HIPAAmart

HIPAA and NIST orientation

Translating HIPAA to NIST.

The HIPAA Security Rule defines obligations for protecting ePHI. NIST SP 800-66 Rev. 2 provides implementation guidance organized around those standards.

Last verified August 28, 2026

How to use this guidance

Regulatory requirements are taken from the current HIPAA Security Rule text and HHS summary. NIST relationships are limited to the corresponding standard guidance and crosswalk publication references that are explicitly identified by NIST. HIPAAmart recommendations are editorial implementation considerations, not regulatory requirements.

Explore the Security Rule

View the verified crosswalk

References