Terminology Index
Glossary
2953 terms
HIPAA Security Rule
The part of HIPAA that sets required safeguards, administrative, physical, and technical, for protecting electronic protected health information, mapped to controls when implementing HIPAA in a framework context.
The HIPAA Security Rule specifies how electronic PHI must be protected, organized into administrative safeguards (policies, training, risk analysis), physical safeguards (facility and device controls), and technical safeguards (access control, encryption, audit, integrity). In framework and control-mapping work, its requirements are mapped to concrete controls and to other frameworks, so an organization can implement and evidence them efficiently alongside standards like ISO 27001 or HITRUST.
Introduced in: Security Frameworks and Control Mapping
Examples
- Implementing technical safeguards like access control and encryption for ePHI.
- Conducting the risk analysis the Security Rule's administrative safeguards require.
- Mapping Security Rule requirements to existing framework controls.
