164.308(a)(1)(i) | Security Management Process (Standard) | 32 |
164.308(a)(1)(ii)(A) | Risk Analysis (Required) | 34 |
164.308(a)(1)(ii)(B) | Risk Management (Required) | 34 |
164.308(a)(1)(ii)(C) | Sanction Policy (Required) | 19 |
164.308(a)(1)(ii)(D) | Information System Activity Review (Required) | 31 |
164.308(a)(2) | Assigned Security Responsibility (Standard) | 29 |
164.308(a)(3)(i) | Workforce Security (Standard) | 27 |
164.308(a)(3)(ii)(A) | Authorization and Supervision (Addressable) | 28 |
164.308(a)(3)(ii)(B) | Workforce Clearance Procedure (Addressable) | 22 |
164.308(a)(3)(ii)(C) | Termination Procedures (Addressable) | 24 |
164.308(a)(4)(i) | Information Access Management (Standard) | 26 |
164.308(a)(4)(ii)(A) | Isolating Health Care Clearinghouse Functions (Required if applicable) | 23 |
164.308(a)(4)(ii)(B) | Access Authorization (Addressable) | 26 |
164.308(a)(4)(ii)(C) | Access Establishment and Modification (Addressable) | 25 |
164.308(a)(5)(i) | Security Awareness and Training (Standard) | 33 |
164.308(a)(5)(ii)(A) | Security Reminders (Addressable) | 23 |
164.308(a)(5)(ii)(B) | Protection from Malicious Software (Addressable) | 30 |
164.308(a)(5)(ii)(C) | Log-in Monitoring (Addressable) | 27 |
164.308(a)(5)(ii)(D) | Password Management (Addressable) | 26 |
164.308(a)(6)(i) | Security Incident Procedures (Standard) | 30 |
164.308(a)(6)(ii) | Response and Reporting (Required) | 34 |
164.308(a)(7)(i) | Contingency Plan (Standard) | 27 |
164.308(a)(7)(ii)(A) | Data Backup Plan (Required) | 25 |
164.308(a)(7)(ii)(B) | Disaster Recovery Plan (Required) | 23 |
164.308(a)(7)(ii)(C) | Emergency Mode Operation Plan (Required) | 18 |
164.308(a)(7)(ii)(D) | Testing and Revision Procedures (Addressable) | 28 |
164.308(a)(7)(ii)(E) | Applications and Data Criticality Analysis (Addressable) | 24 |
164.308(a)(8) | Evaluation (Standard) | 35 |
164.308(b)(1) | Business Associate Contracts and Other Arrangements (Standard) | 31 |
164.310(a)(1) | Facility Access Controls (Standard) | 23 |
164.310(a)(2)(i) | Contingency Operations (Addressable) | 17 |
164.310(a)(2)(ii) | Facility Security Plan (Addressable) | 20 |
164.310(a)(2)(iii) | Access Control and Validation Procedures (Addressable) | 21 |
164.310(a)(2)(iv) | Maintenance Records (Addressable) | 17 |
164.310(b) | Workstation Use (Standard) | 21 |
164.310(c) | Workstation Security (Standard) | 22 |
164.310(d)(1) | Device and Media Controls (Standard) | 23 |
164.310(d)(2)(i) | Disposal (Required) | 27 |
164.310(d)(2)(ii) | Media Re-use (Required) | 22 |
164.310(d)(2)(iii) | Accountability (Addressable) | 20 |
164.310(d)(2)(iv) | Data Backup and Storage (Addressable) | 22 |
164.312(a)(1) | Access Control (Standard) | 31 |
164.312(a)(2)(i) | Unique User Identification (Required) | 27 |
164.312(a)(2)(ii) | Emergency Access Procedure (Required) | 14 |
164.312(a)(2)(iii) | Automatic Logoff (Addressable) | 16 |
164.312(a)(2)(iv) | Encryption and Decryption (Addressable) | 23 |
164.312(b) | Audit Controls (Standard) | 27 |
164.312(c)(1) | Integrity (Standard) | 28 |
164.312(c)(2) | Mechanism to Authenticate ePHI (Addressable) | 11 |
164.312(d) | Person or Entity Authentication (Standard) | 27 |
164.312(e)(1) | Transmission Security (Standard) | 26 |
164.312(e)(2)(i) | Integrity Controls for Transmission (Addressable) | 20 |
164.312(e)(2)(ii) | Encryption of Transmissions (Addressable) | 22 |
164.316(a) | Policies and Procedures (Standard) | 30 |
164.316(b)(1) | Documentation (Standard) | 25 |
164.316(b)(2) | Time Limit, Availability, and Updates (Required) | 0 |
RA-DOC | Risk Analysis: Document the Risk Assessment Results | 0 |
RA-EPHI-LOC | Risk Analysis: Identify Where ePHI Is Created, Received, Maintained, or Transmitted | 0 |
RA-IMPACT | Risk Analysis: Determine the Impact of a Threat Exploiting a Vulnerability | 0 |
RA-LIKELIHOOD | Risk Analysis: Determine the Likelihood of a Threat Exploiting a Vulnerability | 0 |
RA-PREP | Risk Analysis: Prepare for the Assessment | 2 |
RA-RISK | Risk Analysis: Determine the Level of Risk | 2 |
RA-SCOPE | Risk Analysis: Identify Scope of the Analysis | 0 |
RA-THREATS | Risk Analysis: Identify Threats to ePHI | 2 |
RA-VULN | Risk Analysis: Identify Potential Vulnerabilities and Predisposing Conditions | 0 |