MARS-E
Minimum Acceptable Risk Standards for Exchanges (Healthcare marketplace)
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (22)
Access Control
| Code | Title |
|---|---|
| MARS-E-AC-01 | Account Management |
| MARS-E-AC-02 | Least Privilege |
| MARS-E-AC-03 | Remote Access |
| MARSE-AC-001 | Access Authorization for Exchange Systems |
| MARSE-AC-002 | Privileged Access Management |
Assessment and Authorization
| Code | Title |
|---|---|
| MARS-E-CA-01 | Security Assessments |
| MARS-E-CA-02 | Authorization to Operate |
| MARSE-CA-001 | Continuous Monitoring Strategy |
| MARSE-CA-002 | Interconnection Security Agreements |
Audit and Accountability
| Code | Title |
|---|---|
| MARS-E-AU-01 | Audit Events |
| MARS-E-AU-02 | Audit Review, Analysis and Reporting |
| MARSE-AU-001 | Audit Log Retention |
| MARSE-AU-002 | Time Stamps |
Awareness and Training
| Code | Title |
|---|---|
| MARS-E-AT-01 | Security and Privacy Awareness Training |
| MARSE-AT-001 | Insider Threat Awareness |
Configuration Management
| Code | Title |
|---|---|
| MARS-E-CM-01 | Configuration Management |
| MARSE-CM-001 | Software Usage Restrictions |
| MARSE-CM-002 | Information System Component Inventory |
Contingency Planning
| Code | Title |
|---|---|
| MARS-E-CP-01 | Contingency Planning |
Identification and Authentication
| Code | Title |
|---|---|
| MARS-E-IA-01 | Identification and Authentication |
| MARSE-IA-001 | Authenticator Management |
Incident Response
| Code | Title |
|---|---|
| MARS-E-IR-01 | Incident Response |
| MARSE-IR-001 | Incident Reporting to CMS and IRS |
MARS-E: Administrative Safeguards
Organizational security management (MARS-E)
| Code | Title |
|---|---|
| MARSE-06 | Security management process and risk analysis |
| MARSE-07 | Workforce security and clearance procedures |
| MARSE-08 | Information access management |
| MARSE-09 | Security awareness and training program |
| MARSE-10 | Contingency planning for ePHI |
| MARSE-11 | Business associate management |
MARS-E: Organizational Requirements
Policies, procedures, and documentation (MARS-E)
| Code | Title |
|---|---|
| MARSE-21 | Security and privacy policies |
| MARSE-22 | Documentation and record retention |
| MARSE-23 | Compliance evaluation and review |
| MARSE-24 | Incident reporting procedures |
MARS-E: Patient Data Protection
Safeguarding protected health information (MARS-E)
| Code | Title |
|---|---|
| MARSE-01 | ePHI access controls and authorization |
| MARSE-02 | ePHI encryption at rest and in transit |
| MARSE-03 | Minimum necessary standard enforcement |
| MARSE-04 | Patient data de-identification procedures |
| MARSE-05 | Audit trail for ePHI access |
MARS-E: Physical Safeguards
Physical security for systems with ePHI (MARS-E)
| Code | Title |
|---|---|
| MARSE-17 | Facility access controls |
| MARSE-18 | Workstation security and use policies |
| MARSE-19 | Device and media controls |
| MARSE-20 | Disposal and re-use procedures |
MARS-E: Technical Safeguards
Technical measures for ePHI protection (MARS-E)
| Code | Title |
|---|---|
| MARSE-12 | Unique user identification and authentication |
| MARSE-13 | Automatic logoff and session management |
| MARSE-14 | Audit controls and monitoring |
| MARSE-15 | Integrity controls for ePHI |
| MARSE-16 | Transmission security and encryption |
Media Protection
| Code | Title |
|---|---|
| MARS-E-MP-01 | Media Protection |
Personnel Security
| Code | Title |
|---|---|
| MARSE-PS-001 | Personnel Screening |
Physical and Environmental Protection
| Code | Title |
|---|---|
| MARSE-PE-001 | Physical Access Control |
Planning
| Code | Title |
|---|---|
| MARS-E-PL-01 | System Security Plan |
Program Management
| Code | Title |
|---|---|
| MARSE-PM-001 | Information Security Program Plan |
Risk Assessment
| Code | Title |
|---|---|
| MARS-E-RA-01 | Risk Assessment |
| MARSE-RA-001 | Vulnerability Scanning |
System and Communications Protection
| Code | Title |
|---|---|
| MARS-E-SC-01 | Boundary Protection |
| MARS-E-SC-02 | Transmission Confidentiality and Integrity |
| MARSE-SC-001 | Cryptographic Key Management |
| MARSE-SC-002 | Data at Rest Protection |
System and Information Integrity
| Code | Title |
|---|---|
| MARS-E-SI-01 | Flaw Remediation |
| MARS-E-SI-02 | Information System Monitoring |
| MARSE-SI-001 | Malicious Code Protection |
System and Services Acquisition
| Code | Title |
|---|---|
| MARSE-SA-001 | External Service Providers |
Your Compliance Coverage
If you comply with MARS-E, you already cover:
GLI-33 — Gaming Laboratories International Event Wagering Systems
18%
11 controls mapped
Compare →TISAX — Trusted Information Security Assessment Exchange
18%
11 controls mapped
Compare →ISO 13485
18%
11 controls mapped
Compare →+ 564 more: FDA 21 CFR Part 11 (18%), US Gramm-Leach-Bliley Act (GLBA) — Higher Education Safeguards Rule (18%)
See all 567 mapped frameworks ↓Maps to 567 other frameworks
Frequently Asked Questions
What is MARS-E?
MARS-E is a compliance framework from United States with 22 domains and 62 controls. Minimum Acceptable Risk Standards for Exchanges (Healthcare marketplace) It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does MARS-E have?
MARS-E has 62 controls organised across 22 domains. The largest domains are MARS-E: Administrative Safeguards (6 controls), Access Control (5 controls), MARS-E: Patient Data Protection (5 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does MARS-E map to?
MARS-E maps to 567 other compliance frameworks. The top mapping partners are GLI-33 — Gaming Laboratories International Event Wagering Systems (18% coverage), TISAX — Trusted Information Security Assessment Exchange (18% coverage), ISO 13485 (18% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with MARS-E compliance?
Start your MARS-E compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about MARS-E requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 62 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 700 frameworks.
Get Started Free →Free forever — no credit card required