Regulation
HIPAA
HIPAA — Security, Privacy & Breach Notification
16 requirements · 16 connected unified controls
Open HIPAA in the mapRequirements and control mappings
“Full” and “Partial” describe the catalog mapping to a unified control. A partial mapping includes the remaining requirement. These mappings do not establish an organization’s implementation or certification.
HIPAA Security Rule
HIPAA Privacy & Breach Notification
| Requirement | Unified control and mapping |
|---|---|
| HIPAA-164.502Uses and disclosures of PHI (permitted/required uses, minimum necessary) | UC-DATA-03 — Limit personal-data use to stated purposes and minimum necessaryPartial Remaining requirement: required disclosures to HHS, personal-representative and business-associate limits not addressed |
| HIPAA-164.508Authorizations required for other uses and disclosures of PHI | UC-DATA-02 — Obtain and honor consent for collection, use, and disclosurePartial Remaining requirement: when authorization is mandatory (marketing, sale of PHI, psychotherapy notes) not established |
| HIPAA-164.514De-identification of PHI and limited data sets | |
| HIPAA-164.520Notice of privacy practices for PHI | UC-DATA-05 — Provide privacy notices and transparency to data subjectsPartial Remaining requirement: NPP-specific content (header, complaint process, duties, effective date) and acknowledgment mechanics omitted |
| HIPAA-164.524Individual right of access to PHI | |
| HIPAA-164.526Individual right to amend PHI | UC-DATA-07 — Keep personal data accurate and honor correction requestsPartial Remaining requirement: statement-of-disagreement appending and inclusion in future disclosures omitted |
| HIPAA-164.400-414Breach notification to individuals, media, and HHS (incl. business-associate duties) | UC-IR-08 — Notify authorities and affected parties within deadlinesPartial Remaining requirement: individual notice within 60 days; media notice at 500+ residents of a state/jurisdiction; HHS notice at 500+ individuals (contemporaneous); HHS notification required for all breaches (sub-500 via annual log) |