HIPAA Security Rule
The federal safeguards standard for electronic protected health information, binding on covered entities and their business associates.
45 CFR Part 164 Subparts A and C · HHS Office for Civil Rights
00Answer
01Standing
A project opens into evidence lanes with a real control set behind them; collection is demonstrative until a test plan runs against a real target.
Blueprint with 5 evidence lanes and a control set; no registered test plans yet. A project opens into real lanes; collection is demonstrative until a READY plan or a release path exists.
- Engagement
- HIPAA Security Rule readiness
- Control set
- 65 requirements — 22 standards and 43 implementation specifications (Required or Addressable) — with the regulation's own citations and verbatim text, parsed from eCFR point-in-time XML. Federal regulation is not subject to copyright, so the text is the rule's own, not a paraphrase.
- Native identifiers
- Regulation citations, e.g. 164.308(a)(1)(ii)(A) for an implementation specification and 164.312(b) for a standard.
- Evidence lanes
- 01§ 164.308 — Administrative safeguardsrisk analysis and risk management plan · sanction policy and information system activity review records · workforce clearance, authorization and termination records · access authorization and modification records · security awareness training completion · incident response procedure and incident log · contingency, backup and disaster recovery plans with test results · periodic technical and non-technical evaluation · business associate agreements
- 02§ 164.310 — Physical safeguardsfacility security plan and access control records · workstation use and security standards · media disposal and re-use records · hardware and media movement accountability
- 03§ 164.312 — Technical safeguardsunique user identification and emergency access configuration · automatic logoff and encryption settings · audit log configuration and review records · integrity controls for ePHI · authentication configuration (MFA, identity provider) · transmission encryption configuration
- 04§ 164.314 — Organizational requirementsexecuted business associate and subcontractor agreements · group health plan document provisions, where applicable
- 05§ 164.316 — Policies, procedures and documentationsecurity policies and procedures with version history · documentation retention and availability records · periodic review and update records
02Registry record
- Registry status
- Beta · catalog on diskParsed catalog: a source-pinned control or requirement catalog for this regime exists in the repo. `catalogPath` is non-null and `controlCount` is real. This does not mean tenant workflows are activated or that an assurance outcome has been earned.
- Control units
- 6565 requirements — 22 standards and 43 implementation specifications (Required or Addressable) — with the regulation's own citations and verbatim text, parsed from eCFR point-in-time XML. Federal regulation is not subject to copyright, so the text is the rule's own, not a paraphrase.
- Control families
- Administrative safeguards · Physical safeguards · Technical safeguards · Organizational requirements · Policies, procedures and documentation
- Applies to
- healthcare · US
- Verification
- Primary — the issuing body's own page was read and states this version. checked 2026-09-23
- Pending change
- OCR's January 2025 proposal (RIN 0945-AA22) is not final, so the existing Security Rule remains in force. HHS's Unified Agenda lists July 2027 as an anticipated final-action date, not a guaranteed effective date.Expected: July 2027 (anticipated final action in the HHS Unified Agenda)
03Version ledger
| 45 CFR Part 164 Subparts A and C | Current edition | date not published |
06Related frameworks
- HITRUST CSFv11.8.0
Also applies to healthcare · A licensed cybersecurity and risk-management framework used across healthcare and other sectors. HITRUST offers scoped assessment and certification programs through its authorized processes; registry tracking claims no certification.
- HIPAA Breach Notification Rule45 CFR §§ 164.400–414
Also applies to healthcare · What a covered entity or business associate must tell individuals, the media, and HHS after a breach of unsecured protected health information, and how fast.
- SOC 22017 TSC (revised points of focus, 2022)
Same framework family · Independent assurance over how a service organization handles customer data. Type 1 and Type 2 are two report options over the same criteria, not two standards.
- HIPAA Privacy Rule45 CFR Part 160 and Part 164 Subparts A and E
Also applies to healthcare · The federal rule governing permitted uses and disclosures of protected health information, minimum-necessary practices, notices, and individual privacy rights for covered entities and business associates.