| 45 CFR 164.308(a)(1)(ii)(A)Risk analysis | Conduct an accurate and current assessment of the risks to electronic protected health information (ePHI) across the environment. | 1.1 Detailed Enterprise Asset Inventory · 1.2 Address Unauthorized Assets · 3.1 Data Management Process · 18.1 Penetration Testing Program |
|---|
| 45 CFR 164.308(a)(1)(ii)(B)Risk management | Put security measures in place sufficient to reduce identified risks to a reasonable and appropriate level. | 4.1 Secure Configuration Process · 7.1 Vulnerability Management Process |
|---|
| 45 CFR 164.308(a)(3)Workforce security | Authorize and supervise workforce members who work with ePHI, and remove access when a member leaves or changes role. | 5.1 Inventory of Accounts · 6.1 Access Granting Process · 6.2 Access Revoking Process |
|---|
| 45 CFR 164.308(a)(4)Information access management | Authorize access to ePHI on a need-to-know basis and review that access over time, including for service providers under a business associate agreement (BAA). | 6.1 Access Granting Process · 6.8 Role-Based Access Control · 15.1 Inventory of Service Providers · 15.2 Service Provider Management Policy |
|---|
| 45 CFR 164.308(a)(5)Security awareness and training | Provide a security awareness program, including protection from malicious software, log-in monitoring, and password practices. | 14.1 Security Awareness Program · 14.2 Train Workforce to Recognize Social Engineering · 10.1 Anti-Malware Software |
|---|
| 45 CFR 164.310(a), (c), (d)Physical safeguards | Limit physical access to systems and facilities that hold ePHI; govern workstation use and the handling and disposal of media. | 1.1 Detailed Enterprise Asset Inventory · 3.5 Securely Dispose of Data · 12.1 Ensure Network Infrastructure is Up-to-Date |
|---|
| 45 CFR 164.312(a)(1)Access control (technical) | Allow access to ePHI only to authorized persons or software, with unique user identification and an emergency-access procedure. | 5.2 Use Unique Passwords · 6.3 MFA for Externally-Exposed Applications · 6.4 MFA for Remote Network Access · 6.5 MFA for Administrative Access |
|---|
| 45 CFR 164.312(b)Audit controls | Record and examine activity in systems that contain or use ePHI. | 8.2 Collect Audit Logs · 8.5 Collect Detailed Audit Logs · 8.9 Centralize Audit Logs · 8.11 Conduct Audit Log Reviews |
|---|
| 45 CFR 164.312(c), (e)Integrity and transmission security | Protect ePHI from improper alteration or destruction, and guard it against unauthorized access while in transit. | 3.10 Encrypt Sensitive Data in Transit · 3.11 Encrypt Sensitive Data at Rest · 3.6 Encrypt Data on End-User Devices |
|---|
| 45 CFR 164.404Breach notification to individuals | Notify affected individuals without unreasonable delay and no later than 60 days after discovery of a breach of unsecured protected health information; the 45 CFR 164.408 timeline governs notice to the Secretary. | 17.1 Designate Incident-Handling Personnel · 17.4 Incident Response Process · 8.11 Conduct Audit Log Reviews |
|---|