Security Management Process - Risk Analysis and Risk Management
NIST SP 800-66 1: Security Management Process: Risk Analysis and Risk Management for ePHI
Implement the HIPAA Security Rule Security Management Process Administrative Safeguard at 45 CFR 164.308(a)(1) per NIST SP 800-66 Rev 2. Conduct an accurate and thorough Risk Analysis per 45 CFR 164.308(a)(1)(ii)(A) of the potential risks and vulnerabilities to the confidentiality + integrity + availability of electronic protected health information (ePHI) held by the covered entity or business associate using NIST SP 800-30 Rev 1 risk assessment methodology. Implement Risk Management per 45 CFR 164.308(a)(1)(ii)(B) sufficient to reduce risks and vulnerabilities to a reasonable and appropriate level to comply with 45 CFR 164.306(a). Apply Sanction Policy per 45 CFR 164.308(a)(1)(ii)(C) for workforce members who fail to comply with security policies and procedures. Conduct Information System Activity Review per 45 CFR 164.308(a)(1)(ii)(D) to regularly review records of information system activity (audit logs + access reports + security incident tracking reports). Risk analysis must address all ePHI created + received + maintained + transmitted across the enterprise + cover ePHI at rest + in transit + in use across all environments + applications + endpoints + cloud + third parties.
What else in your programme already covers this
This control maps to 102 controls across 58 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.