{
  "code": "HIPAA",
  "name": "Health Insurance Portability and Accountability Act (HIPAA)",
  "version": "2013",
  "issuing_body": "U.S. Department of Health & Human Services",
  "description": "Federal law that required the creation of national standards to protect sensitive patient health information",
  "regions": ["us"],
  "industries": ["Healthcare"],
  "effective_date": "2013-03-26",
  "is_global": false,
  "requirements": [
    {
      "reference_code": "164.308",
      "title": "Administrative Safeguards",
      "requirement_type": "mandatory",
      "category": "Security Rule - Administrative",
      "children": [
        { "reference_code": "164.308(a)(1)", "title": "Security Management Process", "description": "Implement policies and procedures to prevent, detect, contain, and correct security violations.", "requirement_type": "mandatory",
          "children": [
            { "reference_code": "164.308(a)(1)(ii)(A)", "title": "Risk Analysis", "description": "Conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI.", "requirement_type": "mandatory" },
            { "reference_code": "164.308(a)(1)(ii)(B)", "title": "Risk Management", "description": "Implement security measures sufficient to reduce risks and vulnerabilities to a reasonable and appropriate level.", "requirement_type": "mandatory" },
            { "reference_code": "164.308(a)(1)(ii)(C)", "title": "Sanction Policy", "description": "Apply appropriate sanctions against workforce members who fail to comply with security policies.", "requirement_type": "mandatory" },
            { "reference_code": "164.308(a)(1)(ii)(D)", "title": "Information System Activity Review", "description": "Implement procedures to regularly review records of information system activity.", "requirement_type": "mandatory" }
          ]
        },
        { "reference_code": "164.308(a)(2)", "title": "Assigned Security Responsibility", "description": "Identify the security official responsible for development and implementation of security policies.", "requirement_type": "mandatory" },
        { "reference_code": "164.308(a)(3)", "title": "Workforce Security", "description": "Implement policies and procedures to ensure appropriate access by workforce members.", "requirement_type": "mandatory" },
        { "reference_code": "164.308(a)(4)", "title": "Information Access Management", "description": "Implement policies and procedures for authorizing access to ePHI.", "requirement_type": "mandatory" },
        { "reference_code": "164.308(a)(5)", "title": "Security Awareness and Training", "description": "Implement a security awareness and training program for all workforce members.", "requirement_type": "mandatory" },
        { "reference_code": "164.308(a)(6)", "title": "Security Incident Procedures", "description": "Implement policies and procedures to address security incidents.", "requirement_type": "mandatory" },
        { "reference_code": "164.308(a)(7)", "title": "Contingency Plan", "description": "Establish and implement policies and procedures for responding to an emergency.", "requirement_type": "mandatory" },
        { "reference_code": "164.308(a)(8)", "title": "Evaluation", "description": "Perform a periodic technical and non-technical evaluation of security policies.", "requirement_type": "mandatory" }
      ]
    },
    {
      "reference_code": "164.310",
      "title": "Physical Safeguards",
      "requirement_type": "mandatory",
      "category": "Security Rule - Physical",
      "children": [
        { "reference_code": "164.310(a)(1)", "title": "Facility Access Controls", "description": "Implement policies and procedures to limit physical access to electronic information systems.", "requirement_type": "mandatory" },
        { "reference_code": "164.310(b)", "title": "Workstation Use", "description": "Implement policies and procedures that specify the proper functions to be performed on workstations.", "requirement_type": "mandatory" },
        { "reference_code": "164.310(c)", "title": "Workstation Security", "description": "Implement physical safeguards for all workstations that access ePHI.", "requirement_type": "mandatory" },
        { "reference_code": "164.310(d)(1)", "title": "Device and Media Controls", "description": "Implement policies and procedures that govern the receipt and removal of hardware and electronic media.", "requirement_type": "mandatory" }
      ]
    },
    {
      "reference_code": "164.312",
      "title": "Technical Safeguards",
      "requirement_type": "mandatory",
      "category": "Security Rule - Technical",
      "children": [
        { "reference_code": "164.312(a)(1)", "title": "Access Control", "description": "Implement technical policies and procedures for electronic information systems that maintain ePHI.", "requirement_type": "mandatory" },
        { "reference_code": "164.312(b)", "title": "Audit Controls", "description": "Implement hardware, software, and/or procedural mechanisms to record and examine activity.", "requirement_type": "mandatory" },
        { "reference_code": "164.312(c)(1)", "title": "Integrity", "description": "Implement policies and procedures to protect ePHI from improper alteration or destruction.", "requirement_type": "mandatory" },
        { "reference_code": "164.312(d)", "title": "Person or Entity Authentication", "description": "Implement procedures to verify that a person seeking access to ePHI is the one claimed.", "requirement_type": "mandatory" },
        { "reference_code": "164.312(e)(1)", "title": "Transmission Security", "description": "Implement technical security measures to guard against unauthorized access to ePHI transmitted over an electronic communications network.", "requirement_type": "mandatory" }
      ]
    },
    {
      "reference_code": "164.406",
      "title": "Breach Notification Rule",
      "requirement_type": "mandatory",
      "category": "Breach Notification",
      "children": [
        { "reference_code": "164.406(a)", "title": "Individual Notification", "description": "Notify each individual whose unsecured PHI has been or is reasonably believed to have been, accessed, acquired, used, or disclosed.", "requirement_type": "mandatory" },
        { "reference_code": "164.406(b)", "title": "Media Notification", "description": "Notify prominent media outlets following discovery of breach affecting more than 500 residents of a state.", "requirement_type": "mandatory" },
        { "reference_code": "164.406(c)", "title": "Secretary Notification", "description": "Notify the Secretary of HHS following discovery of a breach.", "requirement_type": "mandatory" }
      ]
    }
  ]
}
