Skip to content

Evidence request lists

HIPAA Security Rule

Evidence request list. 67 controls, 67 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Administrative

164.306
Security Standards: General Rules

Covered entities and business associates must ensure the confidentiality, integrity, and availability of all electronic protected health information (ePHI) they create, receive, maintain, or transmit; protect against reasonably anticipated threats; protect against reasonably anticipated impermissible uses or disclosures; and ensure workforce compliance. Entities may use flexibility of approach considering size, complexity, capabilities, technical infrastructure, costs, and probability and criticality of risks to ePHI.

Artefacts an auditor will ask for
  • Information security program charter signed by executive leadership
  • Documented determination of covered entity vs. business associate status
  • ePHI inventory and data flow diagrams identifying creation, receipt, maintenance, transmission
  • Documented rationale for flexibility of approach decisions citing size, complexity, capabilities, costs, risk
  • Annual security program review minutes with executive sign-off
  • Statement of applicability mapping security measures to CIA triad
  • Workforce compliance attestation records
  • Risk acceptance register for residual risks
Where this commonly fails
  • No documented justification for addressable specification decisions
  • ePHI inventory incomplete or stale (missing SaaS, mobile, backup repositories)
  • Flexibility decisions not tied back to risk analysis
  • Workforce attestations expired or not collected for new hires
  • No clear demarcation of covered entity vs. business associate functions
  • Executive sign-off missing on security program documents
164.308(a)(1)(i)
Security Management Process (Standard)

Implement policies and procedures to prevent, detect, contain, and correct security violations. NIST recommends establishing an enterprise security governance program with defined roles and risk-based decision making.

Artefacts an auditor will ask for
  • Information security policy
  • Security program charter
  • Governance committee minutes
  • Risk management framework documentation
Where this commonly fails
  • No designated governance body
  • Policies exist but not approved
  • Program lacks executive sponsorship
164.308(a)(1)(ii)(A)
Risk Analysis (Required)

Conduct accurate and thorough assessment of potential risks and vulnerabilities to ePHI. NIST recommends the nine-step risk analysis methodology and integration with NIST SP 800-30 and the NIST RMF.

Artefacts an auditor will ask for
  • Documented risk analysis report
  • Risk analysis methodology aligned to NIST SP 800-30
  • Periodic refresh schedule
  • Evidence of ePHI scoping
Where this commonly fails
  • Risk analysis is checklist-style, not threat-based
  • Not refreshed after material changes
  • No integration with enterprise risk register
164.308(a)(1)(ii)(B)
Risk Management (Required)

Implement security measures sufficient to reduce risks and vulnerabilities to a reasonable and appropriate level. NIST recommends prioritized treatment plans, residual risk acceptance by leadership, and continuous monitoring tied to NIST SP 800-137.

Artefacts an auditor will ask for
  • Risk treatment plan with owners and deadlines
  • Residual risk acceptance memos
  • Continuous monitoring strategy
  • Metrics dashboard
Where this commonly fails
  • Treatment plan lacks deadlines
  • Residual risks accepted without executive sign-off
  • No continuous monitoring program
164.308(a)(1)(ii)(C)
Sanction Policy (Required)

Apply appropriate sanctions against workforce members who fail to comply with security policies. NIST recommends graduated sanctions, HR coordination, and documentation of each sanction action.

Artefacts an auditor will ask for
  • Sanction policy with graduated tiers
  • Sanction case log
  • HR acknowledgement of policy
  • Examples of sanctions applied
Where this commonly fails
  • Policy exists but never enforced
  • No record of sanctions applied
  • Inconsistent application across departments
164.308(a)(1)(ii)(D)
Information System Activity Review (Required)

Regularly review audit logs, access reports, and security incident tracking reports. NIST recommends defined review frequency, SIEM integration, anomaly detection, and documented review evidence.

Artefacts an auditor will ask for
  • Log review procedure
  • SIEM correlation rules
  • Sampled log review records
  • Anomaly investigation tickets
Where this commonly fails
  • Logs collected but never reviewed
  • No documented review cadence
  • SIEM alerts unactioned
164.308(a)(2)
Assigned Security Responsibility (Standard)

Identify the security official responsible for development and implementation of policies and procedures. NIST recommends a documented appointment, position description, and reporting line to executive leadership.

Artefacts an auditor will ask for
  • Security official appointment letter
  • Position description
  • Org chart showing reporting line
  • Authority delegation documentation
Where this commonly fails
  • Role assigned informally
  • No documented authority to enforce policy
  • Reports to IT rather than independent risk function
164.308(a)(3)(i)
Workforce Security (Standard)

Implement policies ensuring workforce members have appropriate access to ePHI and that those who should not have access are prevented from obtaining it.

Artefacts an auditor will ask for
  • Workforce security policy
  • Role-based access design
  • Position sensitivity definitions
  • Onboarding and offboarding checklists
Where this commonly fails
  • No role-based access model
  • Shared accounts widespread
  • Workforce categories undefined
164.308(a)(3)(ii)(A)
Authorization and Supervision (Addressable)

Implement procedures for authorization and supervision of workforce members who work with ePHI. NIST recommends formal approval workflows and supervisory checks for sensitive functions.

Artefacts an auditor will ask for
  • Access request and approval forms
  • Supervisor sign-off records
  • Privileged action monitoring
  • Workforce supervision policy
Where this commonly fails
  • Access granted without supervisor approval
  • Privileged users unsupervised
  • Approvals retained only in email
164.308(a)(3)(ii)(B)
Workforce Clearance Procedure (Addressable)

Determine that access to ePHI is appropriate. NIST recommends background screening proportionate to role sensitivity and documented clearance decisions.

Artefacts an auditor will ask for
  • Background check policy
  • Clearance determination records
  • Role-to-screening mapping
  • Re-screening schedule for sensitive roles
Where this commonly fails
  • Screening not aligned to role sensitivity
  • Contractors exempted
  • Re-screening not performed
164.308(a)(3)(ii)(C)
Termination Procedures (Addressable)

Implement procedures for terminating access to ePHI when employment ends or as required. NIST recommends time-bounded SLA, asset recovery, and HR-IT coordination.

Artefacts an auditor will ask for
  • Termination checklist
  • Account disablement SLA evidence
  • Asset return records
  • Termination audit log
Where this commonly fails
  • Accounts active days after termination
  • Mobile devices not recovered
  • Cloud SaaS accounts overlooked
164.308(a)(4)(i)
Information Access Management (Standard)

Implement policies authorizing access to ePHI consistent with applicable HIPAA Privacy Rule requirements. NIST recommends minimum necessary, role-based, and least-privilege access.

Artefacts an auditor will ask for
  • Access management policy
  • Role catalog
  • Minimum necessary determinations
  • Access review reports
Where this commonly fails
  • No minimum necessary analysis
  • Roles overly broad
  • Access reviews informal
164.308(a)(4)(ii)(A)
Isolating Health Care Clearinghouse Functions (Required if applicable)

If a clearinghouse is part of a larger organization, isolate ePHI from the larger organization. NIST recommends network segmentation and separate access domains.

Artefacts an auditor will ask for
  • Network segmentation design
  • Clearinghouse isolation policy
  • Access boundary documentation
  • Firewall rules separating clearinghouse
Where this commonly fails
  • Logical isolation incomplete
  • Shared administrative accounts cross boundary
  • No periodic isolation verification
164.308(a)(4)(ii)(B)
Access Authorization (Addressable)

Implement policies for granting access to ePHI via workstation, transaction, program, or process. NIST recommends formal access request workflow with approval and provisioning records.

Artefacts an auditor will ask for
  • Access request workflow tool
  • Approval records
  • Provisioning logs
  • Role assignment audit trail
Where this commonly fails
  • Manual provisioning with no audit trail
  • Approvals via informal channels
  • No reconciliation of requests to grants
164.308(a)(4)(ii)(C)
Access Establishment and Modification (Addressable)

Implement policies that document, review, and modify a user's right of access. NIST recommends periodic recertification and just-in-time elevation for privileged tasks.

Artefacts an auditor will ask for
  • Quarterly access recertification reports
  • Modification approval records
  • Privileged access management logs
  • Manager attestations
Where this commonly fails
  • Recertification not performed
  • Privileged accounts not reviewed
  • No tracking of access changes over time
164.308(a)(5)(i)
Security Awareness and Training (Standard)

Implement a security awareness and training program for all workforce members. NIST recommends role-based content, onboarding plus annual refresh, and reinforcement reminders.

Artefacts an auditor will ask for
  • Training curriculum
  • Completion records by workforce member
  • Role-based modules
  • Awareness campaigns calendar
Where this commonly fails
  • Training generic to all roles
  • Contractors not included
  • No tracking of completion
164.308(a)(5)(ii)(A)
Security Reminders (Addressable)

Issue periodic security updates and reminders. NIST recommends multiple channels including email, posters, intranet, and team meetings, refreshed quarterly minimum.

Artefacts an auditor will ask for
  • Reminder calendar
  • Email blast records
  • Awareness poster designs
  • Intranet article archive
Where this commonly fails
  • No ongoing reminders after annual training
  • Reminders not differentiated by audience
  • No measurement of effectiveness
164.308(a)(5)(ii)(B)
Protection from Malicious Software (Addressable)

Implement procedures for guarding against, detecting, and reporting malicious software. NIST recommends endpoint protection, email filtering, web filtering, and user reporting channels.

Artefacts an auditor will ask for
  • Endpoint protection deployment report
  • Email gateway configuration
  • Malware incident records
  • User reporting procedure
Where this commonly fails
  • Endpoints with disabled protection
  • No central management console
  • Servers excluded from protection
164.308(a)(5)(ii)(C)
Log-in Monitoring (Addressable)

Implement procedures for monitoring log-in attempts and reporting discrepancies. NIST recommends automated alerts on failed authentication thresholds and anomalous login patterns.

Artefacts an auditor will ask for
  • Failed login alert configuration
  • Account lockout policy
  • Anomalous login investigation records
  • Sample monitoring reports
Where this commonly fails
  • No lockout threshold defined
  • Failed logins logged but not alerted on
  • Service accounts excluded from monitoring
164.308(a)(5)(ii)(D)
Password Management (Addressable)

Implement procedures for creating, changing, and safeguarding passwords. NIST recommends aligning to SP 800-63B authenticator assurance levels and considering multi-factor authentication for ePHI access.

Artefacts an auditor will ask for
  • Password policy aligned with NIST SP 800-63B
  • MFA deployment report
  • Password manager rollout records
  • Breached password screening configuration
Where this commonly fails
  • Forced rotation without compromise indicator
  • No MFA for remote access to ePHI
  • Shared accounts with static passwords
164.308(a)(6)(i)
Security Incident Procedures (Standard)

Implement policies to address security incidents. NIST recommends an incident response plan aligned to NIST SP 800-61 with detection, analysis, containment, eradication, and recovery phases.

Artefacts an auditor will ask for
  • Incident response plan aligned to NIST SP 800-61r2
  • IR team roster
  • Tabletop exercise reports
  • Incident classification taxonomy
Where this commonly fails
  • Plan exists but not exercised
  • Roles ambiguous during real incident
  • No criteria for breach determination
164.308(a)(6)(ii)
Response and Reporting (Required)

Identify and respond to suspected or known incidents, mitigate harmful effects, and document incidents and their outcomes. NIST recommends linkage to HIPAA Breach Notification Rule timelines.

Artefacts an auditor will ask for
  • Incident ticket log
  • Post-incident reports
  • Breach risk assessments per 164.402
  • Notification records (individuals, HHS, media)
Where this commonly fails
  • Incident closure without root cause
  • Breach risk assessment not performed
  • Missed 60-day notification windows
164.308(a)(7)(i)
Contingency Plan (Standard)

Establish policies for responding to emergencies that damage ePHI systems. NIST recommends contingency planning per SP 800-34 with business impact analysis driving recovery priorities.

Artefacts an auditor will ask for
  • Contingency plan
  • Business impact analysis
  • Recovery time and point objectives
  • Plan distribution list
Where this commonly fails
  • BIA not performed
  • RTO and RPO undefined
  • Plan stored only on impacted systems
164.308(a)(7)(ii)(A)
Data Backup Plan (Required)

Establish procedures to create and maintain retrievable exact copies of ePHI. NIST recommends offline or immutable backups, encryption, and regular restoration testing.

Artefacts an auditor will ask for
  • Backup policy and schedule
  • Backup completion logs
  • Restoration test results
  • Immutable or offline backup evidence
Where this commonly fails
  • Backups exist but never restored
  • No air-gapped or immutable copy for ransomware
  • Encryption of backups not verified
164.308(a)(7)(ii)(B)
Disaster Recovery Plan (Required)

Establish procedures to restore lost data and resume operations. NIST recommends documented recovery procedures, alternate site arrangements, and aligned dependencies.

Artefacts an auditor will ask for
  • DR plan
  • Alternate site contracts
  • Recovery runbooks
  • Dependency map
Where this commonly fails
  • Alternate site capacity insufficient
  • Runbooks stale
  • Recovery dependencies (DNS, identity) unaddressed
164.308(a)(7)(ii)(C)
Emergency Mode Operation Plan (Required)

Establish procedures to enable continuation of critical processes and security of ePHI during emergency mode. NIST recommends documented manual workflows preserving access controls.

Artefacts an auditor will ask for
  • Emergency mode procedures
  • Manual workflow documentation
  • Emergency access controls
  • Audit logging during degraded mode
Where this commonly fails
  • Emergency procedures degrade access controls
  • No logging during emergency operations
  • Procedures not exercised
164.308(a)(7)(ii)(D)
Testing and Revision Procedures (Addressable)

Implement procedures for periodic testing and revision of contingency plans. NIST recommends annual tabletop, biennial functional, and post-incident lessons-learned updates.

Artefacts an auditor will ask for
  • Test schedule
  • Test reports
  • After-action reports
  • Plan revision history
Where this commonly fails
  • Plans untested for years
  • Lessons learned never folded into plan
  • Test scope too narrow
164.308(a)(7)(ii)(E)
Applications and Data Criticality Analysis (Addressable)

Assess the relative criticality of applications and data in support of other contingency components. NIST recommends tiered classification driving backup, DR, and protection investments.

Artefacts an auditor will ask for
  • Application tier list
  • Data classification register
  • Criticality-driven protection mapping
  • Annual review of tiers
Where this commonly fails
  • All systems treated equally
  • Criticality assigned by IT alone without business input
  • No refresh after acquisitions
164.308(a)(8)
Evaluation (Standard)

Perform periodic technical and nontechnical evaluation. NIST recommends combining policy review, control testing, vulnerability assessments, and audits to evaluate ongoing compliance.

Artefacts an auditor will ask for
  • Annual evaluation report
  • Internal audit reports
  • Vulnerability assessment results
  • Policy compliance reviews
Where this commonly fails
  • Evaluation skipped after major changes
  • Evaluation limited to technical scans
  • Findings unremediated
164.308(b)(1)
Business Associate Contracts and Other Arrangements (Standard)

A covered entity may permit a business associate to handle ePHI only after obtaining satisfactory assurances via written contract. NIST recommends due diligence, security questionnaires, and ongoing monitoring of BAs.

Artefacts an auditor will ask for
  • BA inventory
  • Executed BAAs
  • Vendor risk assessments
  • Ongoing monitoring records
Where this commonly fails
  • BA inventory incomplete
  • BAAs missing for cloud vendors
  • No ongoing monitoring after onboarding
164.308(b)(2)
Subcontractor Arrangements

A business associate may permit a business associate that is a subcontractor to create, receive, maintain, or transmit electronic protected health information on its behalf only if the business associate obtains satisfactory assurances, in accordance with 164.314(a), that the subcontractor will appropriately safeguard the information.

Artefacts an auditor will ask for
  • Inventory of subcontractors that create, receive, maintain or transmit electronic protected health information on the business associate's behalf
  • Executed written agreements with each subcontractor containing the satisfactory assurances required
  • Evidence the assurances obtained are equivalent to those the business associate provided to the covered entity
  • Due diligence records supporting the assurance, such as security assessments or attestations, rather than the contract alone
  • Records of action taken where a subcontractor was known to have breached the assurance, including termination or reporting
Where this commonly fails
  • Assurances obtained from the immediate subcontractor while its own downstream subcontractors handling the same data are unaddressed
  • Signed agreement treated as the whole control, with no due diligence or ongoing verification behind it
  • Cloud and support vendors that incidentally access electronic protected health information never identified as subcontractors, so no agreement exists
164.308(b)(3)
Written Contract or Other Arrangement

Document the satisfactory assurances required by paragraph (b)(1) of this section through a written contract or other arrangement with the business associate that meets the applicable requirements of 164.314(a).

Artefacts an auditor will ask for
  • Standard BAA template aligned to 164.314(a)
  • Executed BAAs stored in contract repository
  • Alternative arrangement documentation where BA is a government entity
  • Contract version history
  • Legal review records for BAA negotiations
  • Mapping of contract clauses to 164.314(a) requirements
  • Retention of BAAs for 6 years post-termination
  • Subcontractor BAAs
Where this commonly fails
  • BAAs missing required Security Rule clauses
  • Verbal or implied arrangements without writing
  • Legacy BAAs from pre-Omnibus Rule never updated
  • Government arrangement alternatives undocumented
  • BAA records not retained after termination
  • Templates not updated when Rule changes

Organizational

164.314(a)(1)
Business Associate Contracts or Other Arrangements (Standard)

The contract or other arrangement required by 164.308(b)(3) must meet the requirements of paragraph (a)(2)(i), (a)(2)(ii), or (a)(2)(iii) of this section, as applicable.

Artefacts an auditor will ask for
  • BAA template addressing all required 164.314(a)(2) elements
  • Government arrangement documentation where applicable
  • Special arrangement records (group health plan, plan sponsor)
  • Subcontractor BAAs flowing down requirements
  • Legal review records for BAAs
  • Inventory of BAAs by type (BA, subcontractor, government)
  • Procedures for negotiating BAA exceptions
  • Termination provisions evidence
Where this commonly fails
  • Older BAAs missing post-Omnibus requirements
  • Government arrangements undocumented
  • Subcontractor flow-down not verified
  • Termination obligations not exercised in practice
  • BAAs lack reporting obligations
  • Special arrangements treated as standard BAAs
164.314(a)(2)(i)
Business Associate Contract Required Provisions

The contract between a covered entity and a business associate must provide that the business associate will comply with the applicable Security Rule requirements, ensure subcontractors comply, report security incidents including breaches, and authorize termination by the covered entity if the business associate violates a material term.

Artefacts an auditor will ask for
  • BAA template with required clauses traceable to 164.314(a)(2)(i)
  • Incident reporting requirements and SLAs
  • Subcontractor flow-down clause
  • Termination for cause clause
  • BA breach notification timelines tied to 164.410
  • Periodic BAA compliance reviews
  • Records of incidents reported by BAs
  • Termination events and outcomes
Where this commonly fails
  • Incident reporting SLA missing or longer than reasonable
  • Subcontractor flow-down not enforced
  • Termination clauses never exercised
  • BA breach reports late or incomplete
  • BAA does not require Security Rule compliance explicitly
  • Compliance reviews skipped
164.314(a)(2)(ii)
Other Arrangements (Government)

When a covered entity and its business associate are both governmental entities, the requirements may be met through an MOU or other law that accomplishes the objectives of paragraph (a)(2)(i).

Artefacts an auditor will ask for
  • MOU or memorandum of agreement for government entities
  • Citation of statute or regulation accomplishing equivalent objectives
  • Mapping of MOU clauses to 164.314(a)(2)(i) elements
  • Records of incidents reported under MOU
  • Annual review of MOU adequacy
  • Legal counsel sign-off on MOU sufficiency
  • Termination or modification procedures
  • Inventory of government BAs
Where this commonly fails
  • MOU lacks required reporting obligations
  • Alternative legal mechanism not validated
  • No mapping to required elements
  • Inventory of government BAs absent
  • MOU expired or unsigned
  • Legal counsel sign-off missing
164.314(a)(2)(iii)
Business Associate Contracts with Subcontractors

The requirements of paragraph (a)(2)(i) of this section apply to the contract or other arrangement between a business associate and a subcontractor required by 164.308(b)(4) in the same manner as such requirements apply to contracts or other arrangements between a covered entity and business associate.

Artefacts an auditor will ask for
  • Subcontractor BAA template aligned to 164.314(a)(2)(i)
  • Executed subcontractor BAAs
  • Subcontractor inventory with ePHI scope
  • Records of subcontractor incident notifications
  • Subcontractor risk assessment results
  • Annual subcontractor review
  • Termination clauses for subcontractor non-compliance
  • Evidence that BA enforces same requirements on subcontractors
Where this commonly fails
  • Subcontractor inventory incomplete
  • BAA flow-down inconsistent
  • Subcontractor risk assessments absent
  • Incident notification chain to covered entity unclear
  • No periodic review of subcontractor compliance
  • Termination clauses not exercised
164.314(b)(1)
Requirements for Group Health Plans (Standard)

Except when the only ePHI disclosed to a plan sponsor is disclosed pursuant to 164.504(f)(1)(ii) or (iii), or as authorized under 164.508, a group health plan must ensure that its plan documents provide that the plan sponsor will reasonably and appropriately safeguard ePHI created, received, maintained, or transmitted to or by the plan sponsor on behalf of the group health plan.

Artefacts an auditor will ask for
  • Plan document amendments addressing ePHI safeguards
  • Plan sponsor security obligations documentation
  • Records of disclosures to plan sponsor
  • Determination of group health plan applicability
  • Procedures for limited disclosures under 164.504(f)
  • Annual review of plan sponsor compliance
  • Plan sponsor workforce training records
  • Coordination procedures between plan and sponsor
Where this commonly fails
  • Plan documents not updated to reflect ePHI safeguards
  • Plan sponsor practices not aligned to plan obligations
  • Disclosures exceed allowed scope
  • No applicability determination
  • Plan sponsor training absent
  • No annual compliance review
164.314(b)(2)
Implementation Specifications for Group Health Plans

The plan documents of the group health plan must be amended to incorporate provisions to require the plan sponsor to implement administrative, physical, and technical safeguards that reasonably and appropriately protect the ePHI; ensure that the adequate separation required by 164.504(f)(2)(iii) is supported by reasonable and appropriate security measures; ensure that any agent to whom it provides such information agrees to implement reasonable and appropriate security measures to protect the information; and report to the group health plan any security incident of which it becomes aware.

Artefacts an auditor will ask for
  • Plan document amendments containing all four required provisions
  • Plan sponsor safeguards documentation (administrative, physical, technical)
  • Adequate separation procedures and evidence
  • Plan sponsor agent agreements with security obligations
  • Incident reporting procedures from plan sponsor to plan
  • Records of reported incidents
  • Annual validation of plan sponsor compliance
  • Legal counsel review records
Where this commonly fails
  • Plan amendments missing one or more required provisions
  • Plan sponsor administrative safeguards weak
  • Adequate separation not implemented in HR or IT
  • Agent agreements lack security obligations
  • Incidents not reported to plan
  • No annual validation

Physical

164.310(a)(1)
Facility Access Controls (Standard)

Implement policies limiting physical access to electronic information systems and facilities while ensuring properly authorized access is allowed. NIST recommends layered physical security and visitor management.

Artefacts an auditor will ask for
  • Facility access policy
  • Badge system records
  • Visitor logs
  • CCTV coverage map
Where this commonly fails
  • Tailgating uncontrolled
  • Visitor logs incomplete
  • Vendor access not separately tracked
164.310(a)(2)(i)
Contingency Operations (Addressable)

Establish procedures allowing facility access in support of restoration of lost data under disaster recovery plan and emergency mode operations plan.

Artefacts an auditor will ask for
  • Emergency facility access list
  • Procedures for revoking after incident
  • Audit log of emergency entries
Where this commonly fails
  • Emergency access not reviewed
  • No audit log of who entered during incident
164.310(a)(2)(ii)
Facility Security Plan (Addressable)

Implement policies to safeguard facility and equipment from unauthorized physical access, tampering, and theft. NIST recommends documented zones, controls, and inspection regime.

Artefacts an auditor will ask for
  • Facility security plan
  • Zone diagrams
  • Inspection records
  • Tamper-evident seal program
Where this commonly fails
  • Plan not aligned to threat model
  • No periodic inspections
  • Server rooms unlocked
164.310(a)(2)(iii)
Access Control and Validation Procedures (Addressable)

Implement procedures to control and validate access to facilities based on role or function, including visitor control and access to software programs for testing and revision.

Artefacts an auditor will ask for
  • Visitor procedures
  • Role-to-zone mapping
  • Badge access reports
  • Periodic access review of physical zones
Where this commonly fails
  • All staff have facility-wide access
  • Visitor escorts not enforced
  • Physical access reviews not performed
164.310(a)(2)(iv)
Maintenance Records (Addressable)

Implement policies to document repairs and modifications to physical security components of the facility related to security (e.g., hardware, walls, doors, locks).

Artefacts an auditor will ask for
  • Maintenance log
  • Work order records
  • Vendor maintenance reports
  • Lock and key issuance log
Where this commonly fails
  • Maintenance log absent
  • Lock changes not recorded
  • Vendor work not retained
164.310(b)
Workstation Use (Standard)

Implement policies specifying proper functions, manner of performance, and physical attributes for workstations accessing ePHI. NIST recommends acceptable use policy and remote worker provisions.

Artefacts an auditor will ask for
  • Acceptable use policy
  • Remote work standard
  • Workstation configuration guide
  • Workforce acknowledgements
Where this commonly fails
  • Remote workstation expectations undocumented
  • BYOD unaddressed
  • Public area workstation use unrestricted
164.310(c)
Workstation Security (Standard)

Implement physical safeguards for workstations accessing ePHI to restrict access to authorized users. NIST recommends positioning, privacy screens, cable locks, and clear-desk policy.

Artefacts an auditor will ask for
  • Clear-desk policy
  • Workstation positioning standards
  • Privacy screen issuance log
  • Cable lock inventory
Where this commonly fails
  • Screens visible to public
  • Clear-desk policy unenforced
  • Mobile devices not secured when unattended
164.310(d)(1)
Device and Media Controls (Standard)

Implement policies governing receipt and removal of hardware and electronic media containing ePHI into, out of, and within the facility.

Artefacts an auditor will ask for
  • Media handling policy
  • Media inventory
  • Chain of custody records
  • Removable media controls
Where this commonly fails
  • Removable media unrestricted
  • No inventory of portable storage
  • Chain of custody absent
164.310(d)(2)(i)
Disposal (Required)

Implement policies to address the final disposition of ePHI and the hardware or media on which it is stored. NIST recommends sanitization per SP 800-88 with certificates of destruction.

Artefacts an auditor will ask for
  • Disposal policy aligned to NIST SP 800-88r1
  • Sanitization logs
  • Certificates of destruction
  • Disposal vendor BAA
Where this commonly fails
  • Disks sold or donated without sanitization
  • Certificates of destruction not retained
  • Cloud media deletion not requested
164.310(d)(2)(ii)
Media Re-use (Required)

Implement procedures for removal of ePHI from electronic media before the media are made available for re-use. NIST recommends purging or clearing per SP 800-88 categorization.

Artefacts an auditor will ask for
  • Re-use sanitization procedure
  • Sanitization tool records
  • Verification log
  • Reuse approval workflow
Where this commonly fails
  • Quick reformat used in lieu of secure wipe
  • SSD-specific sanitization not used
  • No verification of completion
164.310(d)(2)(iii)
Accountability (Addressable)

Maintain a record of the movements of hardware and electronic media containing ePHI and any person responsible. NIST recommends asset tagging, custody logs, and reconciliation.

Artefacts an auditor will ask for
  • Asset register
  • Custody logs for moves
  • Annual reconciliation
  • Lost asset incident records
Where this commonly fails
  • Asset register out of date
  • No custody handover on moves
  • Lost assets not tracked
164.310(d)(2)(iv)
Data Backup and Storage (Addressable)

Create a retrievable, exact copy of ePHI when needed before movement of equipment. NIST recommends pre-move backup verification and secure transport for media.

Artefacts an auditor will ask for
  • Pre-move backup checklist
  • Backup verification records
  • Secure transport procedure
  • Equipment move authorization
Where this commonly fails
  • Backups skipped due to time pressure
  • Unencrypted media transported
  • No verification before move

Policies and Procedures

164.316(a)
Policies and Procedures (Standard)

Implement reasonable and appropriate policies and procedures to comply with the Security Rule standards. NIST recommends a managed policy hierarchy with ownership, version control, and review cadence.

Artefacts an auditor will ask for
  • Policy hierarchy map
  • Policy ownership register
  • Version history
  • Annual policy review evidence
Where this commonly fails
  • Orphan policies without owners
  • Policies untouched for years
  • Local procedures conflict with corporate policy
164.316(b)(1)
Documentation (Standard)

Maintain the policies and procedures and a written or electronic record of any required action, activity, or assessment. NIST recommends document management platform with controlled retention.

Artefacts an auditor will ask for
  • Document management platform export
  • Records retention schedule
  • Evidence repository index
  • Access controls on records
Where this commonly fails
  • Records scattered across shares
  • No retention schedule
  • Records not retrievable on demand
164.316(b)(2)(i)
Time Limit (Documentation Retention)

Retain the documentation required by paragraph (b)(1) of this section for 6 years from the date of its creation or the date when it last was in effect, whichever is later.

Artefacts an auditor will ask for
  • Documentation retention schedule with 6-year minimum
  • Records management system or procedure
  • Storage and backup evidence for retained documentation
  • Disposal records at end of retention period
  • Legal hold procedures
  • Audit trail demonstrating retention compliance
  • Procedure for retired policies showing date last in effect
  • Verification samples confirming retention adherence
Where this commonly fails
  • Retention periods shorter than 6 years
  • Retention applied from creation date only, ignoring last-in-effect rule
  • Departed staff documentation lost
  • Legal holds not honored
  • Disposal undocumented
  • Backup retention misaligned
164.316(b)(2)(ii)
Availability (Documentation)

Make documentation available to those persons responsible for implementing the procedures to which the documentation pertains.

Artefacts an auditor will ask for
  • Documentation portal or repository accessible to relevant workforce
  • Access records demonstrating workforce can retrieve relevant policies
  • Communication evidence (intranet posts, training references)
  • Role-based mapping of documentation to responsibility
  • Workforce acknowledgement of access
  • Procedure for distributing updates
  • Availability metrics (page views, downloads, access requests)
  • Procedures for offline or remote workforce access
Where this commonly fails
  • Documentation locked behind admin-only access
  • Workforce unaware of where to find policies
  • Updates not communicated
  • Remote and clinical workforce lack access
  • No role-based distribution
  • Acknowledgements absent
164.316(b)(2)(iii)
Updates (Documentation)

Review documentation periodically, and update as needed, in response to environmental or operational changes affecting the security of ePHI.

Artefacts an auditor will ask for
  • Documentation review schedule (annual minimum)
  • Review records with reviewer name, date, and outcome
  • Update history triggered by environmental or operational changes (M&A, new systems, regulatory updates)
  • Version control demonstrating supersession
  • Communication of updates to workforce
  • Workforce re-acknowledgement after material updates
  • Linkage to risk analysis updates
  • Trigger inventory (events that mandate review)
Where this commonly fails
  • Documentation not reviewed annually
  • Updates triggered only by audit findings
  • Version control absent or inconsistent
  • Workforce not informed of changes
  • No linkage between risk analysis updates and policy updates
  • Change triggers undefined

Technical

164.312(a)(1)
Access Control (Standard)

Implement technical policies and procedures to allow only authorized persons or software programs access to ePHI. NIST recommends identity, authentication, authorization, and session management aligned to SP 800-53 AC family.

Artefacts an auditor will ask for
  • Identity and access management design
  • Authentication standard
  • Authorization model
  • Session management configuration
Where this commonly fails
  • Shared accounts in production
  • Session timeouts not enforced
  • Privileged access not isolated
164.312(a)(2)(i)
Unique User Identification (Required)

Assign a unique name or number for identifying and tracking user identity. NIST recommends no shared accounts and centralized identity store.

Artefacts an auditor will ask for
  • Identity directory inventory
  • Unique ID standard
  • Shared account exception register
  • Privileged account naming convention
Where this commonly fails
  • Generic admin accounts in use
  • Service accounts shared by humans
  • No central identity store
164.312(a)(2)(ii)
Emergency Access Procedure (Required)

Establish procedures for obtaining necessary ePHI during an emergency. NIST recommends break-glass accounts, time-bounded activation, and full logging.

Artefacts an auditor will ask for
  • Break-glass procedure
  • Vaulted credential evidence
  • Activation log review records
  • Post-use rotation evidence
Where this commonly fails
  • Break-glass not tested
  • Activation not logged
  • Credentials not rotated after use
164.312(a)(2)(iii)
Automatic Logoff (Addressable)

Implement electronic procedures that terminate an electronic session after a predetermined time of inactivity. NIST recommends timeouts proportionate to risk and re-authentication for sensitive functions.

Artefacts an auditor will ask for
  • Session timeout standard
  • GPO or MDM configuration evidence
  • Application-level timeout settings
  • Exception register
Where this commonly fails
  • Timeout disabled for convenience
  • Inconsistent timeouts across systems
  • Clinical workstations excluded without compensating control
164.312(a)(2)(iv)
Encryption and Decryption (Addressable)

Implement a mechanism to encrypt and decrypt ePHI. NIST recommends FIPS 140-validated cryptography, encryption at rest for all ePHI stores, and key management aligned to SP 800-57.

Artefacts an auditor will ask for
  • Encryption standard
  • FIPS 140 validation references
  • Key management procedures
  • Database, file, and endpoint encryption coverage report
Where this commonly fails
  • Legacy databases unencrypted
  • Endpoint encryption not enforced
  • Key custody undefined
164.312(b)
Audit Controls (Standard)

Implement hardware, software, and procedural mechanisms that record and examine activity in information systems that contain or use ePHI. NIST recommends central log management aligned to SP 800-92.

Artefacts an auditor will ask for
  • Logging standard
  • Central log management deployment
  • Log retention configuration
  • SIEM use case catalog
Where this commonly fails
  • Application-level audit logs missing
  • Logs retained less than six years where applicable
  • Admin actions on log system not logged separately
164.312(c)(1)
Integrity (Standard)

Implement policies and procedures to protect ePHI from improper alteration or destruction. NIST recommends integrity controls including checksums, signed records, and tamper detection.

Artefacts an auditor will ask for
  • Integrity control standard
  • Database integrity controls
  • File integrity monitoring (FIM) deployment
  • Backup integrity verification
Where this commonly fails
  • No FIM on critical ePHI stores
  • Database triggers not monitored
  • Tampering detection only via backups
164.312(c)(2)
Mechanism to Authenticate ePHI (Addressable)

Implement electronic mechanisms to corroborate that ePHI has not been altered or destroyed in an unauthorized manner. NIST recommends hash-based or signed integrity verification.

Artefacts an auditor will ask for
  • Hash or signature verification configuration
  • FIM alert investigation records
  • Audit trail of integrity events
Where this commonly fails
  • No verification process defined
  • Alerts triggered but unactioned
  • Critical data sets excluded
164.312(d)
Person or Entity Authentication (Standard)

Implement procedures to verify that a person or entity seeking access to ePHI is the one claimed. NIST recommends multi-factor authentication and authenticator assurance levels per SP 800-63B.

Artefacts an auditor will ask for
  • Authentication standard aligned to NIST SP 800-63B
  • MFA deployment report
  • Service account authentication design
  • Federation and SSO design
Where this commonly fails
  • No MFA on ePHI access
  • Weak factor combinations
  • Service-to-service authentication uses static secrets
164.312(e)(1)
Transmission Security (Standard)

Implement technical security measures to guard against unauthorized access to ePHI transmitted over an electronic communications network. NIST recommends encrypted transport, secure email, and validated VPN.

Artefacts an auditor will ask for
  • Transport encryption standard
  • TLS configuration scans
  • Secure email gateway records
  • VPN configuration evidence
Where this commonly fails
  • Legacy TLS versions enabled
  • FTP and SMTP used in clear
  • Inter-site links not encrypted
164.312(e)(2)(i)
Integrity Controls for Transmission (Addressable)

Implement security measures to ensure electronically transmitted ePHI is not improperly modified without detection until disposed of. NIST recommends authenticated TLS, signed messages, and integrity validation on receipt.

Artefacts an auditor will ask for
  • TLS with strong cipher suites
  • Message signing configuration
  • Integrity validation logs
  • Tamper alert procedure
Where this commonly fails
  • Unauthenticated TLS endpoints
  • Messages not signed
  • No receipt-side verification
164.312(e)(2)(ii)
Encryption of Transmissions (Addressable)

Implement a mechanism to encrypt ePHI whenever deemed appropriate. NIST recommends defaulting to encryption for all ePHI transmissions, with documented exception only where infeasible.

Artefacts an auditor will ask for
  • Encryption-in-transit standard
  • Coverage report for all ePHI flows
  • Exception register with compensating controls
  • Cloud provider TLS attestations
Where this commonly fails
  • Internal network treated as trusted and unencrypted
  • Fax or unsecure messaging in use without compensating control
  • No periodic scan of cipher quality
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the HIPAA Security Rule framework page.