Compliance, Mapped to Your Cloud

Assess your AWS, Azure, and Google Cloud environments against the industry frameworks and regulations your auditors expect.

56
Frameworks Supported
18
Standards Families
3
Cloud Providers
5 min
To First Results
ASecureCloud compliance report preview
Google Cloud logo

HIPAA

9 controls
30 checks mapped

HIPAA safeguards the confidentiality, integrity, and availability of electronic protected health information (ePHI) handled by covered entities and business associates.

Controls assessed

164.308(a)(1)(ii) - Implementation specifications2

Conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information held by the covered entity or business associate. Implement security measures sufficient to reduce risks and vulnerabilities to a reasonable and appropriate level to comply with § 164.306(a). Apply appropriate sanctions against workforce members who fail to comply with the security policies and procedures of the covered entity or business associate. Implement procedures to regularly review records of information system activity, such as audit logs, access reports, and security incident tracking reports.

164.308(a)(3)(i) - Workforce security12

Implement policies and procedures to ensure that all members of its workforce have appropriate access to electronic protected health information, as provided under paragraph (a)(4) of this section, and to prevent those workforce members who do not have access under paragraph (a)(4) of this section from obtaining access to electronic protected health information.

164.308(a)(3)(ii) - Implementation specifications12

Implement procedures for the authorization and/or supervision of workforce members who work with electronic protected health information or in locations where it might be accessed. Implement procedures to determine that a workforce member's access to electronic protected health information is appropriate. Implement procedures for terminating access to electronic protected health information when the employment of, or other arrangement with, a workforce member ends or as required by determinations made as specified in paragraph (a)(3)(ii)(B) of this section.

164.308(a)(7)(ii) - Implementation specifications1

Establish and implement procedures to create and maintain retrievable exact copies of electronic protected health information. Establish and implement procedures to restore any loss of data. Establish and implement procedures to enable the continuation of critical business processes for protecting the security of electronic protected health information while operating in emergency mode. Implement procedures for periodic testing and revision of contingency plans. Assess the relative criticality of specific applications and data to support other contingency plan components.

164.310(d)(2)(iii) - Media re-use1

Implement procedures for removal of electronic protected health information from electronic media before the media are made available for re-use.

164.312(a)(1) - Access control.12

Implement technical policies and procedures for electronic information systems that maintain electronic protected health information to allow access only to those persons or software programs that have been granted access rights as specified in § 164.308(a)(4).

164.312(a)(2)(iv) - Encryption and decryption5

Implement a mechanism to encrypt and decrypt electronic protected health information.

164.312(b) - Audit controls12

Implement hardware, software, and/or procedural mechanisms that record and examine activity in information systems that contain or use electronic protected health information.

164.312(e)(2)(ii) - Encryption5

Implement a mechanism to encrypt electronic protected health information whenever deemed appropriate.

See where you stand against any framework

Connect an account and get a full compliance breakdown with mapped findings and remediation guidance — free to start.