Frameworks / MARS-E / MARS-E-Privacy-PII-PHI-Minimum-Necessary-HIPAA-Privacy-Rule-NIST-800-122-45-CFR-164-Subpart-E MARS-E
Privacy PII PHI Protection - MARS-E v2.0
MARS-E MARS-E-Privacy-PII-PHI-Minimum-Necessary-HIPAA-Privacy-Rule-NIST-800-122-45-CFR-164-Subpart-E: MARS-E Privacy + PII + PHI + Minimum Necessary + HIPAA Privacy Rule + NIST 800-122 + 45 CFR 164 Subpart E Protect Personally Identifiable Information (PII) and Protected Health Information (PHI) handled by Exchanges. Apply NIST 800-122 PII Confidentiality Impact Level determination + minimum necessary standard for use disclosure and request + HIPAA Privacy Rule 45 CFR 164 Subpart E (Privacy of Individually Identifiable Health Information) where applicable + ACA Section 1411 information requirements + 45 CFR 155.260(a)(3) privacy and security requirements. Implement notice of privacy practices for Exchange consumers. Honor opt-out and choice mechanisms. De-identification under HIPAA Safe Harbor or Expert Determination. Limited Data Set procedures with Data Use Agreements. Tax Filing Status disclosure restrictions. Beneficiary consent for information sharing across Exchange + Medicaid + CHIP + plan issuers. Strict controls for sharing with Federal Data Services Hub. Annual privacy training. Privacy Officer designation. Privacy Impact Assessment per OMB M-03-22 + DHS Privacy Office Handbook + CMS PIA Template.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 192 controls across 65 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
ISO27799-01 ePHI access controls and authorization ISO27799-03 Minimum necessary standard enforcement ISO27799-04 Patient data de-identification procedures ISO27799-05 Audit trail for ePHI access ISO27799-08 Information access management ISO27799-09 Security awareness and training program ISO27799-17 Facility access controls CH-FADP-15 Cooperation with the FDPIC CH-FADP-19 Transparency and proactive information CH-FADP-21 Data protection impact assessments FADP-16 FDPIC Independence and Functions FADP-7 Data Protection Impact Assessment (Articles 9-10) FADP-9 Data Protection Advisor (Articles 14-15) 27011-5.2 Information Security Roles in Telecoms 27011-5.3 Segregation of duties 27011-6.3 Awareness and Training 27011-8.1 User Endpoint Devices 27011-8.6 Data protection and backup ASD37-18 Restrict administrative privileges (Essential) ASD37-20 Multi-factor authentication (Essential) ASD37-27 Outbound data loss prevention (Very Good) ASD37-37 Personnel management (Very Good) AWWA-1.3 Security Awareness and Training AWWA-2.1 User Access Management AWWA-2.4 Physical Access Controls AWWA-3.4 Encryption and Data Protection BSI-02 Access enforcement and least privilege BSI-03 Multi-factor authentication requirements BSI-04 Remote access controls BSI-05 Wireless access restrictions CAT-D1-4 Training and culture CAT-D3-1 Preventative controls CAT-D4-3 Third-party access controls CAT-IRP-4 Organizational characteristics API1164-06 Access Control API1164-07 Remote Access API1164-09 Patch and Vulnerability Management AT-DSG-10 Section 29 - Liability and right to compensation / civil jurisdiction AT-DSG-12 Section 62 - Administrative penalties AT-DSG-7 Section 18 - Establishment of the Data Protection Authority UAE-PDPL-Art.10 Data Protection Officer (DPO) (UAE PDPL Article 10) UAE-PDPL-Art.18_19_20_21 Security measures, controller/processor relationship, DPIA (UAE PDPL Articles 18-21) UAE-PDPL-Art.6_7 Sensitive personal data and children's data (UAE PDPL Articles 6-7) IEC62443-07 Personnel risk assessment IEC62443-08 Electronic access perimeter management IEC62443-10 Revocation of access procedures ISO27019-07 Personnel risk assessment ISO27019-08 Electronic access perimeter management ISO27019-10 Revocation of access procedures ISO27043-11 Access control policy and enforcement ISO27043-14 Privileged access management ISO27043-15 Access review and recertification 27400-6.1 Secure Device Design 27400-7.1 Network Security for IoT 27400-7.4 Data retention and deletion ISO21434-12 User access management and provisioning ISO21434-14 Privileged access management ISO21434-15 Access review and recertification DSOMM-1 Culture, Organization, Education, and Governance DSOMM-3 Build, Deployment, Infrastructure Hardening, and Secrets Management DSOMM-4 Test and Verification - SAST, DAST, IAST, SCA, Penetration Testing OWASPLLM-1 Prompt Injection and System Prompt Leakage (LLM01 + LLM07) OWASPLLM-2 Improper Output Handling and Misinformation (LLM05 + LLM09) OWASPLLM-6 Excessive Agency and Unbounded Consumption (LLM06 + LLM10) AUPRV-1 APP 1 Open and Transparent Management + Privacy Management Framework AUPRV-4 APP 10-11 Quality, Security of Personal Information AUPRV-6 Sensitive Information, PIA, Privacy by Design, Children IM8-DAT.2 Data Protection IM8-DAT.4 Data Retention and Disposal IM8-SEC.2 Access Control AZ-DPA-15 Article 17 - Dispute resolution AZ-DPA-6 Article 6 - State regulation in personal data protection BB-DPA-1 Section 1 - Short Title BB-DPA-4 Section 4 - Principles Relating to Processing DSO-2 Data Security DSO-3 Data Access Management FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c)) FTC-Safeguards-ServiceProvider-Evaluation Service Provider Oversight + Program Evaluation + Personnel Training (16 CFR 314.4(d-g)) ISO28001-PI-02 Security Awareness and Training ISO28001-PS-01 Facility Security 27010-9.1 Access Control to Shared Information 27010-9.2 Authentication of Sources MY-PDPA-Cross-Border-Transfer-Section-129-Whitelist-Abolition-2024-Adequacy-SCC-BCR-Processor-Direct-Marketing Malaysia PDPA Cross-Border + Section 129 + Whitelist Abolition 2024 + Adequacy + SCC + BCR + Processor + Marketing MY-PDPA-DPO-Designation-Class-Data-User-Registration-DPIA-Code-Practice-Section-43A-2024-Amendment Malaysia PDPA Governance + DPO Section 43A + Class of Data User Registration + DPIA + Code of Practice OWASPAPI-1 Broken Object Level Authorization (BOLA) and BFLA OWASPAPI-3 Broken Object Property Level Authorization (BOPLA) PAKPDPB-6 Cross-Border Transfer and Data Localization PAKPDPB-7 NCPDP, Registration, Records, Processor Contracts, DPO PSPF24-2 Information Security, Cybersecurity Maturity, Essential Eight PSPF24-4 Physical Security ISMSP-AC-01 Access Control Policy ISMSP-AC-04 Network Access Control PIPA-CPO-DPO-Privacy-Officer-PIA-Personal-Information-Impact-Assessment-Articles-31-33 Korea PIPA CPO + DPO + Privacy Officer + PIA + Personal Information Impact Assessment + Articles 31-33 PIPA-Cross-Border-Transfer-Articles-28-8-28-9-Adequacy-Standard-Contract-Certification-EU Korea PIPA Cross-Border Transfer + Articles 28-8 + 28-9 + Adequacy + EU 2021 TURKEYKVKK-2 Information Notice and Data Subject Rights TURKEYKVKK-3 Special Categories and Sensitive Data D.1 Incident Response Planning UKDEFSTD-1 Cyber Defence Cyber Risk Profile (CRP) CPSC-CS.2 Authentication and Access Controls CPSC-CS.3 Data Protection for Safety Systems VERMONTAICDA-3 Bias Testing, Discrimination Prevention, Transparency VERMONTAICDA-4 Vermont AG Enforcement and Cure APPI-A26 Report of Leakage to the Commission and Notification to the Person AL-DPA-14 Direct Marketing CA-ITSG33-SC-01 Security Control Catalogue CJIS-2 Security Awareness Training FDBR-ControllerObligations-DPA-Notice Controller + Processor Obligations + Data Protection Assessments (Fla. Stat. 501.707, 501.708, 501.71, 501.711) IATA-IOSA-Section8-SEC-SecurityManagement-AVSEC IATA IOSA Section 8 - SEC Security Management + Aviation Security Programme (AVSEC) + ICAO Annex 17 Alignment ICAO-ANX17-Chap2-ThreatAssessment-RiskManagement-Cyber-GASeP ICAO Annex 17 Chapter 2 - Threat Assessment + Risk Management + Cyber Threats to Critical Aviation Systems (Amendment 17/18) 62351-8 Role-based access control (RBAC) ISO-19650-2-5.7 Information model delivery ISO-26000-6.7 Consumer issues ISO20000-15 Access management for services ISO23894-A.5 Privacy and Data Protection in AI ITIL4-15 Access management for services RUSPD-4 Special Categories, Biometric Data GT-4 Social Engineering Attacks ACE-CR-4 Cargo Release Authorization USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR) VIETNAMCYBER-4 Incident Reporting and Cooperation Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Query this from an agent The graph holds this control, the 192 it maps to, and the evidence behind each claim, over MCP and REST.