NIST SP 800-66
Workforce Security + Access + Training

NIST SP 800-66 2: Workforce Security, Information Access Management, and Awareness Training

Implement HIPAA Security Rule Administrative Safeguards covering workforce + access + training. Workforce Security per 45 CFR 164.308(a)(3): Authorization and/or Supervision of workforce members + Workforce Clearance Procedures + Termination Procedures ensuring access revocation when employment ends or roles change. Information Access Management per 45 CFR 164.308(a)(4): Isolating Health Care Clearinghouse Functions + Access Authorization (procedures for granting access to ePHI through workstation + transaction + program + process) + Access Establishment and Modification (procedures to establish + document + review + modify access rights). Security Awareness and Training per 45 CFR 164.308(a)(5): Security Reminders + Protection from Malicious Software + Log-In Monitoring + Password Management. Apply minimum necessary principle per 45 CFR 164.502(b) when establishing access. Maintain workforce roster + access reviews + recertification cycles + training completion records + phishing simulation evidence.

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.