HIPAA Security Rule (45 CFR 164): the clauses the register cites
The 11 HIPAA Security Rule (45 CFR 164) clauses that questions are placed on, each with the evidence an assessor asks for and where answers usually fall short.
The requirement lines are our statement of each clause, read against the copy we hold and cited to it.
11 clauses
the families they anchorHIPAA 164.308(a)(1)(ii)(A) Risk Analysis (Required)Conduct accurate and thorough assessment of potential risks and vulnerabilities to ePHI. NIST recommends the nine-step risk analysis methodology and integration with NIST SP 800-30 and the NIST RMF.
Where answers usually fall short: Risk analysis is checklist-style, not threat-based; Not refreshed after material changes
Source: HIPAA Security Rule (45 CFR 164)
HIPAA 164.308(a)(6)(i) Security Incident Procedures (Standard)Implement policies to address security incidents. NIST recommends an incident response plan aligned to NIST SP 800-61 with detection, analysis, containment, eradication, and recovery phases.
Where answers usually fall short: Plan exists but not exercised; Roles ambiguous during real incident
Source: HIPAA Security Rule (45 CFR 164)
HIPAA 164.308(a)(6)(ii) Response and Reporting (Required)Identify and respond to suspected or known incidents, mitigate harmful effects, and document incidents and their outcomes. NIST recommends linkage to HIPAA Breach Notification Rule timelines.
Where answers usually fall short: Incident closure without root cause; Breach risk assessment not performed
Source: HIPAA Security Rule (45 CFR 164)
HIPAA 164.308(a)(7)(i) Contingency Plan (Standard)Establish policies for responding to emergencies that damage ePHI systems. NIST recommends contingency planning per SP 800-34 with business impact analysis driving recovery priorities.
Where answers usually fall short: BIA not performed; RTO and RPO undefined
Source: HIPAA Security Rule (45 CFR 164)
HIPAA 164.308(a)(7)(ii)(A) Data Backup Plan (Required)Establish procedures to create and maintain retrievable exact copies of ePHI. NIST recommends offline or immutable backups, encryption, and regular restoration testing.
Where answers usually fall short: Backups exist but never restored; No air-gapped or immutable copy for ransomware
Source: HIPAA Security Rule (45 CFR 164)
HIPAA 164.308(b)(1) Business Associate Contracts and Other Arrangements (Standard)A covered entity may permit a business associate to handle ePHI only after obtaining satisfactory assurances via written contract. NIST recommends due diligence, security questionnaires, and ongoing monitoring of BAs.
Where answers usually fall short: BA inventory incomplete; BAAs missing for cloud vendors
Source: HIPAA Security Rule (45 CFR 164)
HIPAA 164.312(a)(2)(iv) Encryption and Decryption (Addressable)Implement a mechanism to encrypt and decrypt ePHI. NIST recommends FIPS 140-validated cryptography, encryption at rest for all ePHI stores, and key management aligned to SP 800-57.
Where answers usually fall short: Legacy databases unencrypted; Endpoint encryption not enforced
Source: HIPAA Security Rule (45 CFR 164)
HIPAA 164.312(b) Audit Controls (Standard)Implement hardware, software, and procedural mechanisms that record and examine activity in information systems that contain or use ePHI. NIST recommends central log management aligned to SP 800-92.
Where answers usually fall short: Application-level audit logs missing; Logs retained less than six years where applicable
Source: HIPAA Security Rule (45 CFR 164)
HIPAA 164.312(d) Person or Entity Authentication (Standard)Implement procedures to verify that a person or entity seeking access to ePHI is the one claimed. NIST recommends multi-factor authentication and authenticator assurance levels per SP 800-63B.
Where answers usually fall short: No MFA on ePHI access; Weak factor combinations
Source: HIPAA Security Rule (45 CFR 164)
HIPAA 164.312(e)(1) Transmission Security (Standard)Implement technical security measures to guard against unauthorized access to ePHI transmitted over an electronic communications network. NIST recommends encrypted transport, secure email, and validated VPN.
Where answers usually fall short: Legacy TLS versions enabled; FTP and SMTP used in clear
Source: HIPAA Security Rule (45 CFR 164)
HIPAA 164.314(a)(1) Business Associate Contracts or Other Arrangements (Standard)The contract or other arrangement required by 164.308(b)(3) must meet the requirements of paragraph (a)(2)(i), (a)(2)(ii), or (a)(2)(iii) of this section, as applicable.
Where answers usually fall short: Older BAAs missing post-Omnibus requirements; Government arrangements undocumented
Source: HIPAA Security Rule (45 CFR 164)