Skip to content

Evidence request lists

NIST SP 800-66 Rev 2

Evidence request list. 65 controls, 65 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Administrative

164.308(a)(1)(i)
Security Management Process (Standard)

Implement policies and procedures to prevent, detect, contain, and correct security violations. NIST recommends establishing an enterprise security governance program with defined roles and risk-based decision making.

Artefacts an auditor will ask for
  • Information security policy
  • Security program charter
  • Governance committee minutes
  • Risk management framework documentation
Where this commonly fails
  • No designated governance body
  • Policies exist but not approved
  • Program lacks executive sponsorship
164.308(a)(1)(ii)(A)
Risk Analysis (Required)

Conduct accurate and thorough assessment of potential risks and vulnerabilities to ePHI. NIST recommends the nine-step risk analysis methodology and integration with NIST SP 800-30 and the NIST RMF.

Artefacts an auditor will ask for
  • Documented risk analysis report
  • Risk analysis methodology aligned to NIST SP 800-30
  • Periodic refresh schedule
  • Evidence of ePHI scoping
Where this commonly fails
  • Risk analysis is checklist-style, not threat-based
  • Not refreshed after material changes
  • No integration with enterprise risk register
164.308(a)(1)(ii)(B)
Risk Management (Required)

Implement security measures sufficient to reduce risks and vulnerabilities to a reasonable and appropriate level. NIST recommends prioritized treatment plans, residual risk acceptance by leadership, and continuous monitoring tied to NIST SP 800-137.

Artefacts an auditor will ask for
  • Risk treatment plan with owners and deadlines
  • Residual risk acceptance memos
  • Continuous monitoring strategy
  • Metrics dashboard
Where this commonly fails
  • Treatment plan lacks deadlines
  • Residual risks accepted without executive sign-off
  • No continuous monitoring program
164.308(a)(1)(ii)(C)
Sanction Policy (Required)

Apply appropriate sanctions against workforce members who fail to comply with security policies. NIST recommends graduated sanctions, HR coordination, and documentation of each sanction action.

Artefacts an auditor will ask for
  • Sanction policy with graduated tiers
  • Sanction case log
  • HR acknowledgement of policy
  • Examples of sanctions applied
Where this commonly fails
  • Policy exists but never enforced
  • No record of sanctions applied
  • Inconsistent application across departments
164.308(a)(1)(ii)(D)
Information System Activity Review (Required)

Regularly review audit logs, access reports, and security incident tracking reports. NIST recommends defined review frequency, SIEM integration, anomaly detection, and documented review evidence.

Artefacts an auditor will ask for
  • Log review procedure
  • SIEM correlation rules
  • Sampled log review records
  • Anomaly investigation tickets
Where this commonly fails
  • Logs collected but never reviewed
  • No documented review cadence
  • SIEM alerts unactioned
164.308(a)(2)
Assigned Security Responsibility (Standard)

Identify the security official responsible for development and implementation of policies and procedures. NIST recommends a documented appointment, position description, and reporting line to executive leadership.

Artefacts an auditor will ask for
  • Security official appointment letter
  • Position description
  • Org chart showing reporting line
  • Authority delegation documentation
Where this commonly fails
  • Role assigned informally
  • No documented authority to enforce policy
  • Reports to IT rather than independent risk function
164.308(a)(3)(i)
Workforce Security (Standard)

Implement policies ensuring workforce members have appropriate access to ePHI and that those who should not have access are prevented from obtaining it.

Artefacts an auditor will ask for
  • Workforce security policy
  • Role-based access design
  • Position sensitivity definitions
  • Onboarding and offboarding checklists
Where this commonly fails
  • No role-based access model
  • Shared accounts widespread
  • Workforce categories undefined
164.308(a)(3)(ii)(A)
Authorization and Supervision (Addressable)

Implement procedures for authorization and supervision of workforce members who work with ePHI. NIST recommends formal approval workflows and supervisory checks for sensitive functions.

Artefacts an auditor will ask for
  • Access request and approval forms
  • Supervisor sign-off records
  • Privileged action monitoring
  • Workforce supervision policy
Where this commonly fails
  • Access granted without supervisor approval
  • Privileged users unsupervised
  • Approvals retained only in email
164.308(a)(3)(ii)(B)
Workforce Clearance Procedure (Addressable)

Determine that access to ePHI is appropriate. NIST recommends background screening proportionate to role sensitivity and documented clearance decisions.

Artefacts an auditor will ask for
  • Background check policy
  • Clearance determination records
  • Role-to-screening mapping
  • Re-screening schedule for sensitive roles
Where this commonly fails
  • Screening not aligned to role sensitivity
  • Contractors exempted
  • Re-screening not performed
164.308(a)(3)(ii)(C)
Termination Procedures (Addressable)

Implement procedures for terminating access to ePHI when employment ends or as required. NIST recommends time-bounded SLA, asset recovery, and HR-IT coordination.

Artefacts an auditor will ask for
  • Termination checklist
  • Account disablement SLA evidence
  • Asset return records
  • Termination audit log
Where this commonly fails
  • Accounts active days after termination
  • Mobile devices not recovered
  • Cloud SaaS accounts overlooked
164.308(a)(4)(i)
Information Access Management (Standard)

Implement policies authorizing access to ePHI consistent with applicable HIPAA Privacy Rule requirements. NIST recommends minimum necessary, role-based, and least-privilege access.

Artefacts an auditor will ask for
  • Access management policy
  • Role catalog
  • Minimum necessary determinations
  • Access review reports
Where this commonly fails
  • No minimum necessary analysis
  • Roles overly broad
  • Access reviews informal
164.308(a)(4)(ii)(A)
Isolating Health Care Clearinghouse Functions (Required if applicable)

If a clearinghouse is part of a larger organization, isolate ePHI from the larger organization. NIST recommends network segmentation and separate access domains.

Artefacts an auditor will ask for
  • Network segmentation design
  • Clearinghouse isolation policy
  • Access boundary documentation
  • Firewall rules separating clearinghouse
Where this commonly fails
  • Logical isolation incomplete
  • Shared administrative accounts cross boundary
  • No periodic isolation verification
164.308(a)(4)(ii)(B)
Access Authorization (Addressable)

Implement policies for granting access to ePHI via workstation, transaction, program, or process. NIST recommends formal access request workflow with approval and provisioning records.

Artefacts an auditor will ask for
  • Access request workflow tool
  • Approval records
  • Provisioning logs
  • Role assignment audit trail
Where this commonly fails
  • Manual provisioning with no audit trail
  • Approvals via informal channels
  • No reconciliation of requests to grants
164.308(a)(4)(ii)(C)
Access Establishment and Modification (Addressable)

Implement policies that document, review, and modify a user's right of access. NIST recommends periodic recertification and just-in-time elevation for privileged tasks.

Artefacts an auditor will ask for
  • Quarterly access recertification reports
  • Modification approval records
  • Privileged access management logs
  • Manager attestations
Where this commonly fails
  • Recertification not performed
  • Privileged accounts not reviewed
  • No tracking of access changes over time
164.308(a)(5)(i)
Security Awareness and Training (Standard)

Implement a security awareness and training program for all workforce members. NIST recommends role-based content, onboarding plus annual refresh, and reinforcement reminders.

Artefacts an auditor will ask for
  • Training curriculum
  • Completion records by workforce member
  • Role-based modules
  • Awareness campaigns calendar
Where this commonly fails
  • Training generic to all roles
  • Contractors not included
  • No tracking of completion
164.308(a)(5)(ii)(A)
Security Reminders (Addressable)

Issue periodic security updates and reminders. NIST recommends multiple channels including email, posters, intranet, and team meetings, refreshed quarterly minimum.

Artefacts an auditor will ask for
  • Reminder calendar
  • Email blast records
  • Awareness poster designs
  • Intranet article archive
Where this commonly fails
  • No ongoing reminders after annual training
  • Reminders not differentiated by audience
  • No measurement of effectiveness
164.308(a)(5)(ii)(B)
Protection from Malicious Software (Addressable)

Implement procedures for guarding against, detecting, and reporting malicious software. NIST recommends endpoint protection, email filtering, web filtering, and user reporting channels.

Artefacts an auditor will ask for
  • Endpoint protection deployment report
  • Email gateway configuration
  • Malware incident records
  • User reporting procedure
Where this commonly fails
  • Endpoints with disabled protection
  • No central management console
  • Servers excluded from protection
164.308(a)(5)(ii)(C)
Log-in Monitoring (Addressable)

Implement procedures for monitoring log-in attempts and reporting discrepancies. NIST recommends automated alerts on failed authentication thresholds and anomalous login patterns.

Artefacts an auditor will ask for
  • Failed login alert configuration
  • Account lockout policy
  • Anomalous login investigation records
  • Sample monitoring reports
Where this commonly fails
  • No lockout threshold defined
  • Failed logins logged but not alerted on
  • Service accounts excluded from monitoring
164.308(a)(5)(ii)(D)
Password Management (Addressable)

Implement procedures for creating, changing, and safeguarding passwords. NIST recommends aligning to SP 800-63B authenticator assurance levels and considering multi-factor authentication for ePHI access.

Artefacts an auditor will ask for
  • Password policy aligned with NIST SP 800-63B
  • MFA deployment report
  • Password manager rollout records
  • Breached password screening configuration
Where this commonly fails
  • Forced rotation without compromise indicator
  • No MFA for remote access to ePHI
  • Shared accounts with static passwords
164.308(a)(6)(i)
Security Incident Procedures (Standard)

Implement policies to address security incidents. NIST recommends an incident response plan aligned to NIST SP 800-61 with detection, analysis, containment, eradication, and recovery phases.

Artefacts an auditor will ask for
  • Incident response plan aligned to NIST SP 800-61r2
  • IR team roster
  • Tabletop exercise reports
  • Incident classification taxonomy
Where this commonly fails
  • Plan exists but not exercised
  • Roles ambiguous during real incident
  • No criteria for breach determination
164.308(a)(6)(ii)
Response and Reporting (Required)

Identify and respond to suspected or known incidents, mitigate harmful effects, and document incidents and their outcomes. NIST recommends linkage to HIPAA Breach Notification Rule timelines.

Artefacts an auditor will ask for
  • Incident ticket log
  • Post-incident reports
  • Breach risk assessments per 164.402
  • Notification records (individuals, HHS, media)
Where this commonly fails
  • Incident closure without root cause
  • Breach risk assessment not performed
  • Missed 60-day notification windows
164.308(a)(7)(i)
Contingency Plan (Standard)

Establish policies for responding to emergencies that damage ePHI systems. NIST recommends contingency planning per SP 800-34 with business impact analysis driving recovery priorities.

Artefacts an auditor will ask for
  • Contingency plan
  • Business impact analysis
  • Recovery time and point objectives
  • Plan distribution list
Where this commonly fails
  • BIA not performed
  • RTO and RPO undefined
  • Plan stored only on impacted systems
164.308(a)(7)(ii)(A)
Data Backup Plan (Required)

Establish procedures to create and maintain retrievable exact copies of ePHI. NIST recommends offline or immutable backups, encryption, and regular restoration testing.

Artefacts an auditor will ask for
  • Backup policy and schedule
  • Backup completion logs
  • Restoration test results
  • Immutable or offline backup evidence
Where this commonly fails
  • Backups exist but never restored
  • No air-gapped or immutable copy for ransomware
  • Encryption of backups not verified
164.308(a)(7)(ii)(B)
Disaster Recovery Plan (Required)

Establish procedures to restore lost data and resume operations. NIST recommends documented recovery procedures, alternate site arrangements, and aligned dependencies.

Artefacts an auditor will ask for
  • DR plan
  • Alternate site contracts
  • Recovery runbooks
  • Dependency map
Where this commonly fails
  • Alternate site capacity insufficient
  • Runbooks stale
  • Recovery dependencies (DNS, identity) unaddressed
164.308(a)(7)(ii)(C)
Emergency Mode Operation Plan (Required)

Establish procedures to enable continuation of critical processes and security of ePHI during emergency mode. NIST recommends documented manual workflows preserving access controls.

Artefacts an auditor will ask for
  • Emergency mode procedures
  • Manual workflow documentation
  • Emergency access controls
  • Audit logging during degraded mode
Where this commonly fails
  • Emergency procedures degrade access controls
  • No logging during emergency operations
  • Procedures not exercised
164.308(a)(7)(ii)(D)
Testing and Revision Procedures (Addressable)

Implement procedures for periodic testing and revision of contingency plans. NIST recommends annual tabletop, biennial functional, and post-incident lessons-learned updates.

Artefacts an auditor will ask for
  • Test schedule
  • Test reports
  • After-action reports
  • Plan revision history
Where this commonly fails
  • Plans untested for years
  • Lessons learned never folded into plan
  • Test scope too narrow
164.308(a)(7)(ii)(E)
Applications and Data Criticality Analysis (Addressable)

Assess the relative criticality of applications and data in support of other contingency components. NIST recommends tiered classification driving backup, DR, and protection investments.

Artefacts an auditor will ask for
  • Application tier list
  • Data classification register
  • Criticality-driven protection mapping
  • Annual review of tiers
Where this commonly fails
  • All systems treated equally
  • Criticality assigned by IT alone without business input
  • No refresh after acquisitions
164.308(a)(8)
Evaluation (Standard)

Perform periodic technical and nontechnical evaluation. NIST recommends combining policy review, control testing, vulnerability assessments, and audits to evaluate ongoing compliance.

Artefacts an auditor will ask for
  • Annual evaluation report
  • Internal audit reports
  • Vulnerability assessment results
  • Policy compliance reviews
Where this commonly fails
  • Evaluation skipped after major changes
  • Evaluation limited to technical scans
  • Findings unremediated
RA-EPHI-LOC
Risk Analysis: Identify Where ePHI Is Created, Received, Maintained, or Transmitted

Map every system, application, device, storage location, and transmission path handling ePHI across on-premises, cloud, mobile, and third-party environments.

Artefacts an auditor will ask for
  • ePHI location register
  • System characterization documents
  • Cloud service ePHI inventory
  • Endpoint and mobile ePHI assessment
  • Email and messaging ePHI flow
Where this commonly fails
  • Backups and archives not mapped
  • Test environments containing live ePHI overlooked
  • Email attachments treated as transient and excluded
RA-IMPACT
Risk Analysis: Determine the Impact of a Threat Exploiting a Vulnerability

Determine adverse impact to ePHI confidentiality, integrity, and availability per scenario, including impact to individuals, the organization, and the nation.

Artefacts an auditor will ask for
  • Impact rating scale
  • Business impact analysis tied to ePHI loss
  • Patient harm scenarios
  • Regulatory and reputational impact estimates
Where this commonly fails
  • Impact limited to financial loss
  • Patient safety impact omitted
  • No distinction between confidentiality, integrity, availability impacts
RA-LIKELIHOOD
Risk Analysis: Determine the Likelihood of a Threat Exploiting a Vulnerability

Assess likelihood for each threat and vulnerability pairing using a defined scale, considering threat source capability, intent, and historical occurrence.

Artefacts an auditor will ask for
  • Likelihood rating rubric
  • Per-scenario likelihood determinations
  • Historical incident data feeding likelihood estimates
Where this commonly fails
  • Likelihood assigned arbitrarily without rubric
  • Same likelihood applied across all scenarios
  • No traceability to threat intelligence
RA-PREP
Risk Analysis: Prepare for the Assessment

Establish risk analysis purpose, scope, assumptions, constraints, sources of information, and risk model before commencing assessment activities for ePHI environments.

Artefacts an auditor will ask for
  • Risk analysis methodology document
  • Scope statement listing facilities and systems
  • Risk model with likelihood and impact scales
  • Information source inventory
  • Executive charter for risk program
Where this commonly fails
  • No documented methodology
  • Scope excludes business associate systems
  • Risk scales inconsistent across assessments
RA-RISK
Risk Analysis: Determine the Level of Risk

Combine likelihood and impact determinations to assign a risk level to each threat and vulnerability pairing using a defined risk matrix.

Artefacts an auditor will ask for
  • Risk register with calculated risk levels
  • Risk matrix (likelihood x impact)
  • Risk-ranked threat scenarios
  • Aggregate risk profile
Where this commonly fails
  • Risk register absent
  • Risks not ranked by severity
  • No aggregation to organizational risk posture
RA-SCOPE
Risk Analysis: Identify Scope of the Analysis

Identify all ePHI created, received, maintained, or transmitted by the regulated entity, including data flows to business associates and subcontractors.

Artefacts an auditor will ask for
  • ePHI inventory by system and location
  • Data flow diagrams
  • Business associate list with ePHI elements
  • Network topology showing ePHI zones
Where this commonly fails
  • Shadow IT systems holding ePHI not inventoried
  • Data flows to subcontractors undocumented
  • Mobile devices and removable media excluded
RA-THREATS
Risk Analysis: Identify Threats to ePHI

Catalogue reasonably anticipated threats to confidentiality, integrity, and availability of ePHI including adversarial, accidental, structural, and environmental threat sources.

Artefacts an auditor will ask for
  • Threat source catalog (NIST SP 800-30 Appendix D taxonomy)
  • Industry threat intelligence subscriptions
  • Threat event scenarios
  • HHS OCR breach trend analysis
Where this commonly fails
  • Threat catalog stale and not refreshed annually
  • Insider threats absent
  • Ransomware scenarios not modeled
RA-VULN
Risk Analysis: Identify Potential Vulnerabilities and Predisposing Conditions

Identify technical, physical, and administrative vulnerabilities and predisposing conditions that threats could exploit to compromise ePHI.

Artefacts an auditor will ask for
  • Vulnerability scan reports
  • Penetration test results
  • Configuration baseline reviews
  • Physical walkthroughs
  • Process gap analyses
Where this commonly fails
  • Only technical vulnerabilities considered
  • Predisposing conditions (geography, architecture) not documented
  • Vulnerabilities not linked to specific ePHI systems

Documentation

164.316(a)
Policies and Procedures (Standard)

Implement reasonable and appropriate policies and procedures to comply with the Security Rule standards. NIST recommends a managed policy hierarchy with ownership, version control, and review cadence.

Artefacts an auditor will ask for
  • Policy hierarchy map
  • Policy ownership register
  • Version history
  • Annual policy review evidence
Where this commonly fails
  • Orphan policies without owners
  • Policies untouched for years
  • Local procedures conflict with corporate policy
164.316(b)(1)
Documentation (Standard)

Maintain the policies and procedures and a written or electronic record of any required action, activity, or assessment. NIST recommends document management platform with controlled retention.

Artefacts an auditor will ask for
  • Document management platform export
  • Records retention schedule
  • Evidence repository index
  • Access controls on records
Where this commonly fails
  • Records scattered across shares
  • No retention schedule
  • Records not retrievable on demand
164.316(b)(2)
Time Limit, Availability, and Updates (Required)

Retain documentation for six years from creation or last effective date, make it available to those responsible for implementation, and review and update periodically as needed.

Artefacts an auditor will ask for
  • Six-year retention policy
  • Document distribution list
  • Periodic update schedule
  • Access logs for documentation
Where this commonly fails
  • Documents destroyed before six years
  • Staff cannot locate current policy version
  • Updates not communicated
RA-DOC
Risk Analysis: Document the Risk Assessment Results

Document risk analysis methodology, inputs, determinations, and results in a manner sufficient to support risk management decisions and demonstrate compliance.

Artefacts an auditor will ask for
  • Risk analysis report signed by leadership
  • Methodology appendix
  • Risk treatment recommendations
  • Six-year retention proof
Where this commonly fails
  • Verbal-only risk discussions never documented
  • Report not signed by accountable executive
  • Prior assessments destroyed before six-year retention met

Organizational

164.308(b)(1)
Business Associate Contracts and Other Arrangements (Standard)

A covered entity may permit a business associate to handle ePHI only after obtaining satisfactory assurances via written contract. NIST recommends due diligence, security questionnaires, and ongoing monitoring of BAs.

Artefacts an auditor will ask for
  • BA inventory
  • Executed BAAs
  • Vendor risk assessments
  • Ongoing monitoring records
Where this commonly fails
  • BA inventory incomplete
  • BAAs missing for cloud vendors
  • No ongoing monitoring after onboarding

Physical

164.310(a)(1)
Facility Access Controls (Standard)

Implement policies limiting physical access to electronic information systems and facilities while ensuring properly authorized access is allowed. NIST recommends layered physical security and visitor management.

Artefacts an auditor will ask for
  • Facility access policy
  • Badge system records
  • Visitor logs
  • CCTV coverage map
Where this commonly fails
  • Tailgating uncontrolled
  • Visitor logs incomplete
  • Vendor access not separately tracked
164.310(a)(2)(i)
Contingency Operations (Addressable)

Establish procedures allowing facility access in support of restoration of lost data under disaster recovery plan and emergency mode operations plan.

Artefacts an auditor will ask for
  • Emergency facility access list
  • Procedures for revoking after incident
  • Audit log of emergency entries
Where this commonly fails
  • Emergency access not reviewed
  • No audit log of who entered during incident
164.310(a)(2)(ii)
Facility Security Plan (Addressable)

Implement policies to safeguard facility and equipment from unauthorized physical access, tampering, and theft. NIST recommends documented zones, controls, and inspection regime.

Artefacts an auditor will ask for
  • Facility security plan
  • Zone diagrams
  • Inspection records
  • Tamper-evident seal program
Where this commonly fails
  • Plan not aligned to threat model
  • No periodic inspections
  • Server rooms unlocked
164.310(a)(2)(iii)
Access Control and Validation Procedures (Addressable)

Implement procedures to control and validate access to facilities based on role or function, including visitor control and access to software programs for testing and revision.

Artefacts an auditor will ask for
  • Visitor procedures
  • Role-to-zone mapping
  • Badge access reports
  • Periodic access review of physical zones
Where this commonly fails
  • All staff have facility-wide access
  • Visitor escorts not enforced
  • Physical access reviews not performed
164.310(a)(2)(iv)
Maintenance Records (Addressable)

Implement policies to document repairs and modifications to physical security components of the facility related to security (e.g., hardware, walls, doors, locks).

Artefacts an auditor will ask for
  • Maintenance log
  • Work order records
  • Vendor maintenance reports
  • Lock and key issuance log
Where this commonly fails
  • Maintenance log absent
  • Lock changes not recorded
  • Vendor work not retained
164.310(b)
Workstation Use (Standard)

Implement policies specifying proper functions, manner of performance, and physical attributes for workstations accessing ePHI. NIST recommends acceptable use policy and remote worker provisions.

Artefacts an auditor will ask for
  • Acceptable use policy
  • Remote work standard
  • Workstation configuration guide
  • Workforce acknowledgements
Where this commonly fails
  • Remote workstation expectations undocumented
  • BYOD unaddressed
  • Public area workstation use unrestricted
164.310(c)
Workstation Security (Standard)

Implement physical safeguards for workstations accessing ePHI to restrict access to authorized users. NIST recommends positioning, privacy screens, cable locks, and clear-desk policy.

Artefacts an auditor will ask for
  • Clear-desk policy
  • Workstation positioning standards
  • Privacy screen issuance log
  • Cable lock inventory
Where this commonly fails
  • Screens visible to public
  • Clear-desk policy unenforced
  • Mobile devices not secured when unattended
164.310(d)(1)
Device and Media Controls (Standard)

Implement policies governing receipt and removal of hardware and electronic media containing ePHI into, out of, and within the facility.

Artefacts an auditor will ask for
  • Media handling policy
  • Media inventory
  • Chain of custody records
  • Removable media controls
Where this commonly fails
  • Removable media unrestricted
  • No inventory of portable storage
  • Chain of custody absent
164.310(d)(2)(i)
Disposal (Required)

Implement policies to address the final disposition of ePHI and the hardware or media on which it is stored. NIST recommends sanitization per SP 800-88 with certificates of destruction.

Artefacts an auditor will ask for
  • Disposal policy aligned to NIST SP 800-88r1
  • Sanitization logs
  • Certificates of destruction
  • Disposal vendor BAA
Where this commonly fails
  • Disks sold or donated without sanitization
  • Certificates of destruction not retained
  • Cloud media deletion not requested
164.310(d)(2)(ii)
Media Re-use (Required)

Implement procedures for removal of ePHI from electronic media before the media are made available for re-use. NIST recommends purging or clearing per SP 800-88 categorization.

Artefacts an auditor will ask for
  • Re-use sanitization procedure
  • Sanitization tool records
  • Verification log
  • Reuse approval workflow
Where this commonly fails
  • Quick reformat used in lieu of secure wipe
  • SSD-specific sanitization not used
  • No verification of completion
164.310(d)(2)(iii)
Accountability (Addressable)

Maintain a record of the movements of hardware and electronic media containing ePHI and any person responsible. NIST recommends asset tagging, custody logs, and reconciliation.

Artefacts an auditor will ask for
  • Asset register
  • Custody logs for moves
  • Annual reconciliation
  • Lost asset incident records
Where this commonly fails
  • Asset register out of date
  • No custody handover on moves
  • Lost assets not tracked
164.310(d)(2)(iv)
Data Backup and Storage (Addressable)

Create a retrievable, exact copy of ePHI when needed before movement of equipment. NIST recommends pre-move backup verification and secure transport for media.

Artefacts an auditor will ask for
  • Pre-move backup checklist
  • Backup verification records
  • Secure transport procedure
  • Equipment move authorization
Where this commonly fails
  • Backups skipped due to time pressure
  • Unencrypted media transported
  • No verification before move

Technical

164.312(a)(1)
Access Control (Standard)

Implement technical policies and procedures to allow only authorized persons or software programs access to ePHI. NIST recommends identity, authentication, authorization, and session management aligned to SP 800-53 AC family.

Artefacts an auditor will ask for
  • Identity and access management design
  • Authentication standard
  • Authorization model
  • Session management configuration
Where this commonly fails
  • Shared accounts in production
  • Session timeouts not enforced
  • Privileged access not isolated
164.312(a)(2)(i)
Unique User Identification (Required)

Assign a unique name or number for identifying and tracking user identity. NIST recommends no shared accounts and centralized identity store.

Artefacts an auditor will ask for
  • Identity directory inventory
  • Unique ID standard
  • Shared account exception register
  • Privileged account naming convention
Where this commonly fails
  • Generic admin accounts in use
  • Service accounts shared by humans
  • No central identity store
164.312(a)(2)(ii)
Emergency Access Procedure (Required)

Establish procedures for obtaining necessary ePHI during an emergency. NIST recommends break-glass accounts, time-bounded activation, and full logging.

Artefacts an auditor will ask for
  • Break-glass procedure
  • Vaulted credential evidence
  • Activation log review records
  • Post-use rotation evidence
Where this commonly fails
  • Break-glass not tested
  • Activation not logged
  • Credentials not rotated after use
164.312(a)(2)(iii)
Automatic Logoff (Addressable)

Implement electronic procedures that terminate an electronic session after a predetermined time of inactivity. NIST recommends timeouts proportionate to risk and re-authentication for sensitive functions.

Artefacts an auditor will ask for
  • Session timeout standard
  • GPO or MDM configuration evidence
  • Application-level timeout settings
  • Exception register
Where this commonly fails
  • Timeout disabled for convenience
  • Inconsistent timeouts across systems
  • Clinical workstations excluded without compensating control
164.312(a)(2)(iv)
Encryption and Decryption (Addressable)

Implement a mechanism to encrypt and decrypt ePHI. NIST recommends FIPS 140-validated cryptography, encryption at rest for all ePHI stores, and key management aligned to SP 800-57.

Artefacts an auditor will ask for
  • Encryption standard
  • FIPS 140 validation references
  • Key management procedures
  • Database, file, and endpoint encryption coverage report
Where this commonly fails
  • Legacy databases unencrypted
  • Endpoint encryption not enforced
  • Key custody undefined
164.312(b)
Audit Controls (Standard)

Implement hardware, software, and procedural mechanisms that record and examine activity in information systems that contain or use ePHI. NIST recommends central log management aligned to SP 800-92.

Artefacts an auditor will ask for
  • Logging standard
  • Central log management deployment
  • Log retention configuration
  • SIEM use case catalog
Where this commonly fails
  • Application-level audit logs missing
  • Logs retained less than six years where applicable
  • Admin actions on log system not logged separately
164.312(c)(1)
Integrity (Standard)

Implement policies and procedures to protect ePHI from improper alteration or destruction. NIST recommends integrity controls including checksums, signed records, and tamper detection.

Artefacts an auditor will ask for
  • Integrity control standard
  • Database integrity controls
  • File integrity monitoring (FIM) deployment
  • Backup integrity verification
Where this commonly fails
  • No FIM on critical ePHI stores
  • Database triggers not monitored
  • Tampering detection only via backups
164.312(c)(2)
Mechanism to Authenticate ePHI (Addressable)

Implement electronic mechanisms to corroborate that ePHI has not been altered or destroyed in an unauthorized manner. NIST recommends hash-based or signed integrity verification.

Artefacts an auditor will ask for
  • Hash or signature verification configuration
  • FIM alert investigation records
  • Audit trail of integrity events
Where this commonly fails
  • No verification process defined
  • Alerts triggered but unactioned
  • Critical data sets excluded
164.312(d)
Person or Entity Authentication (Standard)

Implement procedures to verify that a person or entity seeking access to ePHI is the one claimed. NIST recommends multi-factor authentication and authenticator assurance levels per SP 800-63B.

Artefacts an auditor will ask for
  • Authentication standard aligned to NIST SP 800-63B
  • MFA deployment report
  • Service account authentication design
  • Federation and SSO design
Where this commonly fails
  • No MFA on ePHI access
  • Weak factor combinations
  • Service-to-service authentication uses static secrets
164.312(e)(1)
Transmission Security (Standard)

Implement technical security measures to guard against unauthorized access to ePHI transmitted over an electronic communications network. NIST recommends encrypted transport, secure email, and validated VPN.

Artefacts an auditor will ask for
  • Transport encryption standard
  • TLS configuration scans
  • Secure email gateway records
  • VPN configuration evidence
Where this commonly fails
  • Legacy TLS versions enabled
  • FTP and SMTP used in clear
  • Inter-site links not encrypted
164.312(e)(2)(i)
Integrity Controls for Transmission (Addressable)

Implement security measures to ensure electronically transmitted ePHI is not improperly modified without detection until disposed of. NIST recommends authenticated TLS, signed messages, and integrity validation on receipt.

Artefacts an auditor will ask for
  • TLS with strong cipher suites
  • Message signing configuration
  • Integrity validation logs
  • Tamper alert procedure
Where this commonly fails
  • Unauthenticated TLS endpoints
  • Messages not signed
  • No receipt-side verification
164.312(e)(2)(ii)
Encryption of Transmissions (Addressable)

Implement a mechanism to encrypt ePHI whenever deemed appropriate. NIST recommends defaulting to encryption for all ePHI transmissions, with documented exception only where infeasible.

Artefacts an auditor will ask for
  • Encryption-in-transit standard
  • Coverage report for all ePHI flows
  • Exception register with compensating controls
  • Cloud provider TLS attestations
Where this commonly fails
  • Internal network treated as trusted and unencrypted
  • Fax or unsecure messaging in use without compensating control
  • No periodic scan of cipher quality
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the NIST SP 800-66 Rev 2 framework page.