Customer type
What a hospital or health plan's security questionnaire reaches for
Health customers ask the HIPAA Security Rule questions and a business associate agreement before anything else, then the ordinary security ones.
Frameworks ticked by default for this customer: ISO/IEC 27001:2022, SOC 2 (Trust Services Criteria), HIPAA Security Rule (45 CFR 164) and GDPR, Regulation (EU) 2016/679. Read a questionnaire as this customer.
Families, with the clauses from this customer's other frameworks
| Family | Anchor clauses in this customer's frameworks |
|---|---|
| Information security policy | SOC 2 CC5.3 |
| Risk assessment | SOC 2 CC3.2 · HIPAA 164.308(a)(1)(ii)(A) |
| Independent audit and certification | SOC 2 CC4.1 |
| Multi-factor authentication | SOC 2 CC6.1 · HIPAA 164.312(d) |
| Password policy | SOC 2 CC6.1 |
| Access provisioning and review | SOC 2 CC6.2 |
| Encryption at rest | SOC 2 CC6.1 · HIPAA 164.312(a)(2)(iv) · GDPR Art. 32 |
| Encryption in transit | HIPAA 164.312(e)(1) |
| Data retention and secure deletion | GDPR Art. 28 |
| Data location and transfers | GDPR Art. 44 · GDPR Art. 46 |
| Logging and monitoring | SOC 2 CC7.2 · HIPAA 164.312(b) |
| Vulnerability and patch management | SOC 2 CC7.1 |
| Secure development and change | SOC 2 CC8.1 |
| Incident response plan | SOC 2 CC7.4 · HIPAA 164.308(a)(6)(i) |
| Notifying the customer of an incident | SOC 2 CC7.4 · HIPAA 164.308(a)(6)(ii) · GDPR Art. 33 |
| Business continuity plan | SOC 2 A1.3 · HIPAA 164.308(a)(7)(i) |
| Backup and disaster recovery | SOC 2 A1.2 · HIPAA 164.308(a)(7)(ii)(A) |
| Subcontractors and subprocessors | SOC 2 CC9.2 · GDPR Art. 28 |
| Assessing your own suppliers | SOC 2 CC9.2 |
| Data subject requests | GDPR Art. 15 · GDPR Art. 28 |
| Lawful basis, consent and privacy notice | GDPR Art. 6 |
| Data processing agreement | GDPR Art. 28 |
| Health information and business associate termsno ISO 27001 clause: beyond an ISO 27001 certificate | HIPAA 164.308(b)(1) · HIPAA 164.314(a)(1) |