Controls
Selected HIPAA controls with passing evidence in Vanta.
59 controls with passing evidence
Infrastructure and continuity
- Passing
Device and media disposal policies implemented
The company has implemented policies and procedures to address the final disposition of electronic Protected Health Information (ePHI), and/or the hardware or electronic media on which it is stored.
- Passing
Device and media movement recorded
The company maintains a record of the movements of hardware and electronic media and any person responsible therefore.
- Passing
Media re-use procedures implemented
The company has implemented procedures for removal of electronic protected health information (ePHI) from electronic media before the media are made available for re-use.
- Passing
Media removal policies implemented
The company has implemented policies and procedures that govern the receipt and removal of hardware and electronic media that contain electronic Protected Health Information (ePHI) into and out of a facility, and the movement of these items within the facility.
- Passing
Application and data criticality analyzed
The company assesses the relative criticality of specific applications and data in support of other contingency plan components.
- Passing
Contingency operations established
The company has established (and implements as needed) procedures that allow facility access in support of restoration of lost data under the disaster recovery plan and emergency mode operations plan in the event of an emergency.
- Passing
Contingency plan established
The company has established (and implements as needed) policies and procedures for responding to an emergency or other occurrence (for example, fire, vandalism, system failure, and natural disaster) that damages systems that contain electronic Protected Health Information (ePHI).
- Passing
Contingency plan tested and revised
The company has implemented procedures for periodic testing and revision of contingency plans.
- Passing
Data backed up and stored
The company creates a retrievable, exact copy of electronic protected health information (ePHI), when needed, before the movement of equipment.
- Passing
Data backup plan implemented
The company has established and implements procedures to create and maintain retrievable exact copies of electronic protected health information (ePHI).
- Passing
Disaster recovery plan established
The company has established (and implements as needed) procedures to restore any loss of data.
- Passing
Emergency mode operation plan established
The company has established (and implements as needed) procedures to enable the continuation of critical business processes for the protection and security of electronic Protected Health Information (ePHI) while operating in emergency mode.
- Passing
Workstation security implemented
The company has implemented physical safeguards for all workstations that access electronic protected health information (ePHI), to restrict access to authorized users.
- Passing
Maintenance records maintained
The company has implemented policies and procedures to document repairs and modifications to the physical components of a facility which are related to security (for example, hardware, walls, doors, and locks).
- Passing
Access control and validation procedures implemented
The company has implemented procedures to control and validate a person's access to facilities based on their role or function, including visitor control, and control of access to software programs for testing and revision.
- Passing
Facility access controls implemented
The company has implemented policies and procedures to limit physical access to its electronic information systems and the facility or facilities in which they are housed while ensuring that properly authorized access is allowed.
- Passing
Facility security plan implemented
The company has implemented policies and procedures to safeguard the facility and the equipment therein from unauthorized physical access, tampering, and theft.
Access and product security
- Passing
Access authorized
The company has implemented policies and procedures for granting access to electronic protected health information (for example, through access to a workstation, transaction, program, process, or other mechanism).
- Passing
Access controls applied
The company implements technical policies and procedures for electronic information systems that maintain electronic protected health information (ePHI) to allow access only to those persons or software programs that have been granted access rights.
- Passing
Access established, reviewed and modified
The company has implemented policies and procedures that, based upon the entity’s access authorization policies, establish, document, review, and modify a user’s right of access to a workstation, transaction, program, or process.
- Passing
Workforce authorized and/or supervised
The company has implemented procedures for the authorization and/or supervision of workforce members who work with electronic protected health information (ePHI) or in locations where it might be accessed.
- Passing
Log-off automated
The company has implemented electronic procedures that terminate an electronic session after a predetermined time of inactivity.
- Passing
Emergency access procedures established
The company has established (and implements as needed) procedures for obtaining necessary electronic protected health information (ePHI) during an emergency.
- Passing
Termination procedures established
The company has implement procedures for terminating access to electronic protected health information (ePHI) when the employment of a workforce member ends or as required when access is no longer appropriate.
- Passing
Information access managed
The company has implemented policies and procedures for authorizing access to electronic protected health information (ePHI) that are consistent with the applicable privacy rule requirements (subpart E).
- Passing
Person or entities authenticated
The company has implemented procedures to verify that a person or entity seeking access to electronic protected health information is the one claimed.
- Passing
Unique user identified
The company assigns a unique name and/or number for identifying and tracking user identity.
- Passing
Workforce clearance procedures implemented
The company has implemented procedures to determine that the access of a workforce member to electronic protected health information (ePHI) is appropriate.
- Passing
Workforce security implemented
The company has implemented policies and procedures to ensure that all members of its workforce have appropriate access to electronic protected health information (ePHI), and to prevent those workforce members who do not have access from obtaining access to ePHI.
- Passing
Audit controls implemented
The company has implemented hardware, software, and/or procedural mechanisms that record and examine activity in information systems that contain or use electronic protected health information (ePHI).
- Passing
Data integrity maintained
The company has implemented policies and procedures to protect electronic protected health information (ePHI) from improper alteration or destruction.
Governance and risk
- Passing
HIPAA security officer
The company should identify the security official who is responsible for the development and implementation of the policies and procedures required by this subpart for the covered entity or business associate.
- Passing
Policies and procedures available
The company makes documentation available to those persons responsible for implementing the procedures to which the documentation pertains.
- Passing
Policies and procedures created
The company, as a covered entity or business associate, must, in accordance with the HIPAA security rule (§ 164.306), implement reasonable and appropriate policies and procedures to comply with implementation specifications, or other requirements, taking into account those factors specified in the HIPAA security general rules (§ 164.306(b)(2)(i), (ii), (iii), and (iv)). This standard is not to be construed to permit or excuse an action that violates any other standard, implementation specification, or other requirements (§164.316). A covered entity or business associate may change its policies and procedures at any time, provided that the changes are documented and are implemented in accordance with this subpart.
- Passing
Policies and procedures documented
The company maintains the policies and procedures implemented to comply with the HIPAA security safeguards in written (which may be electronic) form.
- Passing
Policies and procedures updated
The company reviews documentation periodically, and updates as needed, in response to environmental or operational changes affecting the security of electronic protected health information (ePHI).
- Passing
Security violations managed
The company has implemented policies and procedures to prevent, detect, contain, and correct security violations. If the company has committed to an SLA for a security violation, the corrective action is completed within that SLA.
- Passing
Security responsibility assigned
The company has identified a security official to be responsible for the development and implementation of the policies and procedures required by the HIPAA Security rules for the company.
- Passing
Workstation security policies implemented
The company has implemented policies and procedures that specify the proper functions to be performed, the manner in which those functions are to be performed, and the physical attributes of the surroundings of a specific workstation or class of workstation that can access electronic Protected Health Information (ePHI).
- Passing
Sanction policy applied
The company applies appropriate sanctions against workforce members who fail to comply with the security policies and procedures.
- Passing
Information system activity reviewed
The company has implemented procedures to regularly review records of information system activity, such as audit logs, access reports, and security incident tracking reports.
- Passing
Risks analyzed
The company has conducted an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information held in its system.
- Passing
Risks managed
The company has implemented security measures sufficient to reduce risks and vulnerabilities to a reasonable and appropriate level to comply with the HIPAA security general requirements (described in § 164.306(a)).
- Passing
Log-ins monitored
The company has implemented procedures for monitoring log-in attempts and reporting discrepancies.
- Passing
Passwords managed
The company has implemented procedures for creating, changing, and safeguarding passwords.
- Passing
Malicious software protection implemented
The company has implemented procedures for guarding against, detecting, and reporting malicious software.
- Passing
Security awareness training implemented
The company has implemented a security awareness and training program for all members of its workforce, including management.
Incident response
- Passing
Security incidents identified and reported
The company identifies and responds to suspected or known security incidents, mitigates, to the extent practicable, harmful effects of security incidents that are known to the company, and documents security incidents and their outcomes.
- Passing
Security incident procedures implemented
The company has implemented policies and procedures to address security incidents.
- Passing
Timeliness of breach notification
Except in cases of a law enforcement delay ( § 164.412), a business associate provides the breach notification required by the company Breach Notification policy ( § 164.410(a)) without unreasonable delay and in no case later than 60 calendar days after the discovery of a breach.
Data and third parties
- Passing
Data retention and time limit
The company retains the documentation of policies, procedures and action, activity or assessments as required by paragraph (b)(1) of the HIPAA rules for 6 years from the date of its creation or the date when it last was in effect, whichever is later.
- Passing
Business associate agreements required
The company requires an agreement contract or other arrangement from business associates that meets administrative safeguards (§ 164.308(b)(3)) and the requirements of the organization (§ 164.314(a)(2)(i), (a)(2)(ii), or (a)(2)(iii)) as applicable.
- Passing
Business associate agreements comply
The company requires that business associate agreements include compliance with the applicable requirements.
- Passing
Business associate security incidents reported
The company requires business associates and subcontractors to report any security incident of which it becomes aware, including breaches of unsecured protected health information as required by the Breach Notification rules (§ 164.410).
- Passing
Business associate contracts with subcontractors established
The company, as a business associate, may permit a business associate that is a subcontractor to create, receive, maintain, or transmit electronic Protected Health Information (ePHI) on its behalf only if the company can obtain satisfactory assurances, in accordance with company policies, that the subcontractor will appropriately safeguard the information.
- Passing
Business associate agreements with subcontractors obtained
The company requires that the requirements described for § 164.314(a)(2)(i) and § 164.314(a)(2)(ii) apply to the agreement contract or other arrangements between a business associate and a subcontractor in the same manner as such requirements apply to agreement contracts or other arrangements between the company and the business associate.
- Passing
Subcontractor agreements enforced
The company, in accordance with administrative safeguards (§ 164.308(b)(2)), ensures that any subcontractors that create, receive, maintain, or transmit electronic Protected Health Information (ePHI) on behalf of the business associate agree to comply with the applicable requirements by entering into an agreement contract or other arrangement that complies with organization requirements.
- Passing
Business associate contract content required
The company enters into business associate contracts that establish permitted and required uses and disclosures and obligate the business associate to safeguard PHI, report breaches, flow down terms to subcontractors, support individual rights, make records available to the Secretary, and return or destroy PHI at termination.
- Passing
Business associate management and administration uses controlled
The company, acting as a business associate, uses or discloses PHI for its own proper management and administration or legal responsibilities only as the contract permits and with required confidentiality and breach-notice assurances.