What HIPAA Security Rule sets on each scheduled job
Reads regularly and periodic; no hours in the held text. Tick HIPAA on the register and every job in these classes carries its row below. A lit cell is a figure the clause states; a row that reads no clock stays that way, because the register never fills a blank the standard left open.
The clock each rule sets
| Consumer class | Clock | Clause |
|---|---|---|
| Security monitoring and log review | ||
| Card environment log review | no clock | HIPAA 164.308(a)(1)(ii)(D) Information System Activity Review (Required) |
| Security event log review export | no clock | HIPAA 164.308(a)(1)(ii)(D) Information System Activity Review (Required) |
| Log collection and forwarding | no clock | HIPAA 164.308(a)(1)(ii)(D) Information System Activity Review (Required) |
| Backup, restore and replication | ||
| Backup restore test | no clock | HIPAA 164.308(a)(7)(ii)(D) Testing and Revision Procedures (Addressable)periodic |
| Full backup | no clock | HIPAA 164.308(a)(7)(ii)(A) Data Backup Plan (Required) |
| Incremental or differential backup | no clock | HIPAA 164.308(a)(7)(ii)(A) Data Backup Plan (Required) |
| Replication and failover sync | no clock | HIPAA 164.308(a)(7)(ii)(B) Disaster Recovery Plan (Required) |
| Incident and breach reporting | ||
| Breach notification report pack | no clock | HIPAA 164.308(a)(6)(ii) Response and Reporting (Required) |
| Incident and service report | no clock | HIPAA 164.308(a)(6)(ii) Response and Reporting (Required) |
| Incident response exercise or drill | no clock | HIPAA 164.308(a)(7)(ii)(D) Testing and Revision Procedures (Addressable)periodic |
| Access and identity reviews | ||
| User access review export | no clock | HIPAA 164.308(a)(4)(ii)(C) Access Establishment and Modification (Addressable) |
| Leaver and termination feed | no clock | HIPAA 164.308(a)(4)(ii)(C) Access Establishment and Modification (Addressable) |
| Dormant account disable | no clock | HIPAA 164.308(a)(4)(ii)(C) Access Establishment and Modification (Addressable) |
The clauses in full
Regularly review audit logs, access reports, and security incident tracking reports. NIST recommends defined review frequency, SIEM integration, anomaly detection, and documented review evidence.
What an assessor asks to see: Log review procedure; SIEM correlation rules; Sampled log review records; Anomaly investigation tickets. Where it usually falls short: Logs collected but never reviewed
Implement procedures for periodic testing and revision of contingency plans. NIST recommends annual tabletop, biennial functional, and post-incident lessons-learned updates.
What an assessor asks to see: Test schedule; Test reports; After-action reports; Plan revision history. Where it usually falls short: Plans untested for years
Establish procedures to create and maintain retrievable exact copies of ePHI. NIST recommends offline or immutable backups, encryption, and regular restoration testing.
What an assessor asks to see: Backup policy and schedule; Backup completion logs; Restoration test results; Immutable or offline backup evidence. Where it usually falls short: Backups exist but never restored
Establish procedures to restore lost data and resume operations. NIST recommends documented recovery procedures, alternate site arrangements, and aligned dependencies.
What an assessor asks to see: DR plan; Alternate site contracts; Recovery runbooks; Dependency map. Where it usually falls short: Alternate site capacity insufficient
Identify and respond to suspected or known incidents, mitigate harmful effects, and document incidents and their outcomes. NIST recommends linkage to HIPAA Breach Notification Rule timelines.
What an assessor asks to see: Incident ticket log; Post-incident reports; Breach risk assessments per 164.402; Notification records (individuals, HHS, media). Where it usually falls short: Incident closure without root cause
Implement policies that document, review, and modify a user's right of access. NIST recommends periodic recertification and just-in-time elevation for privileged tasks.
What an assessor asks to see: Quarterly access recertification reports; Modification approval records; Privileged access management logs; Manager attestations. Where it usually falls short: Recertification not performed
Requirement text quoted from the standards themselves, published at compliance.theartofservice.com, the same publisher as this register, read against the held text of each standard: our statement of each clause, not the instrument verbatim. Every regime: the index.