TEFCA - Trusted Exchange Framework and Common Agreement
Privacy and Security

TEFCA - Trusted Exchange Framework and Common Agreement TEFCAREC-2: Privacy, Security, Minimum Necessary

Per TEFCA: privacy + security including HIPAA + Minimum Necessary Standard + appropriate safeguards + encryption + access control.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 27 controls across 13 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • ACQS-3-1 Safe and Effective Care
  • ACQS-8-2 Clinical Governance
  • ACQS-8-4 Risk Management

HITECH Act · 3 controls

  • HITECH-Coord-HIPAA-Privacy-Security-Cures-ONC HITECH Coordination with HIPAA Privacy Rule + HIPAA Security Rule (Verified Separately) + 21st Century Cures Act + ONC
  • HITECH-Enforcement-CMP-Tiers-StateAGs-OCR HITECH 4-Tier Civil Monetary Penalty Structure, State AGs Enforcement and HHS OCR Settlements
  • HITECH-SubtitleD-Breach-Notification-BA-Direct-Liability HITECH Subtitle D - Breach Notification Rule (45 CFR Part 164 Subpart D), Business Associate Direct Liability, Subcontractors

MDS2 (Medical Device) · 3 controls

  • MDS2-Audit-Logging-AUDT-Integrity-IGAU-Cybersecurity-Risk-CYBR-Monitoring MDS2 Audit Controls + AUDT + Integrity + IGAU + Cybersecurity Risk + CYBR + Continuous Monitoring
  • MDS2-PHI-Data-Handling-DATA-Storage-STCF-Transmission-TXCF-TXIG-Encryption-FIPS MDS2 PHI Handling + DATA + STCF Storage + TXCF Transmission + TXIG Integrity + Encryption + FIPS
  • MDS2-Person-Node-Authentication-Authorization-Auto-Logoff-AUTH-PAUT-NAUT MDS2 Authentication + Authorization + Auto Logoff + PAUT + NAUT + AUTH + Identity Management
  • EHDSREG-1 Mandatory Requirements for EHR Systems (Articles 14-29)
  • EHDSREG-3 Secondary Use - Health Data for Research and Innovation
  • EHDSREG-5 Cross-Border Health Data Flows
  • QMSR-820.10 Requirements for a Quality Management System - ISO 13485:2016 Sections 4-8 incorporation (§820.10)
  • QMSR-ISO13485-Sec7_DesignControls Product realization - Design and Development controls (ISO 13485:2016 Section 7.3)
  • FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704)
  • GAMP5-Risk-CriticalThinking Risk-Based Approach, Critical Thinking and 5 Key Concepts
  • 60601-1.12 Accuracy of controls and instruments
  • NAIC-1 NAIC Model Law Adoption, Scope, and Licensee Definitions
  • AQAP2110-3 Design and Development Control - NATO plus ISO 13485 Cross-Walk
  • PICSGMP-1 Chapter 1: Pharmaceutical Quality System (PQS) and Quality Risk Management

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 27 it maps to, and the evidence behind each claim, over MCP and REST.