Back to Frameworks

HIPAA Breach Notification Rule

United States
v2013
4 domains
8 controls

HIPAA Breach Notification Rule standards for breach risk assessment and notification to individuals, the media, HHS and covered entities by business associates.

Verified

HIPAA Breach Notification Rule is a compliance framework from United States with 4 domains and 8 controls. The largest domains are Notification to individuals, media and HHS (164.404, 164.406, 164.408) – HIPAA Breach Notification Rule (3 controls), Breach definition and risk assessment (164.400, 164.402) – HIPAA Breach Notification Rule (2 controls), Delay, burden of proof and documentation (164.412, 164.414) – HIPAA Breach Notification Rule (2 controls). Every control below carries what it requires and what an assessor expects to see.

Maintained by Gerard Blokdyk

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (4)

Breach definition and risk assessment (164.400, 164.402) – HIPAA Breach Notification Rule

2 controls
Controls in the Breach definition and risk assessment (164.400, 164.402) – HIPAA Breach Notification Rule domain of HIPAA Breach Notification Rule — 2 controls
CodeTitle
hipaa-breach-notification-rule::164.402breachDefinition of breach and the three statutory exceptions
hipaa-breach-notification-rule::164.402riskLow probability of compromise risk assessment

Business associate notification to the covered entity (164.410) – HIPAA Breach Notification Rule

1 controls
Controls in the Business associate notification to the covered entity (164.410) – HIPAA Breach Notification Rule domain of HIPAA Breach Notification Rule — 1 controls
CodeTitle
hipaa-breach-notification-rule::164.410Business associate notification to the covered entity

Delay, burden of proof and documentation (164.412, 164.414) – HIPAA Breach Notification Rule

2 controls
Controls in the Delay, burden of proof and documentation (164.412, 164.414) – HIPAA Breach Notification Rule domain of HIPAA Breach Notification Rule — 2 controls
CodeTitle
hipaa-breach-notification-rule::164.412Delay of notification for law enforcement purposes
hipaa-breach-notification-rule::164.414Administrative requirements, documentation and burden of proof

Notification to individuals, media and HHS (164.404, 164.406, 164.408) – HIPAA Breach Notification Rule

3 controls
Controls in the Notification to individuals, media and HHS (164.404, 164.406, 164.408) – HIPAA Breach Notification Rule domain of HIPAA Breach Notification Rule — 3 controls
CodeTitle
hipaa-breach-notification-rule::164.404Notification to affected individuals, timing and content
hipaa-breach-notification-rule::164.406Notification to the media
hipaa-breach-notification-rule::164.408Notification to the Secretary of HHS

What is HIPAA Breach Notification Rule and who does it apply to?

HIPAA Breach Notification Rule is a compliance framework from United States with 4 domains and 8 controls. HIPAA Breach Notification Rule standards for breach risk assessment and notification to individuals, the media, HHS and covered entities by business associates. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

What does HIPAA Breach Notification Rule actually require?

HIPAA Breach Notification Rule has 8 controls organised across 4 domains. The largest domains are Notification to individuals, media and HHS (164.404, 164.406, 164.408) – HIPAA Breach Notification Rule (3 controls), Breach definition and risk assessment (164.400, 164.402) – HIPAA Breach Notification Rule (2 controls), Delay, burden of proof and documentation (164.412, 164.414) – HIPAA Breach Notification Rule (2 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

If I already comply with another framework, how much of HIPAA Breach Notification Rule do I already cover?

HIPAA Breach Notification Rule does not currently have cross-framework mappings in our system. Check back as we continuously expand our mapping database.

How do I implement HIPAA Breach Notification Rule?

Start your HIPAA Breach Notification Rule compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about HIPAA Breach Notification Rule requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 8 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 894 frameworks.

Get Started Free →

Free forever — no credit card required