NIST SP 800-66 Rev 2
Evidence request list. 65 controls, 65 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Administrative
Implement policies and procedures to prevent, detect, contain, and correct security violations. NIST recommends establishing an enterprise security governance program with defined roles and risk-based decision making.
- Information security policy
- Security program charter
- Governance committee minutes
- Risk management framework documentation
- No designated governance body
- Policies exist but not approved
- Program lacks executive sponsorship
Conduct accurate and thorough assessment of potential risks and vulnerabilities to ePHI. NIST recommends the nine-step risk analysis methodology and integration with NIST SP 800-30 and the NIST RMF.
- Documented risk analysis report
- Risk analysis methodology aligned to NIST SP 800-30
- Periodic refresh schedule
- Evidence of ePHI scoping
- Risk analysis is checklist-style, not threat-based
- Not refreshed after material changes
- No integration with enterprise risk register
Implement security measures sufficient to reduce risks and vulnerabilities to a reasonable and appropriate level. NIST recommends prioritized treatment plans, residual risk acceptance by leadership, and continuous monitoring tied to NIST SP 800-137.
- Risk treatment plan with owners and deadlines
- Residual risk acceptance memos
- Continuous monitoring strategy
- Metrics dashboard
- Treatment plan lacks deadlines
- Residual risks accepted without executive sign-off
- No continuous monitoring program
Apply appropriate sanctions against workforce members who fail to comply with security policies. NIST recommends graduated sanctions, HR coordination, and documentation of each sanction action.
- Sanction policy with graduated tiers
- Sanction case log
- HR acknowledgement of policy
- Examples of sanctions applied
- Policy exists but never enforced
- No record of sanctions applied
- Inconsistent application across departments
Regularly review audit logs, access reports, and security incident tracking reports. NIST recommends defined review frequency, SIEM integration, anomaly detection, and documented review evidence.
- Log review procedure
- SIEM correlation rules
- Sampled log review records
- Anomaly investigation tickets
- Logs collected but never reviewed
- No documented review cadence
- SIEM alerts unactioned
Identify the security official responsible for development and implementation of policies and procedures. NIST recommends a documented appointment, position description, and reporting line to executive leadership.
- Security official appointment letter
- Position description
- Org chart showing reporting line
- Authority delegation documentation
- Role assigned informally
- No documented authority to enforce policy
- Reports to IT rather than independent risk function
Implement policies ensuring workforce members have appropriate access to ePHI and that those who should not have access are prevented from obtaining it.
- Workforce security policy
- Role-based access design
- Position sensitivity definitions
- Onboarding and offboarding checklists
- No role-based access model
- Shared accounts widespread
- Workforce categories undefined
Implement procedures for authorization and supervision of workforce members who work with ePHI. NIST recommends formal approval workflows and supervisory checks for sensitive functions.
- Access request and approval forms
- Supervisor sign-off records
- Privileged action monitoring
- Workforce supervision policy
- Access granted without supervisor approval
- Privileged users unsupervised
- Approvals retained only in email
Determine that access to ePHI is appropriate. NIST recommends background screening proportionate to role sensitivity and documented clearance decisions.
- Background check policy
- Clearance determination records
- Role-to-screening mapping
- Re-screening schedule for sensitive roles
- Screening not aligned to role sensitivity
- Contractors exempted
- Re-screening not performed
Implement procedures for terminating access to ePHI when employment ends or as required. NIST recommends time-bounded SLA, asset recovery, and HR-IT coordination.
- Termination checklist
- Account disablement SLA evidence
- Asset return records
- Termination audit log
- Accounts active days after termination
- Mobile devices not recovered
- Cloud SaaS accounts overlooked
Implement policies authorizing access to ePHI consistent with applicable HIPAA Privacy Rule requirements. NIST recommends minimum necessary, role-based, and least-privilege access.
- Access management policy
- Role catalog
- Minimum necessary determinations
- Access review reports
- No minimum necessary analysis
- Roles overly broad
- Access reviews informal
If a clearinghouse is part of a larger organization, isolate ePHI from the larger organization. NIST recommends network segmentation and separate access domains.
- Network segmentation design
- Clearinghouse isolation policy
- Access boundary documentation
- Firewall rules separating clearinghouse
- Logical isolation incomplete
- Shared administrative accounts cross boundary
- No periodic isolation verification
Implement policies for granting access to ePHI via workstation, transaction, program, or process. NIST recommends formal access request workflow with approval and provisioning records.
- Access request workflow tool
- Approval records
- Provisioning logs
- Role assignment audit trail
- Manual provisioning with no audit trail
- Approvals via informal channels
- No reconciliation of requests to grants
Implement policies that document, review, and modify a user's right of access. NIST recommends periodic recertification and just-in-time elevation for privileged tasks.
- Quarterly access recertification reports
- Modification approval records
- Privileged access management logs
- Manager attestations
- Recertification not performed
- Privileged accounts not reviewed
- No tracking of access changes over time
Implement a security awareness and training program for all workforce members. NIST recommends role-based content, onboarding plus annual refresh, and reinforcement reminders.
- Training curriculum
- Completion records by workforce member
- Role-based modules
- Awareness campaigns calendar
- Training generic to all roles
- Contractors not included
- No tracking of completion
Issue periodic security updates and reminders. NIST recommends multiple channels including email, posters, intranet, and team meetings, refreshed quarterly minimum.
- Reminder calendar
- Email blast records
- Awareness poster designs
- Intranet article archive
- No ongoing reminders after annual training
- Reminders not differentiated by audience
- No measurement of effectiveness
Implement procedures for guarding against, detecting, and reporting malicious software. NIST recommends endpoint protection, email filtering, web filtering, and user reporting channels.
- Endpoint protection deployment report
- Email gateway configuration
- Malware incident records
- User reporting procedure
- Endpoints with disabled protection
- No central management console
- Servers excluded from protection
Implement procedures for monitoring log-in attempts and reporting discrepancies. NIST recommends automated alerts on failed authentication thresholds and anomalous login patterns.
- Failed login alert configuration
- Account lockout policy
- Anomalous login investigation records
- Sample monitoring reports
- No lockout threshold defined
- Failed logins logged but not alerted on
- Service accounts excluded from monitoring
Implement procedures for creating, changing, and safeguarding passwords. NIST recommends aligning to SP 800-63B authenticator assurance levels and considering multi-factor authentication for ePHI access.
- Password policy aligned with NIST SP 800-63B
- MFA deployment report
- Password manager rollout records
- Breached password screening configuration
- Forced rotation without compromise indicator
- No MFA for remote access to ePHI
- Shared accounts with static passwords
Implement policies to address security incidents. NIST recommends an incident response plan aligned to NIST SP 800-61 with detection, analysis, containment, eradication, and recovery phases.
- Incident response plan aligned to NIST SP 800-61r2
- IR team roster
- Tabletop exercise reports
- Incident classification taxonomy
- Plan exists but not exercised
- Roles ambiguous during real incident
- No criteria for breach determination
Identify and respond to suspected or known incidents, mitigate harmful effects, and document incidents and their outcomes. NIST recommends linkage to HIPAA Breach Notification Rule timelines.
- Incident ticket log
- Post-incident reports
- Breach risk assessments per 164.402
- Notification records (individuals, HHS, media)
- Incident closure without root cause
- Breach risk assessment not performed
- Missed 60-day notification windows
Establish policies for responding to emergencies that damage ePHI systems. NIST recommends contingency planning per SP 800-34 with business impact analysis driving recovery priorities.
- Contingency plan
- Business impact analysis
- Recovery time and point objectives
- Plan distribution list
- BIA not performed
- RTO and RPO undefined
- Plan stored only on impacted systems
Establish procedures to create and maintain retrievable exact copies of ePHI. NIST recommends offline or immutable backups, encryption, and regular restoration testing.
- Backup policy and schedule
- Backup completion logs
- Restoration test results
- Immutable or offline backup evidence
- Backups exist but never restored
- No air-gapped or immutable copy for ransomware
- Encryption of backups not verified
Establish procedures to restore lost data and resume operations. NIST recommends documented recovery procedures, alternate site arrangements, and aligned dependencies.
- DR plan
- Alternate site contracts
- Recovery runbooks
- Dependency map
- Alternate site capacity insufficient
- Runbooks stale
- Recovery dependencies (DNS, identity) unaddressed
Establish procedures to enable continuation of critical processes and security of ePHI during emergency mode. NIST recommends documented manual workflows preserving access controls.
- Emergency mode procedures
- Manual workflow documentation
- Emergency access controls
- Audit logging during degraded mode
- Emergency procedures degrade access controls
- No logging during emergency operations
- Procedures not exercised
Implement procedures for periodic testing and revision of contingency plans. NIST recommends annual tabletop, biennial functional, and post-incident lessons-learned updates.
- Test schedule
- Test reports
- After-action reports
- Plan revision history
- Plans untested for years
- Lessons learned never folded into plan
- Test scope too narrow
Assess the relative criticality of applications and data in support of other contingency components. NIST recommends tiered classification driving backup, DR, and protection investments.
- Application tier list
- Data classification register
- Criticality-driven protection mapping
- Annual review of tiers
- All systems treated equally
- Criticality assigned by IT alone without business input
- No refresh after acquisitions
Perform periodic technical and nontechnical evaluation. NIST recommends combining policy review, control testing, vulnerability assessments, and audits to evaluate ongoing compliance.
- Annual evaluation report
- Internal audit reports
- Vulnerability assessment results
- Policy compliance reviews
- Evaluation skipped after major changes
- Evaluation limited to technical scans
- Findings unremediated
Map every system, application, device, storage location, and transmission path handling ePHI across on-premises, cloud, mobile, and third-party environments.
- ePHI location register
- System characterization documents
- Cloud service ePHI inventory
- Endpoint and mobile ePHI assessment
- Email and messaging ePHI flow
- Backups and archives not mapped
- Test environments containing live ePHI overlooked
- Email attachments treated as transient and excluded
Determine adverse impact to ePHI confidentiality, integrity, and availability per scenario, including impact to individuals, the organization, and the nation.
- Impact rating scale
- Business impact analysis tied to ePHI loss
- Patient harm scenarios
- Regulatory and reputational impact estimates
- Impact limited to financial loss
- Patient safety impact omitted
- No distinction between confidentiality, integrity, availability impacts
Assess likelihood for each threat and vulnerability pairing using a defined scale, considering threat source capability, intent, and historical occurrence.
- Likelihood rating rubric
- Per-scenario likelihood determinations
- Historical incident data feeding likelihood estimates
- Likelihood assigned arbitrarily without rubric
- Same likelihood applied across all scenarios
- No traceability to threat intelligence
Establish risk analysis purpose, scope, assumptions, constraints, sources of information, and risk model before commencing assessment activities for ePHI environments.
- Risk analysis methodology document
- Scope statement listing facilities and systems
- Risk model with likelihood and impact scales
- Information source inventory
- Executive charter for risk program
- No documented methodology
- Scope excludes business associate systems
- Risk scales inconsistent across assessments
Combine likelihood and impact determinations to assign a risk level to each threat and vulnerability pairing using a defined risk matrix.
- Risk register with calculated risk levels
- Risk matrix (likelihood x impact)
- Risk-ranked threat scenarios
- Aggregate risk profile
- Risk register absent
- Risks not ranked by severity
- No aggregation to organizational risk posture
Identify all ePHI created, received, maintained, or transmitted by the regulated entity, including data flows to business associates and subcontractors.
- ePHI inventory by system and location
- Data flow diagrams
- Business associate list with ePHI elements
- Network topology showing ePHI zones
- Shadow IT systems holding ePHI not inventoried
- Data flows to subcontractors undocumented
- Mobile devices and removable media excluded
Catalogue reasonably anticipated threats to confidentiality, integrity, and availability of ePHI including adversarial, accidental, structural, and environmental threat sources.
- Threat source catalog (NIST SP 800-30 Appendix D taxonomy)
- Industry threat intelligence subscriptions
- Threat event scenarios
- HHS OCR breach trend analysis
- Threat catalog stale and not refreshed annually
- Insider threats absent
- Ransomware scenarios not modeled
Identify technical, physical, and administrative vulnerabilities and predisposing conditions that threats could exploit to compromise ePHI.
- Vulnerability scan reports
- Penetration test results
- Configuration baseline reviews
- Physical walkthroughs
- Process gap analyses
- Only technical vulnerabilities considered
- Predisposing conditions (geography, architecture) not documented
- Vulnerabilities not linked to specific ePHI systems
Documentation
Implement reasonable and appropriate policies and procedures to comply with the Security Rule standards. NIST recommends a managed policy hierarchy with ownership, version control, and review cadence.
- Policy hierarchy map
- Policy ownership register
- Version history
- Annual policy review evidence
- Orphan policies without owners
- Policies untouched for years
- Local procedures conflict with corporate policy
Maintain the policies and procedures and a written or electronic record of any required action, activity, or assessment. NIST recommends document management platform with controlled retention.
- Document management platform export
- Records retention schedule
- Evidence repository index
- Access controls on records
- Records scattered across shares
- No retention schedule
- Records not retrievable on demand
Retain documentation for six years from creation or last effective date, make it available to those responsible for implementation, and review and update periodically as needed.
- Six-year retention policy
- Document distribution list
- Periodic update schedule
- Access logs for documentation
- Documents destroyed before six years
- Staff cannot locate current policy version
- Updates not communicated
Document risk analysis methodology, inputs, determinations, and results in a manner sufficient to support risk management decisions and demonstrate compliance.
- Risk analysis report signed by leadership
- Methodology appendix
- Risk treatment recommendations
- Six-year retention proof
- Verbal-only risk discussions never documented
- Report not signed by accountable executive
- Prior assessments destroyed before six-year retention met
Organizational
A covered entity may permit a business associate to handle ePHI only after obtaining satisfactory assurances via written contract. NIST recommends due diligence, security questionnaires, and ongoing monitoring of BAs.
- BA inventory
- Executed BAAs
- Vendor risk assessments
- Ongoing monitoring records
- BA inventory incomplete
- BAAs missing for cloud vendors
- No ongoing monitoring after onboarding
Physical
Implement policies limiting physical access to electronic information systems and facilities while ensuring properly authorized access is allowed. NIST recommends layered physical security and visitor management.
- Facility access policy
- Badge system records
- Visitor logs
- CCTV coverage map
- Tailgating uncontrolled
- Visitor logs incomplete
- Vendor access not separately tracked
Establish procedures allowing facility access in support of restoration of lost data under disaster recovery plan and emergency mode operations plan.
- Emergency facility access list
- Procedures for revoking after incident
- Audit log of emergency entries
- Emergency access not reviewed
- No audit log of who entered during incident
Implement policies to safeguard facility and equipment from unauthorized physical access, tampering, and theft. NIST recommends documented zones, controls, and inspection regime.
- Facility security plan
- Zone diagrams
- Inspection records
- Tamper-evident seal program
- Plan not aligned to threat model
- No periodic inspections
- Server rooms unlocked
Implement procedures to control and validate access to facilities based on role or function, including visitor control and access to software programs for testing and revision.
- Visitor procedures
- Role-to-zone mapping
- Badge access reports
- Periodic access review of physical zones
- All staff have facility-wide access
- Visitor escorts not enforced
- Physical access reviews not performed
Implement policies to document repairs and modifications to physical security components of the facility related to security (e.g., hardware, walls, doors, locks).
- Maintenance log
- Work order records
- Vendor maintenance reports
- Lock and key issuance log
- Maintenance log absent
- Lock changes not recorded
- Vendor work not retained
Implement policies specifying proper functions, manner of performance, and physical attributes for workstations accessing ePHI. NIST recommends acceptable use policy and remote worker provisions.
- Acceptable use policy
- Remote work standard
- Workstation configuration guide
- Workforce acknowledgements
- Remote workstation expectations undocumented
- BYOD unaddressed
- Public area workstation use unrestricted
Implement physical safeguards for workstations accessing ePHI to restrict access to authorized users. NIST recommends positioning, privacy screens, cable locks, and clear-desk policy.
- Clear-desk policy
- Workstation positioning standards
- Privacy screen issuance log
- Cable lock inventory
- Screens visible to public
- Clear-desk policy unenforced
- Mobile devices not secured when unattended
Implement policies governing receipt and removal of hardware and electronic media containing ePHI into, out of, and within the facility.
- Media handling policy
- Media inventory
- Chain of custody records
- Removable media controls
- Removable media unrestricted
- No inventory of portable storage
- Chain of custody absent
Implement policies to address the final disposition of ePHI and the hardware or media on which it is stored. NIST recommends sanitization per SP 800-88 with certificates of destruction.
- Disposal policy aligned to NIST SP 800-88r1
- Sanitization logs
- Certificates of destruction
- Disposal vendor BAA
- Disks sold or donated without sanitization
- Certificates of destruction not retained
- Cloud media deletion not requested
Implement procedures for removal of ePHI from electronic media before the media are made available for re-use. NIST recommends purging or clearing per SP 800-88 categorization.
- Re-use sanitization procedure
- Sanitization tool records
- Verification log
- Reuse approval workflow
- Quick reformat used in lieu of secure wipe
- SSD-specific sanitization not used
- No verification of completion
Maintain a record of the movements of hardware and electronic media containing ePHI and any person responsible. NIST recommends asset tagging, custody logs, and reconciliation.
- Asset register
- Custody logs for moves
- Annual reconciliation
- Lost asset incident records
- Asset register out of date
- No custody handover on moves
- Lost assets not tracked
Create a retrievable, exact copy of ePHI when needed before movement of equipment. NIST recommends pre-move backup verification and secure transport for media.
- Pre-move backup checklist
- Backup verification records
- Secure transport procedure
- Equipment move authorization
- Backups skipped due to time pressure
- Unencrypted media transported
- No verification before move
Technical
Implement technical policies and procedures to allow only authorized persons or software programs access to ePHI. NIST recommends identity, authentication, authorization, and session management aligned to SP 800-53 AC family.
- Identity and access management design
- Authentication standard
- Authorization model
- Session management configuration
- Shared accounts in production
- Session timeouts not enforced
- Privileged access not isolated
Assign a unique name or number for identifying and tracking user identity. NIST recommends no shared accounts and centralized identity store.
- Identity directory inventory
- Unique ID standard
- Shared account exception register
- Privileged account naming convention
- Generic admin accounts in use
- Service accounts shared by humans
- No central identity store
Establish procedures for obtaining necessary ePHI during an emergency. NIST recommends break-glass accounts, time-bounded activation, and full logging.
- Break-glass procedure
- Vaulted credential evidence
- Activation log review records
- Post-use rotation evidence
- Break-glass not tested
- Activation not logged
- Credentials not rotated after use
Implement electronic procedures that terminate an electronic session after a predetermined time of inactivity. NIST recommends timeouts proportionate to risk and re-authentication for sensitive functions.
- Session timeout standard
- GPO or MDM configuration evidence
- Application-level timeout settings
- Exception register
- Timeout disabled for convenience
- Inconsistent timeouts across systems
- Clinical workstations excluded without compensating control
Implement a mechanism to encrypt and decrypt ePHI. NIST recommends FIPS 140-validated cryptography, encryption at rest for all ePHI stores, and key management aligned to SP 800-57.
- Encryption standard
- FIPS 140 validation references
- Key management procedures
- Database, file, and endpoint encryption coverage report
- Legacy databases unencrypted
- Endpoint encryption not enforced
- Key custody undefined
Implement hardware, software, and procedural mechanisms that record and examine activity in information systems that contain or use ePHI. NIST recommends central log management aligned to SP 800-92.
- Logging standard
- Central log management deployment
- Log retention configuration
- SIEM use case catalog
- Application-level audit logs missing
- Logs retained less than six years where applicable
- Admin actions on log system not logged separately
Implement policies and procedures to protect ePHI from improper alteration or destruction. NIST recommends integrity controls including checksums, signed records, and tamper detection.
- Integrity control standard
- Database integrity controls
- File integrity monitoring (FIM) deployment
- Backup integrity verification
- No FIM on critical ePHI stores
- Database triggers not monitored
- Tampering detection only via backups
Implement electronic mechanisms to corroborate that ePHI has not been altered or destroyed in an unauthorized manner. NIST recommends hash-based or signed integrity verification.
- Hash or signature verification configuration
- FIM alert investigation records
- Audit trail of integrity events
- No verification process defined
- Alerts triggered but unactioned
- Critical data sets excluded
Implement procedures to verify that a person or entity seeking access to ePHI is the one claimed. NIST recommends multi-factor authentication and authenticator assurance levels per SP 800-63B.
- Authentication standard aligned to NIST SP 800-63B
- MFA deployment report
- Service account authentication design
- Federation and SSO design
- No MFA on ePHI access
- Weak factor combinations
- Service-to-service authentication uses static secrets
Implement technical security measures to guard against unauthorized access to ePHI transmitted over an electronic communications network. NIST recommends encrypted transport, secure email, and validated VPN.
- Transport encryption standard
- TLS configuration scans
- Secure email gateway records
- VPN configuration evidence
- Legacy TLS versions enabled
- FTP and SMTP used in clear
- Inter-site links not encrypted
Implement security measures to ensure electronically transmitted ePHI is not improperly modified without detection until disposed of. NIST recommends authenticated TLS, signed messages, and integrity validation on receipt.
- TLS with strong cipher suites
- Message signing configuration
- Integrity validation logs
- Tamper alert procedure
- Unauthenticated TLS endpoints
- Messages not signed
- No receipt-side verification
Implement a mechanism to encrypt ePHI whenever deemed appropriate. NIST recommends defaulting to encryption for all ePHI transmissions, with documented exception only where infeasible.
- Encryption-in-transit standard
- Coverage report for all ePHI flows
- Exception register with compensating controls
- Cloud provider TLS attestations
- Internal network treated as trusted and unencrypted
- Fax or unsecure messaging in use without compensating control
- No periodic scan of cipher quality
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the NIST SP 800-66 Rev 2 framework page.