HIPAA Security Rule
What is HIPAA Security Rule?
Health Insurance Portability and Accountability Act security standards for protecting electronic protected health information (ePHI). It comprises 67 controls organised across 5 domains, published by U.S. Department of HHS, and applies in the United States.
How HIPAA Security Rule maps to other frameworks
All 67 controls, each one mapped to the equivalent requirement in other standards, with the evidence that carries across and the mappings that were judged and rejected shown alongside. No account needed to look.
See the control mappings →The 5 domains HIPAA Security Rule groups its controls into
Frameworks that share controls with HIPAA Security Rule
Each of these has at least one control mapped to a control in HIPAA Security Rule. The number is how many HIPAA Security Rule controls are shared, counted from the mapping graph.
Where HIPAA Security Rule overlaps with the standards you already hold
Implementation guides for frameworks that overlap HIPAA Security Rule
Step-by-step implementation of HIPAA Security Rule
More HIPAA Security Rule comparisons
Analysis of HIPAA Security Rule
Training that covers HIPAA Security Rule
Where to get trained on HIPAA Security Rule
4 courses in the catalogue cover HIPAA Security Rule directly. Each is self-paced, includes the downloadable toolkit and the implementation playbook, and carries a certificate of completion.
What HIPAA Security Rule means in your sector
What HIPAA Security Rule means for your job
Questions people ask about HIPAA Security Rule
What is HIPAA Security Rule?
How many controls does HIPAA Security Rule have?
Where does HIPAA Security Rule apply?
What frameworks does HIPAA Security Rule map to?
How do I get started with HIPAA Security Rule compliance?
Query HIPAA Security Rule programmatically
HIPAA Security Rule, its 67 controls and every mapping into other standards are available over a REST endpoint and an MCP server, so an agent can read them directly. The free tier is 10 calls a day and needs no signup.
HIPAA Security Rule API reference and MCP config →What HIPAA Security Rule requires, control by control
Each page carries the requirement text for one HIPAA Security Rule control and what an assessor expects to see as evidence.
How much of another standard HIPAA Security Rule already covers
Each crosswalk is judged control by control, and the mappings that were rejected are kept alongside the ones that held.
- ACSC Essential Eight to HIPAA Security Rule crosswalk
- ANSSI Guide d'hygiene informatique (42 mesures, v2.0) to HIPAA Security Rule crosswalk
- HIPAA Security Rule to APEC Cross-Border Privacy Rules (CBPR) System crosswalk
- APRA CPS 230 Operational Risk Management to HIPAA Security Rule crosswalk
- APRA CPS 234 to HIPAA Security Rule crosswalk
- ASD Strategies to Mitigate Cyber Security Incidents to HIPAA Security Rule crosswalk
- Australia Consumer Data Right - Banking (CDR) to HIPAA Security Rule crosswalk
- Australia My Health Records Act 2012 to HIPAA Security Rule crosswalk
How ready are you for HIPAA Security Rule?
Answer 25 questions and get a professional readiness report with gap analysis, maturity scores, and prioritised action items. Results in 5 minutes.