How to use this guidance
Regulatory requirements are taken from the current HIPAA Security Rule text and HHS summary. NIST relationships are limited to the corresponding standard guidance and crosswalk publication references that are explicitly identified by NIST. HIPAAmart recommendations are editorial implementation considerations, not regulatory requirements.
References
- 45 CFR Part 164, Subpart C Electronic Code of Federal Regulations
- Summary of the HIPAA Security Rule HHS Office for Civil Rights
- NIST SP 800-66 Rev. 2 National Institute of Standards and Technology
- NIST Cybersecurity and Privacy Reference Tool National Institute of Standards and Technology
- NIST SP 800-66 Rev. 2 PDF National Institute of Standards and Technology