HIPAA Security Rule
HIPAA Security Rule är en federal regel publicerad som 45 CFR Part 164, Subpart C. Antagen 2003-02-20, tillämpas från 2005-04-20. Gäller: Gäller. Omfattade aktörer och deras leverantörer tillämpar skyddsåtgärderna på elektroniska hälsouppgifter.
- HIPAA Security Rule omfattar administrative safeguards, physical safeguards, technical safeguards och business associate contracts.
- HIPAA Security Rule avgör inte om ett enskilt bolag lever upp till kraven. Det läses i bolagets egen text och dess rapporter.
- Tillsyn: U.S. Department of Health and Human Services, Office for Civil Rights. Texten publiceras av Electronic Code of Federal Regulations och U.S. Department of Health and Human Services, Office for Civil Rights.
- Texten pekar ut vård och hälsa, teknik och försäkring.
- gdpr-2016-679: Båda texterna kräver dokumenterade säkerhetsåtgärder och skriftliga villkor med leverantörer. HIPAA gäller bara hälsodata, EU-texten inte.
- US regulatory register
- Vård och hälsa
- Teknik
- Försäkring
- U.S. Department of Health and Human Services, Office for Civil Rights
- GDPR — Regulation (EU) 2016/679
Identitet
| Beteckning | 45 CFR Part 164, Subpart C |
|---|---|
| Antagen | 2003-02-20 |
| Tillämpas från | 2005-04-20 |
| Status | Gäller. Omfattade aktörer och deras leverantörer tillämpar skyddsåtgärderna på elektroniska hälsouppgifter. |
| Tillsyn | U.S. Department of Health and Human Services, Office for Civil Rights |
| Utpekade marknadsdelar | Vård och hälsa, Teknik, Försäkring |
| Riskområden | Informationssäkerhet, Personuppgifter |
Krav i texten
- Administrative safeguards, Hänvisning: 45 CFR 164.308. Risk analysis, workforce access, training and incident procedures.
- Physical safeguards, Hänvisning: 45 CFR 164.310. Facility access, workstation use and media handling.
- Technical safeguards, Hänvisning: 45 CFR 164.312. Access control, audit controls, integrity and transmission security.
- Business associate contracts, Hänvisning: 45 CFR 164.314. Written terms with every party that handles the data on your behalf.
Officiella källor
- 45 CFR Part 164, Security and Privacy, Electronic Code of Federal Regulations
- HIPAA Security Rule guidance, U.S. Department of Health and Human Services, Office for Civil Rights
ExploreWorldAI is operated by Valkiv Ventures AB (Reg. no. 556995-1311), Kungsgatan 8, 111 43 Stockholm, Sweden. EU-hosted, with data processing assessed against the GDPR. Contact: hello@exploreworldai.com.
Machine-readable summaries for AI agents: /llms.txt and /llms-full.txt.