NIST SP 800-66 NISTSP66-2: Workforce Security, Information Access Management, and Awareness Training
Implement HIPAA Security Rule Administrative Safeguards covering workforce + access + training. Workforce Security per 45 CFR 164.308(a)(3): Authorization and/or Supervision of workforce members + Workforce Clearance Procedures + Termination Procedures ensuring access revocation when employment ends or roles change. Information Access Management per 45 CFR 164.308(a)(4): Isolating Health Care Clearinghouse Functions + Access Authorization (procedures for granting access to ePHI through workstation + transaction + program + process) + Access Establishment and Modification (procedures to establish + document + review + modify access rights). Security Awareness and Training per 45 CFR 164.308(a)(5): Security Reminders + Protection from Malicious Software + Log-In Monitoring + Password Management. Apply minimum necessary principle per 45 CFR 164.502(b) when establishing access. Maintain workforce roster + access reviews + recertification cycles + training completion records + phishing simulation evidence.
Maintained by Gerard Blokdyk·Verified against the published standard ·Control text last updated
What else in your programme already covers this
This control maps to 109 controls across 51 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
PIPA-Cross-Border-Transfer-Articles-28-8-28-9-Adequacy-Standard-Contract-Certification-EU Korea PIPA Cross-Border Transfer + Articles 28-8 + 28-9 + Adequacy + EU 2021