MARS-E
Privacy PII PHI Protection - MARS-E v2.0

MARS-E MARS-E-Privacy-PII-PHI-Minimum-Necessary-HIPAA-Privacy-Rule-NIST-800-122-45-CFR-164-Subpart-E: MARS-E Privacy + PII + PHI + Minimum Necessary + HIPAA Privacy Rule + NIST 800-122 + 45 CFR 164 Subpart E

Protect Personally Identifiable Information (PII) and Protected Health Information (PHI) handled by Exchanges. Apply NIST 800-122 PII Confidentiality Impact Level determination + minimum necessary standard for use disclosure and request + HIPAA Privacy Rule 45 CFR 164 Subpart E (Privacy of Individually Identifiable Health Information) where applicable + ACA Section 1411 information requirements + 45 CFR 155.260(a)(3) privacy and security requirements. Implement notice of privacy practices for Exchange consumers. Honor opt-out and choice mechanisms. De-identification under HIPAA Safe Harbor or Expert Determination. Limited Data Set procedures with Data Use Agreements. Tax Filing Status disclosure restrictions. Beneficiary consent for information sharing across Exchange + Medicaid + CHIP + plan issuers. Strict controls for sharing with Federal Data Services Hub. Annual privacy training. Privacy Officer designation. Privacy Impact Assessment per OMB M-03-22 + DHS Privacy Office Handbook + CMS PIA Template.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 192 controls across 65 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 27799:2025 · 7 controls

  • ISO27799-01 ePHI access controls and authorization
  • ISO27799-03 Minimum necessary standard enforcement
  • ISO27799-04 Patient data de-identification procedures
  • ISO27799-05 Audit trail for ePHI access
  • ISO27799-08 Information access management
  • ISO27799-09 Security awareness and training program
  • ISO27799-17 Facility access controls
  • CH-FADP-15 Cooperation with the FDPIC
  • CH-FADP-19 Transparency and proactive information
  • CH-FADP-21 Data protection impact assessments
  • FADP-16 FDPIC Independence and Functions
  • FADP-7 Data Protection Impact Assessment (Articles 9-10)
  • FADP-9 Data Protection Advisor (Articles 14-15)

ISO/IEC 27011:2024 · 5 controls

  • 27011-5.2 Information Security Roles in Telecoms
  • 27011-5.3 Segregation of duties
  • 27011-6.3 Awareness and Training
  • 27011-8.1 User Endpoint Devices
  • 27011-8.6 Data protection and backup
  • ASD37-18 Restrict administrative privileges (Essential)
  • ASD37-20 Multi-factor authentication (Essential)
  • ASD37-27 Outbound data loss prevention (Very Good)
  • ASD37-37 Personnel management (Very Good)
  • AWWA-1.3 Security Awareness and Training
  • AWWA-2.1 User Access Management
  • AWWA-2.4 Physical Access Controls
  • AWWA-3.4 Encryption and Data Protection

BSI IT-Grundschutz · 4 controls

  • BSI-02 Access enforcement and least privilege
  • BSI-03 Multi-factor authentication requirements
  • BSI-04 Remote access controls
  • BSI-05 Wireless access restrictions
  • CAT-D1-4 Training and culture
  • CAT-D3-1 Preventative controls
  • CAT-D4-3 Third-party access controls
  • CAT-IRP-4 Organizational characteristics

API 1164 · 3 controls

  • API1164-06 Access Control
  • API1164-07 Remote Access
  • API1164-09 Patch and Vulnerability Management
  • AT-DSG-10 Section 29 - Liability and right to compensation / civil jurisdiction
  • AT-DSG-12 Section 62 - Administrative penalties
  • AT-DSG-7 Section 18 - Establishment of the Data Protection Authority

Bahrain PDPL · 3 controls

  • UAE-PDPL-Art.10 Data Protection Officer (DPO) (UAE PDPL Article 10)
  • UAE-PDPL-Art.18_19_20_21 Security measures, controller/processor relationship, DPIA (UAE PDPL Articles 18-21)
  • UAE-PDPL-Art.6_7 Sensitive personal data and children's data (UAE PDPL Articles 6-7)

GDPR · 3 controls

IEC 62443 · 3 controls

  • IEC62443-07 Personnel risk assessment
  • IEC62443-08 Electronic access perimeter management
  • IEC62443-10 Revocation of access procedures

ISO/IEC 27019:2024 · 3 controls

  • ISO27019-07 Personnel risk assessment
  • ISO27019-08 Electronic access perimeter management
  • ISO27019-10 Revocation of access procedures

ISO/IEC 27043:2015 · 3 controls

  • ISO27043-11 Access control policy and enforcement
  • ISO27043-14 Privileged access management
  • ISO27043-15 Access review and recertification

ISO/IEC 27400:2022 · 3 controls

  • 27400-6.1 Secure Device Design
  • 27400-7.1 Network Security for IoT
  • 27400-7.4 Data retention and deletion

ISO/SAE 21434 · 3 controls

  • ISO21434-12 User access management and provisioning
  • ISO21434-14 Privileged access management
  • ISO21434-15 Access review and recertification
  • DSOMM-1 Culture, Organization, Education, and Governance
  • DSOMM-3 Build, Deployment, Infrastructure Hardening, and Secrets Management
  • DSOMM-4 Test and Verification - SAST, DAST, IAST, SCA, Penetration Testing
  • OWASPLLM-1 Prompt Injection and System Prompt Leakage (LLM01 + LLM07)
  • OWASPLLM-2 Improper Output Handling and Misinformation (LLM05 + LLM09)
  • OWASPLLM-6 Excessive Agency and Unbounded Consumption (LLM06 + LLM10)
  • AUPRV-1 APP 1 Open and Transparent Management + Privacy Management Framework
  • AUPRV-4 APP 10-11 Quality, Security of Personal Information
  • AUPRV-6 Sensitive Information, PIA, Privacy by Design, Children
  • IM8-DAT.2 Data Protection
  • IM8-DAT.4 Data Retention and Disposal
  • IM8-SEC.2 Access Control
  • AZ-DPA-15 Article 17 - Dispute resolution
  • AZ-DPA-6 Article 6 - State regulation in personal data protection
  • BB-DPA-1 Section 1 - Short Title
  • BB-DPA-4 Section 4 - Principles Relating to Processing
  • DSO-2 Data Security
  • DSO-3 Data Access Management
  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))
  • FTC-Safeguards-ServiceProvider-Evaluation Service Provider Oversight + Program Evaluation + Personnel Training (16 CFR 314.4(d-g))
  • ISO28001-PI-02 Security Awareness and Training
  • ISO28001-PS-01 Facility Security

ISO/IEC 27010:2015 · 2 controls

  • 27010-9.1 Access Control to Shared Information
  • 27010-9.2 Authentication of Sources

Malaysia PDPA 2010 · 2 controls

  • MY-PDPA-Cross-Border-Transfer-Section-129-Whitelist-Abolition-2024-Adequacy-SCC-BCR-Processor-Direct-Marketing Malaysia PDPA Cross-Border + Section 129 + Whitelist Abolition 2024 + Adequacy + SCC + BCR + Processor + Marketing
  • MY-PDPA-DPO-Designation-Class-Data-User-Registration-DPIA-Code-Practice-Section-43A-2024-Amendment Malaysia PDPA Governance + DPO Section 43A + Class of Data User Registration + DPIA + Code of Practice
  • OWASPAPI-1 Broken Object Level Authorization (BOLA) and BFLA
  • OWASPAPI-3 Broken Object Property Level Authorization (BOPLA)

OWASP ASVS · 2 controls

OWASP Top 10:2025 · 2 controls

  • PAKPDPB-6 Cross-Border Transfer and Data Localization
  • PAKPDPB-7 NCPDP, Registration, Records, Processor Contracts, DPO
  • PSPF24-2 Information Security, Cybersecurity Maturity, Essential Eight
  • PSPF24-4 Physical Security

South Korea ISMS-P · 2 controls

  • ISMSP-AC-01 Access Control Policy
  • ISMSP-AC-04 Network Access Control

South Korea PIPA · 2 controls

  • PIPA-CPO-DPO-Privacy-Officer-PIA-Personal-Information-Impact-Assessment-Articles-31-33 Korea PIPA CPO + DPO + Privacy Officer + PIA + Personal Information Impact Assessment + Articles 31-33
  • PIPA-Cross-Border-Transfer-Articles-28-8-28-9-Adequacy-Standard-Contract-Certification-EU Korea PIPA Cross-Border Transfer + Articles 28-8 + 28-9 + Adequacy + EU 2021

Turkey KVKK · 2 controls

  • TURKEYKVKK-2 Information Notice and Data Subject Rights
  • TURKEYKVKK-3 Special Categories and Sensitive Data
  • D.1 Incident Response Planning
  • UKDEFSTD-1 Cyber Defence Cyber Risk Profile (CRP)
  • CPSC-CS.2 Authentication and Access Controls
  • CPSC-CS.3 Data Protection for Safety Systems
  • VERMONTAICDA-3 Bias Testing, Discrimination Prevention, Transparency
  • VERMONTAICDA-4 Vermont AG Enforcement and Cure

APPI · 1 control

  • APPI-A26 Report of Leakage to the Commission and Notification to the Person
  • AL-DPA-14 Direct Marketing
  • CA-ITSG33-SC-01 Security Control Catalogue
  • CJIS-2 Security Awareness Training
  • FDBR-ControllerObligations-DPA-Notice Controller + Processor Obligations + Data Protection Assessments (Fla. Stat. 501.707, 501.708, 501.71, 501.711)
  • IATA-IOSA-Section8-SEC-SecurityManagement-AVSEC IATA IOSA Section 8 - SEC Security Management + Aviation Security Programme (AVSEC) + ICAO Annex 17 Alignment
  • ICAO-ANX17-Chap2-ThreatAssessment-RiskManagement-Cyber-GASeP ICAO Annex 17 Chapter 2 - Threat Assessment + Risk Management + Cyber Threats to Critical Aviation Systems (Amendment 17/18)
  • 62351-8 Role-based access control (RBAC)

ISO 26000:2010 · 1 control

  • ISO-26000-6.7 Consumer issues
  • ISO20000-15 Access management for services

ISO/IEC 23894:2023 · 1 control

  • ISO23894-A.5 Privacy and Data Protection in AI

ITIL 4 · 1 control

  • ITIL4-15 Access management for services

MITRE D3FEND · 1 control

MiFID II / MiFIR · 1 control

  • RUSPD-4 Special Categories, Biometric Data
  • ACE-CR-4 Cargo Release Authorization
  • USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR)
  • VIETNAMCYBER-4 Incident Reporting and Cooperation

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 192 it maps to, and the evidence behind each claim, over MCP and REST.