Framework module · hipaa-security-rule
HIPAA Security Rule
The federal safeguards standard for electronic protected health information, binding on covered entities and their business associates.
45 CFR Part 164 Subparts A and C · HHS Office for Civil Rights
Standing today
Acquisition required
01Standing
Acquisition required
Named, with the authority's acquisition path recorded; onboarding is refused until a control set is registered.
HIPAA Security Rule cannot be onboarded yet: Verbatim regulatory text not ingested as a control catalog. Onboarding is enabled once a control set is registered, so a new project never opens into an empty workspace.
HIPAA Security Rule cannot be onboarded yet: Verbatim regulatory text not ingested as a control catalog. Onboarding is enabled once a control set is registered, so a new project never opens into an empty workspace.
02Registry record
checked 2026-08-06
- Registry status
- Roadmap · modelledWe model the regime — control families and at least one crosswalk map on disk — but no control catalog is ingested.
- Control units
- Not on record — no catalog ingested and no authority-published count cited.
- Control families
- Administrative safeguards · Physical safeguards · Technical safeguards
- Applies to
- healthcare · US
- Verification
- Secondary — corroborated across independent sources; the authority blocks automated fetch or does not state it plainly. checked 2026-08-06
- Pending change
- OCR's January 2025 proposed overhaul (RIN 0945-AA22) is still not final. HHS moved it to long-term actions with final action anticipated July 2027, and a coalition of more than 100 provider organizations has asked for withdrawal. The rule in force is unchanged.Expected: July 2027 (HHS unified agenda)
03Version ledger
1 edition
| 45 CFR Part 164 Subparts A and C | Current edition | date not published |