HIPAA Security Rule
HIPAA Security Rule er en føderal regel publisert som 45 CFR Part 164, Subpart C. Vedtatt 2003-02-20, gjelder fra 2005-04-20. Gjelder: Gjelder. Omfattede aktører og deres leverandører anvender sikkerhetstiltakene på elektroniske helseopplysninger.
- HIPAA Security Rule omfatter administrative safeguards, physical safeguards, technical safeguards og business associate contracts.
- HIPAA Security Rule avgjør ikke om et enkelt selskap oppfyller kravene. Det leses i selskapets egen tekst og rapportene.
- Tilsyn: U.S. Department of Health and Human Services, Office for Civil Rights. Teksten publiseres av Electronic Code of Federal Regulations og U.S. Department of Health and Human Services, Office for Civil Rights.
- Teksten peker ut helse, teknologi og forsikring.
- gdpr-2016-679: Begge tekstene krever dokumenterte sikkerhetstiltak og skriftlige vilkår med leverandører. HIPAA gjelder bare helsedata, EU-teksten ikke.
- US regulatory register
- Helse
- Teknologi
- Forsikring
- U.S. Department of Health and Human Services, Office for Civil Rights
- GDPR — Regulation (EU) 2016/679
Identitet
| Betegnelse | 45 CFR Part 164, Subpart C |
|---|---|
| Vedtatt | 2003-02-20 |
| Gjelder fra | 2005-04-20 |
| Status | Gjelder. Omfattede aktører og deres leverandører anvender sikkerhetstiltakene på elektroniske helseopplysninger. |
| Tilsyn | U.S. Department of Health and Human Services, Office for Civil Rights |
| Utpekte markedsdeler | Helse, Teknologi, Forsikring |
| Risikoområder | Informasjonssikkerhet, Personopplysninger |
Krav i teksten
- Administrative safeguards, Henvisning: 45 CFR 164.308. Risk analysis, workforce access, training and incident procedures.
- Physical safeguards, Henvisning: 45 CFR 164.310. Facility access, workstation use and media handling.
- Technical safeguards, Henvisning: 45 CFR 164.312. Access control, audit controls, integrity and transmission security.
- Business associate contracts, Henvisning: 45 CFR 164.314. Written terms with every party that handles the data on your behalf.
Offisielle kilder
- 45 CFR Part 164, Security and Privacy, Electronic Code of Federal Regulations
- HIPAA Security Rule guidance, U.S. Department of Health and Human Services, Office for Civil Rights
ExploreWorldAI is operated by Valkiv Ventures AB (Reg. no. 556995-1311), Kungsgatan 8, 111 43 Stockholm, Sweden. EU-hosted, with data processing assessed against the GDPR. Contact: hello@exploreworldai.com.
Machine-readable summaries for AI agents: /llms.txt and /llms-full.txt.