Framework library
Framework module · hipaa-security-rule

HIPAA Security Rule

The federal safeguards standard for electronic protected health information, binding on covered entities and their business associates.

45 CFR Part 164 Subparts A and C · HHS Office for Civil Rights

Standing today
Acquisition required

01Standing

Acquisition required

Named, with the authority's acquisition path recorded; onboarding is refused until a control set is registered.

HIPAA Security Rule cannot be onboarded yet: Verbatim regulatory text not ingested as a control catalog. Onboarding is enabled once a control set is registered, so a new project never opens into an empty workspace.

HIPAA Security Rule cannot be onboarded yet: Verbatim regulatory text not ingested as a control catalog. Onboarding is enabled once a control set is registered, so a new project never opens into an empty workspace.

02Registry record

checked 2026-08-06
Registry status
Roadmap · modelledWe model the regime — control families and at least one crosswalk map on disk — but no control catalog is ingested.
Control units
Not on record — no catalog ingested and no authority-published count cited.
Control families
Administrative safeguards · Physical safeguards · Technical safeguards
Applies to
healthcare · US
Verification
Secondary — corroborated across independent sources; the authority blocks automated fetch or does not state it plainly. checked 2026-08-06
Pending change
OCR's January 2025 proposed overhaul (RIN 0945-AA22) is still not final. HHS moved it to long-term actions with final action anticipated July 2027, and a coalition of more than 100 provider organizations has asked for withdrawal. The rule in force is unchanged.Expected: July 2027 (HHS unified agenda)

03Version ledger

1 edition
45 CFR Part 164 Subparts A and CCurrent editiondate not published
HIPAA Security Rule — framework module | ControlFrame