Security Questionnaire Mapper
Customer type

What a hospital or health plan's security questionnaire reaches for

Health customers ask the HIPAA Security Rule questions and a business associate agreement before anything else, then the ordinary security ones.

Frameworks ticked by default for this customer: ISO/IEC 27001:2022, SOC 2 (Trust Services Criteria), HIPAA Security Rule (45 CFR 164) and GDPR, Regulation (EU) 2016/679. Read a questionnaire as this customer.

Families, with the clauses from this customer's other frameworks

FamilyAnchor clauses in this customer's frameworks
Information security policySOC 2 CC5.3
Risk assessmentSOC 2 CC3.2 · HIPAA 164.308(a)(1)(ii)(A)
Independent audit and certificationSOC 2 CC4.1
Multi-factor authenticationSOC 2 CC6.1 · HIPAA 164.312(d)
Password policySOC 2 CC6.1
Access provisioning and reviewSOC 2 CC6.2
Encryption at restSOC 2 CC6.1 · HIPAA 164.312(a)(2)(iv) · GDPR Art. 32
Encryption in transitHIPAA 164.312(e)(1)
Data retention and secure deletionGDPR Art. 28
Data location and transfersGDPR Art. 44 · GDPR Art. 46
Logging and monitoringSOC 2 CC7.2 · HIPAA 164.312(b)
Vulnerability and patch managementSOC 2 CC7.1
Secure development and changeSOC 2 CC8.1
Incident response planSOC 2 CC7.4 · HIPAA 164.308(a)(6)(i)
Notifying the customer of an incidentSOC 2 CC7.4 · HIPAA 164.308(a)(6)(ii) · GDPR Art. 33
Business continuity planSOC 2 A1.3 · HIPAA 164.308(a)(7)(i)
Backup and disaster recoverySOC 2 A1.2 · HIPAA 164.308(a)(7)(ii)(A)
Subcontractors and subprocessorsSOC 2 CC9.2 · GDPR Art. 28
Assessing your own suppliersSOC 2 CC9.2
Data subject requestsGDPR Art. 15 · GDPR Art. 28
Lawful basis, consent and privacy noticeGDPR Art. 6
Data processing agreementGDPR Art. 28
Health information and business associate termsno ISO 27001 clause: beyond an ISO 27001 certificateHIPAA 164.308(b)(1) · HIPAA 164.314(a)(1)