Regulation

HIPAA

HIPAA — Security, Privacy & Breach Notification

16 requirements · 16 connected unified controls

Open HIPAA in the map
Version
45 CFR Parts 160/164 (Security, Privacy, Breach Notification)
Published
2003-02-20 (Security Rule)
Effective
2005-04-20 (Security Rule)
Amendments
Omnibus Final Rule (2013)

Requirements and control mappings

“Full” and “Partial” describe the catalog mapping to a unified control. A partial mapping includes the remaining requirement. These mappings do not establish an organization’s implementation or certification.

HIPAA Security Rule

RequirementUnified control and mapping
HIPAA-164.308Administrative safeguards (security management, risk analysis, workforce security, training, contingency plan, evaluation, BAAs)
UC-HR-01 — Screen personnel commensurate with position riskPartial

Remaining requirement: risk analysis, training, contingency, evaluation, and BAAs satisfied in other domains

HIPAA-164.310Physical safeguards (facility access controls, workstation use/security, device and media controls)
UC-PHYS-01 — Restrict physical access to facilities and secure areasPartial

Remaining requirement: also covers workstation use/security and device and media controls

HIPAA-164.312(a)Technical access control for ePHI (unique user ID, emergency access, automatic logoff, encryption/decryption)
UC-ACCESS-05 — Enforce approved authorizations for information and functionsPartial

Remaining requirement: automatic logoff and encryption/decryption of ePHI are satisfied by the session-lock (UC-ACCESS-12) and cryptographic (UC-CRYPTO-01) companion controls; emergency-access is an availability arm

HIPAA-164.312(b)Audit controls recording activity in systems with ePHI
HIPAA-164.312(c)Integrity controls protecting ePHI from improper alteration or destruction
UC-DATA-13 — Safeguard personal information with reasonable securityPartial

Remaining requirement: the electronic mechanism to authenticate that ePHI has not been altered or destroyed is the specific integrity-verification arm

HIPAA-164.312(d)Person or entity authentication before ePHI access
HIPAA-164.312(e)Transmission security for ePHI (integrity controls and encryption in transit)
HIPAA-164.314Organizational requirements (business associate contracts, group health plan requirements)
UC-TPRM-03 — Bind vendors to security and privacy terms by contractPartial

Remaining requirement: group health plan document requirements (164.314(b)) fall outside vendor/BA contracting

HIPAA-164.316Policies and procedures and documentation requirements

HIPAA Privacy & Breach Notification

RequirementUnified control and mapping
HIPAA-164.502Uses and disclosures of PHI (permitted/required uses, minimum necessary)
UC-DATA-03 — Limit personal-data use to stated purposes and minimum necessaryPartial

Remaining requirement: required disclosures to HHS, personal-representative and business-associate limits not addressed

HIPAA-164.508Authorizations required for other uses and disclosures of PHI
UC-DATA-02 — Obtain and honor consent for collection, use, and disclosurePartial

Remaining requirement: when authorization is mandatory (marketing, sale of PHI, psychotherapy notes) not established

HIPAA-164.514De-identification of PHI and limited data sets
HIPAA-164.520Notice of privacy practices for PHI
UC-DATA-05 — Provide privacy notices and transparency to data subjectsPartial

Remaining requirement: NPP-specific content (header, complaint process, duties, effective date) and acknowledgment mechanics omitted

HIPAA-164.524Individual right of access to PHI
HIPAA-164.526Individual right to amend PHI
UC-DATA-07 — Keep personal data accurate and honor correction requestsPartial

Remaining requirement: statement-of-disagreement appending and inclusion in future disclosures omitted

HIPAA-164.400-414Breach notification to individuals, media, and HHS (incl. business-associate duties)
UC-IR-08 — Notify authorities and affected parties within deadlinesPartial

Remaining requirement: individual notice within 60 days; media notice at 500+ residents of a state/jurisdiction; HHS notice at 500+ individuals (contemporaneous); HHS notification required for all breaches (sub-500 via annual log)