NIST SP 800-66
Policies, Procedures, Documentation

NIST SP 800-66 NISTSP66-7: Policies, Procedures, Documentation, and Organisational Requirements

Maintain HIPAA Security Rule Policies + Procedures + Documentation per 45 CFR 164.316 and Organisational Requirements per 45 CFR 164.314. Policies and Procedures per 45 CFR 164.316(a): implement reasonable and appropriate policies and procedures to comply with the standards + implementation specifications + and other requirements of the Security Rule. Documentation per 45 CFR 164.316(b)(1): maintain the policies and procedures in written (which may be electronic) form + maintain a written or electronic record of any action + activity + or assessment required by the Security Rule. Documentation Retention per 45 CFR 164.316(b)(2)(i): retain documentation for 6 years from the date of its creation or the date when it last was in effect whichever is later. Documentation Availability per 45 CFR 164.316(b)(2)(ii): make documentation available to those persons responsible for implementing the procedures to which the documentation pertains. Documentation Updates per 45 CFR 164.316(b)(2)(iii): review documentation periodically + update as needed in response to environmental or operational changes affecting the security of ePHI. Organisational Requirements per 45 CFR 164.314 include BAA requirements (covered in NISTSP66-4) and Group Health Plan requirements + Plan Document amendments.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.