Administrative, physical, and technical safeguards
Security Management Process
45 CFR § 164.308(a)(1) · Administrative
Conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI, implement security measures to reduce those risks, apply appropriate sanctions, and regularly review information-system activity.
Assigned Security Responsibility
45 CFR § 164.308(a)(2) · Administrative
Identify the security official who is responsible for developing and implementing the policies and procedures required by the Security Rule.
Workforce Security
45 CFR § 164.308(a)(3) · Administrative
Implement policies and procedures to ensure that all members of the workforce have appropriate access to ePHI and to prevent workforce members from obtaining access not appropriate to their role.
Information Access Management
45 CFR § 164.308(a)(4) · Administrative
Implement policies and procedures for authorizing access to ePHI and for establishing, documenting, reviewing, and modifying access as appropriate to a workforce member's role and the organization's environment.
Security Awareness and Training
45 CFR § 164.308(a)(5) · Administrative
Implement a security-awareness and training program for all members of the workforce, including management.
Security Incident Procedures
45 CFR § 164.308(a)(6) · Administrative
Implement policies and procedures to address security incidents, including identifying and responding to suspected or known incidents, mitigating harmful effects, and documenting incidents and outcomes.
Contingency Plan
45 CFR § 164.308(a)(7) · Administrative
Establish and implement policies and procedures for responding to an emergency or other occurrence that damages systems containing ePHI.
Evaluation
45 CFR § 164.308(a)(8) · Administrative
Perform a periodic technical and nontechnical evaluation, based initially upon the standards implemented under the Security Rule and subsequently in response to environmental or operational changes affecting the security of ePHI.
Business Associate Contracts and Other Arrangements
45 CFR § 164.308(b)(1) · Administrative
Obtain satisfactory assurances from a business associate that it will appropriately safeguard ePHI, documented through a written contract or other arrangement as required.
Facility Access Controls
45 CFR § 164.310(a) · Physical
Implement policies and procedures to limit physical access to electronic information systems and the facilities in which they are housed, while ensuring properly authorized access.
Workstation Use
45 CFR § 164.310(b) · Physical
Implement policies and procedures that specify the proper functions to be performed and the manner in which workstations may be used to access ePHI.
Workstation Security
45 CFR § 164.310(c) · Physical
Implement physical safeguards for all workstations that access ePHI to restrict access to authorized users.
Device and Media Controls
45 CFR § 164.310(d) · Physical
Implement policies and procedures that govern the receipt and removal of hardware and electronic media containing ePHI, including disposal, re-use, accountability, and data backup or storage.
Access Control
45 CFR § 164.312(a) · Technical
Implement technical policies and procedures for electronic information systems that maintain ePHI to allow access only to people or software programs that have been granted access rights.
Audit Controls
45 CFR § 164.312(b) · Technical
Implement hardware, software, and/or procedural mechanisms that record and examine activity in information systems that contain or use ePHI.
Integrity
45 CFR § 164.312(c) · Technical
Implement policies and procedures to protect ePHI from improper alteration or destruction.
Person or Entity Authentication
45 CFR § 164.312(d) · Technical
Implement procedures to verify that a person or entity seeking access to ePHI is the one claimed.
Transmission Security
45 CFR § 164.312(e) · Technical
Implement technical security measures to guard against unauthorized access to ePHI that is being transmitted over an electronic communications network.
References
- 45 CFR Part 164, Subpart C Electronic Code of Federal Regulations
- Summary of the HIPAA Security Rule HHS Office for Civil Rights
- NIST SP 800-66 Rev. 2 National Institute of Standards and Technology
- NIST Cybersecurity and Privacy Reference Tool National Institute of Standards and Technology
- NIST SP 800-66 Rev. 2 PDF National Institute of Standards and Technology