HIPAA Security Rule
6 of the 67 clauses of HIPAA Security Rule are cited by this register, on Backup restore test, Breach notification report pack, Card environment log review, Dormant account disable, Full backup, Incident and service report, Incident response exercise or drill, Incremental or differential backup and more. Every one below is quoted from the copy we hold, with the hours it states where it states any.
Regularly review audit logs, access reports, and security incident tracking reports. NIST recommends defined review frequency, SIEM integration, anomaly detection, and documented review evidence.
What an assessor asks to see: Log review procedure; SIEM correlation rules; Sampled log review records; Anomaly investigation tickets. Where it usually falls short: Logs collected but never reviewed
Implement policies that document, review, and modify a user's right of access. NIST recommends periodic recertification and just-in-time elevation for privileged tasks.
What an assessor asks to see: Quarterly access recertification reports; Modification approval records; Privileged access management logs; Manager attestations. Where it usually falls short: Recertification not performed
Identify and respond to suspected or known incidents, mitigate harmful effects, and document incidents and their outcomes. NIST recommends linkage to HIPAA Breach Notification Rule timelines.
What an assessor asks to see: Incident ticket log; Post-incident reports; Breach risk assessments per 164.402; Notification records (individuals, HHS, media). Where it usually falls short: Incident closure without root cause
Establish procedures to create and maintain retrievable exact copies of ePHI. NIST recommends offline or immutable backups, encryption, and regular restoration testing.
What an assessor asks to see: Backup policy and schedule; Backup completion logs; Restoration test results; Immutable or offline backup evidence. Where it usually falls short: Backups exist but never restored
Establish procedures to restore lost data and resume operations. NIST recommends documented recovery procedures, alternate site arrangements, and aligned dependencies.
What an assessor asks to see: DR plan; Alternate site contracts; Recovery runbooks; Dependency map. Where it usually falls short: Alternate site capacity insufficient
Implement procedures for periodic testing and revision of contingency plans. NIST recommends annual tabletop, biennial functional, and post-incident lessons-learned updates.
What an assessor asks to see: Test schedule; Test reports; After-action reports; Plan revision history. Where it usually falls short: Plans untested for years
Requirement text quoted from the standards themselves, published at compliance.theartofservice.com, the same publisher as this register, read against the held text of each standard: our statement of each clause, not the instrument verbatim. The whole standard on compliance.theartofservice.com.