Skip to content
Tidebreak Advisory

Vertical crosswalk · Healthcare

The Security Rule your compliance officer tracks, mapped to the controls your carrier recognizes.

CIS Controls v8.1.2 × HIPAA Security Rule (45 CFR Part 164 Subpart C)

Introduction and methodology

The HIPAA Security Rule does not read like a technical standard. The §164.308(a)(1) risk-analysis specification asks the covered entity to assess the risks to electronic protected health information. The §164.312 technical safeguards name the outcomes the practice must achieve for access control, audit controls, integrity, and transmission security. The Rule describes the safeguard a practice must have in place; it does not prescribe the controls that satisfy it.

This crosswalk is requirement-first. Each row names a Security Rule requirement and the obligation it carries, then lists the CIS Controls v8.1.2safeguards that support that obligation in a practice's IT environment. CIS Controls v8.1.2is the security framework a practice's cyber-insurance carrier, outside auditor, and regulator already recognize. The mapping is how a control finding lands in documentation a surveyor, a carrier, or OCR will accept.

The mapping is directional, not exhaustive. A safeguard listed against a requirement supports compliance with that requirement; it does not, on its own, establish it. Where no meaningful mapping exists, the absence is information. The crosswalk is a reference tool, not an opinion.

The crosswalk

Ten representative requirement rows. The HIPAA Security Rule requirement is the organizing column; the CIS Controls v8.1.2 safeguards are the supporting column.

HIPAA Security Rule requirements mapped to supporting CIS Controls v8.1.2 safeguards.
HIPAA Security Rule requirementObligationSupporting CIS Controls v8.1.2 safeguards
45 CFR 164.308(a)(1)(ii)(A)Risk analysisConduct an accurate and current assessment of the risks to electronic protected health information (ePHI) across the environment.1.1 Detailed Enterprise Asset Inventory · 1.2 Address Unauthorized Assets · 3.1 Data Management Process · 18.1 Penetration Testing Program
45 CFR 164.308(a)(1)(ii)(B)Risk managementPut security measures in place sufficient to reduce identified risks to a reasonable and appropriate level.4.1 Secure Configuration Process · 7.1 Vulnerability Management Process
45 CFR 164.308(a)(3)Workforce securityAuthorize and supervise workforce members who work with ePHI, and remove access when a member leaves or changes role.5.1 Inventory of Accounts · 6.1 Access Granting Process · 6.2 Access Revoking Process
45 CFR 164.308(a)(4)Information access managementAuthorize access to ePHI on a need-to-know basis and review that access over time, including for service providers under a business associate agreement (BAA).6.1 Access Granting Process · 6.8 Role-Based Access Control · 15.1 Inventory of Service Providers · 15.2 Service Provider Management Policy
45 CFR 164.308(a)(5)Security awareness and trainingProvide a security awareness program, including protection from malicious software, log-in monitoring, and password practices.14.1 Security Awareness Program · 14.2 Train Workforce to Recognize Social Engineering · 10.1 Anti-Malware Software
45 CFR 164.310(a), (c), (d)Physical safeguardsLimit physical access to systems and facilities that hold ePHI; govern workstation use and the handling and disposal of media.1.1 Detailed Enterprise Asset Inventory · 3.5 Securely Dispose of Data · 12.1 Ensure Network Infrastructure is Up-to-Date
45 CFR 164.312(a)(1)Access control (technical)Allow access to ePHI only to authorized persons or software, with unique user identification and an emergency-access procedure.5.2 Use Unique Passwords · 6.3 MFA for Externally-Exposed Applications · 6.4 MFA for Remote Network Access · 6.5 MFA for Administrative Access
45 CFR 164.312(b)Audit controlsRecord and examine activity in systems that contain or use ePHI.8.2 Collect Audit Logs · 8.5 Collect Detailed Audit Logs · 8.9 Centralize Audit Logs · 8.11 Conduct Audit Log Reviews
45 CFR 164.312(c), (e)Integrity and transmission securityProtect ePHI from improper alteration or destruction, and guard it against unauthorized access while in transit.3.10 Encrypt Sensitive Data in Transit · 3.11 Encrypt Sensitive Data at Rest · 3.6 Encrypt Data on End-User Devices
45 CFR 164.404Breach notification to individualsNotify affected individuals without unreasonable delay and no later than 60 days after discovery of a breach of unsecured protected health information; the 45 CFR 164.408 timeline governs notice to the Secretary.17.1 Designate Incident-Handling Personnel · 17.4 Incident Response Process · 8.11 Conduct Audit Log Reviews

Worked examples

Two representative findings drawn from healthcare assessments, each dual-mapped to a CIS Controls v8.1.2 safeguard set and the HIPAA Security Rule requirement it implicates.

Worked example

Critical

BAA with unmonitored vendor standing access

Security mapping

CIS Safeguards 15.1 · 15.2 · 6.8

Professional-standard mapping

HIPAA §164.308(a)(4) Information Access Management

Evidence 5, 11, 19

The practice's imaging vendor held a signed BAA and standing remote access. No periodic access review had been performed since onboarding four years prior. The vendor's subcontractor disclosures had changed twice without BAA amendment, and no log review identified after-hours administrative sessions from the vendor subnet.

Recommended action. Inventory the practice's service providers, review vendor access against current need each quarter, and reconcile BAA terms against the access actually granted, with documented sign-off by the compliance officer.

Worked example

Moderate

Audit logging enabled on ePHI systems but never reviewed

Security mapping

CIS Safeguards 8.9 · 8.11

Professional-standard mapping

HIPAA §164.312(b) Audit Controls

Evidence 22, 27

Systems holding electronic protected health information generated audit logs, but the logs were neither centralized nor examined. No procedure assigned anyone to review activity, and the practice could not demonstrate that unauthorized access would be detected. The §164.312(b) audit-control specification asks the practice to record and examine activity, not only to record it.

Recommended action. Centralize audit logs from systems that contain or use ePHI, and assign documented periodic log review so that anomalous access is surfaced rather than only retained.

Regulatory variation

The HIPAA Security Rule sets a federal floor. The OCR 2024 HIPAA Security Rule NPRM is proposed, not final; state law and the Breach Notification Rule add obligations on top of the Subpart C requirements this crosswalk maps. A practice should map to the rules in force for its own systems and jurisdiction before relying on this crosswalk.

  • OCR 2024 NPRM. The proposed rule would remove much of the addressable latitude on encryption of ePHI in transit and at rest, on multifactor authentication, and on the risk-analysis cadence, making several specifications required rather than addressable. The proposal is not final, and this crosswalk maps to the Subpart C text in force.
  • Breach Notification Rule. 45 CFR Part 164 Subpart D governs notice to individuals, the Secretary, and, in larger breaches, the media. The §164.404 individual-notice timeline and the §164.408 Secretary-notice timeline sit alongside the Security Rule safeguards mapped here.
  • State law.State breach-notification statutes and state attorneys general increasingly cite Security Rule deficiencies under unfair-practice acts, and several states impose notice timelines or data-protection requirements stricter than the federal floor. A practice should map to its own state's text in addition to this crosswalk.

Disclaimers

  1. Not legal or medical advice. This document does not constitute legal or medical advice. Practice leadership and the practice's counsel make all legal and compliance determinations.
  2. Not the formal risk analysis. Tidebreak does not perform the §164.308(a)(1) formal risk analysis that the covered entity is obligated to complete. Our findings inform that risk analysis; they do not replace it.
  3. Not an attestation. Tidebreak performs assessments, not attest audits, and is not a HITRUST CSF assessor. This crosswalk is a reference mapping, not an opinion, certification, or attestation.
  4. Framework currency. Framework references are to the editions identified in this document: CIS Controls v8.1.2 (2024), NIST CSF 2.0 (2024), and the HIPAA Security Rule at 45 CFR Part 164 Subpart C as in force. The OCR 2024 HIPAA Security Rule NPRM is proposed, not final; where it would change an addressable specification to required, this crosswalk flags it. Frameworks are reviewed annually and on material changes.
  5. Distribution. This document is provided for the use of the client and its designated advisors. Further distribution, in whole or part, requires written permission.

Tidebreak performs independent assessments.