HIPAA Security Requirements

Required and Addressable Security Requirements

The Mandatory Required Security Elements include

  1. Ensure CIA of ePHI (Required)
  2. Risk Analysis (Required)
  3. Risk Management (Required)
  4. Sanction Policy (Required)
  5. Information System Activity Review (Required)
  6. Assign a Security Official (Required)
  7. Isolating Healthcare Clearinghouse Functions (Required)
  8. Response and Reporting (Required)
  9. Data Backup Plan (Required)
  10. Written Contract or Other Arrangement (Required)
  11. Emergency Mode Operation Plan (Required).
  12. Disaster Recovery Plan (Required)
  13. Reasonable Protection Against Threats. (Required)
  14. Reasonable Protection Against Disclosure. (Required)
  15. Ensure compliance by workforce (Required)
  16. Flexibility of Approach (Required)
  17. Standards (Required)
  18. Implementation Specifications (Required)
  19. Required or Addressable (Required)
  20. Required Standards (Required)
  21. Assess Applicability for Addressable (Required)
  22. Implement if reasonable and appropriate (Required)
  23. If not reasonable and appropriate: (Required)
  24. Document why not and rationale (Required)
  25. Implement an equivalent alternative (Required)
  26. Maintenance – (Required)

Desired or Addressable Elements Include:

  1. Testing and Revision Procedures (Addressable)
  2. Applications and Data Criticality Analysis (Addressable)
  3. Contingency Operations (Addressable)
  4. Facility Security Plan (Addressable)
  5. Access Control and Validation (Addressable)
  6. Maintenance Records (Addressable)
  7. Authorization and/or Supervision (Addressable)
  8. Workforce Clearance Procedures (Addressable)
  9. Termination Procedures (Addressable)
  10. Access Authorization (Addressable)
  11. Access Establishment and Modification (Addressable)
  12. Security Reminders (Addressable)
  13. Protection from Malicious Software (Addressable)
  14. Log-In Monitoring (Addressable)
  15. Password Management (Addressable)