NIST SP 800-66
Technical Safeguards

NIST SP 800-66 6: Technical Safeguards: Access Control, Audit Controls, Integrity, Person Authentication

Implement HIPAA Security Rule Technical Safeguards per 45 CFR 164.312 covering technical access + audit + integrity + authentication. Access Control per 45 CFR 164.312(a)(1): Unique User Identification (Required) + Emergency Access Procedure (Required) + Automatic Logoff (Addressable) + Encryption and Decryption (Addressable) at rest. Audit Controls per 45 CFR 164.312(b): implement hardware + software + procedural mechanisms that record and examine activity in information systems that contain or use ePHI. Integrity per 45 CFR 164.312(c)(1): implement policies and procedures to protect ePHI from improper alteration or destruction including Mechanism to Authenticate ePHI (Addressable). Person or Entity Authentication per 45 CFR 164.312(d): implement procedures to verify that a person or entity seeking access to ePHI is the one claimed. Transmission Security per 45 CFR 164.312(e)(1): Integrity Controls (Addressable) + Encryption (Addressable) of ePHI in transit. Encryption at rest and in transit although technically Addressable have effectively become Required per OCR guidance and Safe Harbor for breach notification.

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.