NIST SP 800-66
Integration with NIST RMF, CSF, OCR Enforcement

NIST SP 800-66 NISTSP66-8: Integration with NIST RMF, Cybersecurity Framework, and OCR Enforcement Posture

Operate HIPAA Security Rule compliance using NIST SP 800-66 Rev 2 as the bridge to broader NIST cybersecurity guidance per Chapter 5 of SP 800-66 Rev 2. Map HIPAA Security Rule standards to NIST Cybersecurity Framework 2.0 functions + categories + subcategories using the crosswalk in SP 800-66 Rev 2 Appendix F. Map HIPAA Security Rule to NIST SP 800-53 Rev 5 controls using the crosswalk in SP 800-66 Rev 2 Appendix G for organisations operating under NIST RMF (SP 800-37 Rev 2). Integrate HIPAA Security Rule risk analysis (NISTSP66-1) with NIST SP 800-30 Rev 1 + NIST SP 800-39 enterprise risk management. Integrate HIPAA Security Rule incident procedures (NISTSP66-3) with NIST SP 800-61 Rev 2 IR methodology. Integrate HIPAA Security Rule contingency planning (NISTSP66-3) with NIST SP 800-34 contingency planning + NIST SP 800-160 vol 2 cyber resilience. Maintain readiness for OCR Audit Program covering Privacy + Security + Breach Notification rules + recent OCR enforcement themes (ransomware + ePHI in cloud + business associate failures + risk analysis gaps + insufficient encryption).

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.