Back to Frameworks

HIPAA Security Rule

United States
v2013
5 domains
67 controls

Health Insurance Portability and Accountability Act security standards for protecting electronic protected health information (ePHI)

Verified

HIPAA Security Rule is a compliance framework from United States with 5 domains and 67 controls that map to 46 other frameworks. The largest domains are Administrative (32 controls), Physical (12 controls), Technical (12 controls). Every control below carries what it requires and what an assessor expects to see.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (5)

Administrative

32 controls
Controls in the Administrative domain of HIPAA Security Rule32 controls
CodeTitle
164.306Security Standards: General Rules
164.308(a)(1)(i)Security Management Process (Standard)
164.308(a)(1)(ii)(A)Risk Analysis (Required)
164.308(a)(1)(ii)(B)Risk Management (Required)
164.308(a)(1)(ii)(C)Sanction Policy (Required)
164.308(a)(1)(ii)(D)Information System Activity Review (Required)
164.308(a)(2)Assigned Security Responsibility (Standard)
164.308(a)(3)(i)Workforce Security (Standard)
164.308(a)(3)(ii)(A)Authorization and Supervision (Addressable)
164.308(a)(3)(ii)(B)Workforce Clearance Procedure (Addressable)
164.308(a)(3)(ii)(C)Termination Procedures (Addressable)
164.308(a)(4)(i)Information Access Management (Standard)
164.308(a)(4)(ii)(A)Isolating Health Care Clearinghouse Functions (Required if applicable)
164.308(a)(4)(ii)(B)Access Authorization (Addressable)
164.308(a)(4)(ii)(C)Access Establishment and Modification (Addressable)
164.308(a)(5)(i)Security Awareness and Training (Standard)
164.308(a)(5)(ii)(A)Security Reminders (Addressable)
164.308(a)(5)(ii)(B)Protection from Malicious Software (Addressable)
164.308(a)(5)(ii)(C)Log-in Monitoring (Addressable)
164.308(a)(5)(ii)(D)Password Management (Addressable)
164.308(a)(6)(i)Security Incident Procedures (Standard)
164.308(a)(6)(ii)Response and Reporting (Required)
164.308(a)(7)(i)Contingency Plan (Standard)
164.308(a)(7)(ii)(A)Data Backup Plan (Required)
164.308(a)(7)(ii)(B)Disaster Recovery Plan (Required)
164.308(a)(7)(ii)(C)Emergency Mode Operation Plan (Required)
164.308(a)(7)(ii)(D)Testing and Revision Procedures (Addressable)
164.308(a)(7)(ii)(E)Applications and Data Criticality Analysis (Addressable)
164.308(a)(8)Evaluation (Standard)
164.308(b)(1)Business Associate Contracts and Other Arrangements (Standard)
164.308(b)(2)Subcontractor Arrangements
164.308(b)(3)Written Contract or Other Arrangement

Organizational

6 controls
Controls in the Organizational domain of HIPAA Security Rule6 controls
CodeTitle
164.314(a)(1)Business Associate Contracts or Other Arrangements (Standard)
164.314(a)(2)(i)Business Associate Contract Required Provisions
164.314(a)(2)(ii)Other Arrangements (Government)
164.314(a)(2)(iii)Business Associate Contracts with Subcontractors
164.314(b)(1)Requirements for Group Health Plans (Standard)
164.314(b)(2)Implementation Specifications for Group Health Plans

Physical

12 controls
Controls in the Physical domain of HIPAA Security Rule12 controls
CodeTitle
164.310(a)(1)Facility Access Controls (Standard)
164.310(a)(2)(i)Contingency Operations (Addressable)
164.310(a)(2)(ii)Facility Security Plan (Addressable)
164.310(a)(2)(iii)Access Control and Validation Procedures (Addressable)
164.310(a)(2)(iv)Maintenance Records (Addressable)
164.310(b)Workstation Use (Standard)
164.310(c)Workstation Security (Standard)
164.310(d)(1)Device and Media Controls (Standard)
164.310(d)(2)(i)Disposal (Required)
164.310(d)(2)(ii)Media Re-use (Required)
164.310(d)(2)(iii)Accountability (Addressable)
164.310(d)(2)(iv)Data Backup and Storage (Addressable)

Policies and Procedures

5 controls
Controls in the Policies and Procedures domain of HIPAA Security Rule5 controls
CodeTitle
164.316(a)Policies and Procedures (Standard)
164.316(b)(1)Documentation (Standard)
164.316(b)(2)(i)Time Limit (Documentation Retention)
164.316(b)(2)(ii)Availability (Documentation)
164.316(b)(2)(iii)Updates (Documentation)

Technical

12 controls
Controls in the Technical domain of HIPAA Security Rule12 controls
CodeTitle
164.312(a)(1)Access Control (Standard)
164.312(a)(2)(i)Unique User Identification (Required)
164.312(a)(2)(ii)Emergency Access Procedure (Required)
164.312(a)(2)(iii)Automatic Logoff (Addressable)
164.312(a)(2)(iv)Encryption and Decryption (Addressable)
164.312(b)Audit Controls (Standard)
164.312(c)(1)Integrity (Standard)
164.312(c)(2)Mechanism to Authenticate ePHI (Addressable)
164.312(d)Person or Entity Authentication (Standard)
164.312(e)(1)Transmission Security (Standard)
164.312(e)(2)(i)Integrity Controls for Transmission (Addressable)
164.312(e)(2)(ii)Encryption of Transmissions (Addressable)

Your Compliance Coverage

If you comply with HIPAA Security Rule, you already cover:

Maps to 46 other frameworks

67 total controls
ISO 27001:2022
67 source controls mapped|72 target controls covered
100%
SOC 2
66 source controls mapped|46 target controls covered
99%
ISO 27002:2022
66 source controls mapped|70 target controls covered
99%
NIST SP 800-53 Rev 5
66 source controls mapped|133 target controls covered
99%
NIST Cybersecurity Framework 2.0
64 source controls mapped|84 target controls covered
96%
FedRAMP Moderate
64 source controls mapped|131 target controls covered
96%
FedRAMP High
64 source controls mapped|132 target controls covered
96%
NIST SP 800-53 Rev 5 MODERATE
63 source controls mapped|121 target controls covered
94%
NIST SP 800-53 Revision 5.1 HIGH
63 source controls mapped|122 target controls covered
94%
C5 (Germany)
62 source controls mapped|75 target controls covered
93%
Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1
61 source controls mapped|107 target controls covered
91%
ISO 27701:2019
59 source controls mapped|48 target controls covered
88%
NIST SP 800-53 Rev 5 LOW
59 source controls mapped|87 target controls covered
88%
PCI DSS 4.0
59 source controls mapped|153 target controls covered
88%
NIST SP 800-161 Rev 1
59 source controls mapped|86 target controls covered
88%
CIS Controls v8
53 source controls mapped|109 target controls covered
79%
NIST SP 800-171 Rev 3
50 source controls mapped|71 target controls covered
75%
CMMC 2.0
49 source controls mapped|80 target controls covered
73%
CFTC System Safeguards (17 CFR 37, 38, 39, 49)
44 source controls mapped|31 target controls covered
66%
Azure Security Benchmark
44 source controls mapped|65 target controls covered
66%
ANSSI Guide d'hygiene informatique (42 mesures, v2.0)
42 source controls mapped|30 target controls covered
63%
AWS Well-Architected Security Pillar
37 source controls mapped|52 target controls covered
55%
Australia Consumer Data Right - Banking (CDR)
36 source controls mapped|13 target controls covered
54%
Australia My Health Records Act 2012
34 source controls mapped|16 target controls covered
51%
ASD Strategies to Mitigate Cyber Security Incidents
30 source controls mapped|23 target controls covered
45%
NIST SP 800-172
27 source controls mapped|26 target controls covered
40%
ISO 22301:2019
25 source controls mapped|38 target controls covered
37%
APRA CPS 230 Operational Risk Management
25 source controls mapped|30 target controls covered
37%
ACSC Essential Eight
25 source controls mapped|18 target controls covered
37%
APRA CPS 234
23 source controls mapped|22 target controls covered
34%
APEC Cross-Border Privacy Rules (CBPR) System
22 source controls mapped|17 target controls covered
33%
UK Cyber Essentials
20 source controls mapped|25 target controls covered
30%
APPI
12 source controls mapped|6 target controls covered
18%
APRA CPS 220 Risk Management
11 source controls mapped|14 target controls covered
16%
Authorised Economic Operator (AEO) Programmes - Global Standards
9 source controls mapped|7 target controls covered
13%
Australian Privacy Principles (APPs)
7 source controls mapped|5 target controls covered
10%
NIST SP 800-218
3 source controls mapped|3 target controls covered
4%
ISO/IEC 42001:2023
2 source controls mapped|2 target controls covered
3%
NIST SP 800-181
2 source controls mapped|5 target controls covered
3%
ISO/IEC 17050-2:2004
1 source controls mapped|1 target controls covered
1%
ISO/IEC 38500:2024
1 source controls mapped|2 target controls covered
1%
NIST SP 800-53A Rev. 5
1 source controls mapped|3 target controls covered
1%
ISO/IEC 23894:2023
1 source controls mapped|1 target controls covered
1%
ISO 31000:2018
1 source controls mapped|2 target controls covered
1%
COSO Internal Control - Integrated Framework (2013)
1 source controls mapped|1 target controls covered
1%

What is HIPAA Security Rule and who does it apply to?

HIPAA Security Rule is a compliance framework from United States with 5 domains and 67 controls. Health Insurance Portability and Accountability Act security standards for protecting electronic protected health information (ePHI) It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

What does HIPAA Security Rule actually require?

HIPAA Security Rule has 67 controls organised across 5 domains. The largest domains are Administrative (32 controls), Physical (12 controls), Technical (12 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

If I already comply with another framework, how much of HIPAA Security Rule do I already cover?

HIPAA Security Rule maps to 46 other compliance frameworks. The top mapping partners are ISO 27001:2022 (100% coverage), SOC 2 (99% coverage), ISO 27002:2022 (99% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I implement HIPAA Security Rule?

Start your HIPAA Security Rule compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about HIPAA Security Rule requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 67 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.

Get Started Free →

Free forever — no credit card required