Authentic statutory obligations decomposed into atomic machine-actionable conditions, actions, and verification standards.
Implement policies and procedures for authorizing access to ePHI in accordance with the applicable requirements of the Privacy Rule (45 CFR § 164.308(a)(4)).
Statutory verification and compliance logging required.
{
"phi_query_auditing": true,
"minimum_necessary_filtering": true
}Implement technical security measures to guard against unauthorized access to ePHI that is being transmitted over an electronic communications network (45 CFR § 164.312(e)(1)).
Statutory verification and compliance logging required.
{
"tls_1_2_minimum": true,
"vpn_for_remote_ingress": true
}Assign a unique name and/or number for identifying and tracking user identity, and implement emergency access procedures (45 CFR § 164.312(a)(1)).
Statutory verification and compliance logging required.
{
"no_shared_accounts": true,
"break_glass_procedure": true
}Implement policies and procedures to prevent, detect, contain, and correct security violations, including an accurate risk assessment of all ePHI (45 CFR § 164.308(a)(1)).
Statutory verification and compliance logging required.
{
"sanction_policy": true,
"formal_risk_analysis": true
}Implement policies and procedures to limit physical access to electronic information systems and the facility in which they are housed (45 CFR § 164.310(a)(1)).
Statutory verification and compliance logging required.
{
"visitor_escort_policy": true,
"data_center_badge_access": true
}Implement hardware, software, and procedural mechanisms that record and examine activity in systems that contain or use ePHI (45 CFR § 164.312(b)).
Statutory verification and compliance logging required.
{
"immutable_audit_logs": true,
"read_write_delete_logged": true
}Implement policies and procedures to ensure that all members of its workforce have appropriate access to electronic protected health information (45 CFR § 164.308(a)(3)).
Statutory verification and compliance logging required.
{
"least_privilege_access": true,
"termination_offboarding_sla": true
}Covered entities must notify affected individuals and the Secretary of HHS of a breach of unsecured protected health information without unreasonable delay and in no case later than 60 days (45 CFR § 164.404).
Statutory verification and compliance logging required.
{
"60_day_max_notice": true,
"media_notice_if_500_plus": true
}