HITECH crosswalk to verified subordinate substantive rules + adjacent frameworks. HIPAA PRIVACY RULE (45 CFR Parts 160 + 164 Subpart E) - primary substantive privacy controls; HITECH amendments operationalized via 2013 Omnibus Final Rule + ongoing OCR guidance. HIPAA SECURITY RULE (45 CFR Part 164 Subpart C, VERIFIED SEPARATELY in this corpus) - primary substantive security controls; administrative + physical + technical safeguards for ePHI; pending 2024-2025 NPRM modernisation. HITECH BREACH NOTIFICATION RULE (45 CFR Part 164 Subpart D) - breach definition + 4-factor risk assessment + individual + media + HHS notification SLA. NIST CYBERSECURITY FRAMEWORK (CSF) 2.0 + 800-53 + 800-66 (HIPAA Security Rule Implementation Guide) - voluntary cybersecurity framework + recognized security practices; HHS 405d MAPPING crosswalks NIST CSF to HIPAA Security Rule. HHS 405d HEALTH INDUSTRY CYBERSECURITY PRACTICES (HICP) - voluntary best practices for cybersecurity in healthcare published by HHS + 405d Task Group; available in 3 organizational sizes (small + medium + large); HSPP Safe Harbor applies to demonstrably-implemented HICP. ONC INFORMATION BLOCKING FINAL RULE - actors + 8 exceptions + penalties. ONC EHR CERTIFICATION + 2015 EDITION CURES UPDATE - certification criteria for EHR + Health IT module. CYBERSECURITY ACT OF 2015 (P.L. 114-113 Title V) - voluntary cybersecurity information sharing + HSCC operations. HSCC JOINT CYBERSECURITY WORKING GROUP guidance + sectoral cybersecurity coordination + threat-sharing + HHS sectoral cybersecurity. STATE PRIVACY LAWS coordination: California Confidentiality of Medical Information Act (CMIA) + New York State Information Security Breach Notification Act + similar state laws + State Privacy Acts (CCPA + others) coordinate with HITECH/HIPAA; case-by-case preemption analysis. 42 CFR PART 2 (SAMHSA) - substance use disorder treatment record confidentiality; coordinates with HIPAA + HITECH; recent 2024 SAMHSA Final Rule aligning Part 2 with HIPAA. 21st CENTURY CURES ACT (2016) + ONC Implementation - Information Blocking + interoperability + USCDI. FDA + MEDICAL DEVICE CYBERSECURITY (premarket + postmarket guidance) - SBOM + vulnerability management + connected device safety. CMS PROMOTING INTEROPERABILITY PROGRAM (MIPS) - incentive + penalty for EHR + Open API + Information Blocking compliance. STATE BREACH NOTIFICATION LAWS - all 50 states + DC + Puerto Rico + USVI + territories; preempted by HITECH only if more stringent (case-by-case analysis).
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.