
  • 6.6 Confidentiality or non-disclosure agreements

SOC 2 · 3 controls

  • SOC2-CC9.2 CC9.2 Assessing and managing vendor and business partner risk
  • SOC2-P6.4 P6.4 Privacy commitments from vendors and third parties
  • SOC2-P6.5 P6.5 Vendor commitments to report unauthorised disclosures

C5 (Germany) · 2 controls

  • C5-SSO-01 Policies and instructions for controlling and monitoring third parties
  • C5-SSO-02 Risk assessment of service providers and suppliers

CIS Controls v8 · 2 controls

  • CIS-15.2 Establish and Maintain a Service Provider Management Policy
  • CIS-15.4 Ensure Service Provider Contracts Include Security Requirements

ISO 27701:2019 · 2 controls

  • 7.2.7 Joint PII controller
  • 8.5.5 Legally binding PII disclosures

NIST SP 800-161 Rev 1 · 2 controls

  • CPS230-50 Formal Agreement Content for Material Arrangements

APRA CPS 234 · 1 control

  • CPS234-P22 Evaluation of Third Party Control Design
  • CFTC-SS-30 Outsourcing with Retention of Complete Responsibility

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Organizational

You are reading one control. How much of HIPAA Security Rule have you already done?

HIPAA Security Rule 164.314(a)(1) is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of HIPAA Security Rule your existing evidence covers. Hold ISO 27001:2022 and 53 of 67 HIPAA Security Rule controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 64 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 52 it maps to, and the evidence behind each claim, over MCP and REST.