Full language-screen report
Fictional sample · no paymentHIPAA security policy · United States only
63 in-scope checks · 0 unresolved · 0 out of scope
Strong matches earn full credit; partial matches earn half credit. Unresolved and out-of-scope checks are excluded. This is a wording score, not a compliance grade.
Important: This report identifies potential policy and documentation gaps. It does not verify that controls are operating effectively and is not legal advice, certification, or a compliance determination.
HIPAA Security Rule — covered-entity policy wording preview
Version 0.1.0-draft.1 · DRAFT · 63 checks
- 45 CFR 164.308(a)(1)(ii)(A)No matching language · critical
Conduct an accurate and thorough risk analysis covering potential threats and vulnerabilities across all systems, devices, and media holding ePHI.
Department of Health and Human Services · official source
An explicit gap, negation, planned control or conflicting statement prevents any credit for this check. The best remaining wording match is 48.3%; overlapping positive wording does not override an admitted gap. Review the source document's statements for this control.
Suggested fix: List all locations and systems holding ePHI, assess relevant threats and vulnerabilities, record likelihood and impact, and document the resulting risk analysis and owner. Verify implementation separately without uploading patient data.
- 45 CFR 164.308(b)(3)No matching language · critical
Document business associate safeguards in a signed written agreement or a qualifying other arrangement before service starts.
Department of Health and Human Services · official source
An explicit gap, negation, planned control or conflicting statement prevents any credit for this check. The best remaining wording match is 66.0%; overlapping positive wording does not override an admitted gap. Review the source document's statements for this control.
Suggested fix: Describe the process for obtaining and retaining an executed business associate agreement or legally qualifying written arrangement before service begins; address missing or unsigned agreements. Verify implementation separately without uploading patient data.
- 45 CFR 164.312(a)(1)No matching language · critical
Limit electronic system access to authorized persons and software programs.
Department of Health and Human Services · official source
Automated text screen found no eligible passage matching at least 30% of this requirement's wording concepts or weighted terms (best match 25.4%).
Suggested fix: Define how persons and software programs receive authorized electronic access, with permission-setting and removal procedures. Verify implementation separately without uploading patient data.
- 45 CFR 164.306(d)(3)No matching language · high
Assess each addressable safeguard for reasonableness and appropriateness. Implement it when appropriate; otherwise document the decision and an equivalent alternative measure when appropriate. Addressable: implement when reasonable and appropriate; otherwise document why and an equivalent alternative measure when appropriate under 45 CFR 164.306(d)(3).
Department of Health and Human Services · official source
Automated text screen found no eligible passage matching at least 30% of this requirement's wording concepts or weighted terms (best match 22.1%).
Suggested fix: Add an addressable-safeguard decision register: measure, risk basis, reasonableness decision, owner, and the implemented measure or documented alternative. Addressable: implement when reasonable and appropriate; otherwise document why and an equivalent alternative measure when appropriate under 45 CFR 164.306(d)(3). Verify implementation separately without uploading patient data.
- 45 CFR 164.308(a)(5)(i)No matching language · high
Provide security awareness and training to every workforce member, including management.
Department of Health and Human Services · official source
An explicit gap, negation, planned control or conflicting statement prevents any credit for this check. The best remaining wording match is 33.5%; overlapping positive wording does not override an admitted gap. Review the source document's statements for this control.
Suggested fix: Define security training for all workforce members and management, assign an owner, identify delivery and update procedures, and describe how participation is documented. Verify implementation separately without uploading patient data.
- 45 CFR 164.308(a)(5)(ii)(B)No matching language · high
Guard against, detect, and report malicious software. Addressable: implement when reasonable and appropriate; otherwise document why and an equivalent alternative measure when appropriate under 45 CFR 164.306(d)(3).
Department of Health and Human Services · official source
Automated text screen found no eligible passage matching at least 30% of this requirement's wording concepts or weighted terms (best match 16.5%).
Suggested fix: Describe malware prevention and detection measures, workforce reporting steps and the response owner. Addressable: implement when reasonable and appropriate; otherwise document why and an equivalent alternative measure when appropriate under 45 CFR 164.306(d)(3). Verify implementation separately without uploading patient data.
- 45 CFR 164.308(a)(5)(ii)(C)No matching language · high
Monitor login attempts and report discrepancies. Addressable: implement when reasonable and appropriate; otherwise document why and an equivalent alternative measure when appropriate under 45 CFR 164.306(d)(3).
Department of Health and Human Services · official source
Automated text screen found no eligible passage matching at least 30% of this requirement's wording concepts or weighted terms (best match 14.5%).
Suggested fix: Identify login-attempt records, review responsibilities and steps for reporting and investigating discrepancies. Addressable: implement when reasonable and appropriate; otherwise document why and an equivalent alternative measure when appropriate under 45 CFR 164.306(d)(3). Verify implementation separately without uploading patient data.
- 45 CFR 164.308(a)(7)(i)No matching language · high
Maintain a contingency plan for emergencies and events that damage systems holding ePHI.
Department of Health and Human Services · official source
Automated text screen found no eligible passage matching at least 30% of this requirement's wording concepts or weighted terms (best match 19.8%).
Suggested fix: List emergency scenarios affecting ePHI systems, contingency responsibilities and steps for backup, recovery and emergency operation. Verify implementation separately without uploading patient data.
- 45 CFR 164.308(a)(7)(ii)(D)No matching language · high
Periodically test and revise contingency and recovery plans. Addressable: implement when reasonable and appropriate; otherwise document why and an equivalent alternative measure when appropriate under 45 CFR 164.306(d)(3).
Department of Health and Human Services · official source
An explicit gap, negation, planned control or conflicting statement prevents any credit for this check. The best remaining wording match is 50.6%; overlapping positive wording does not override an admitted gap. Review the source document's statements for this control.
Suggested fix: Set a periodic contingency-plan testing and revision process; document exercises, results, identified weaknesses and approved plan changes. Addressable: implement when reasonable and appropriate; otherwise document why and an equivalent alternative measure when appropriate under 45 CFR 164.306(d)(3). Verify implementation separately without uploading patient data.
- 45 CFR 164.308(a)(7)(ii)(E)No matching language · high
Assess application and data criticality to support contingency planning. Addressable: implement when reasonable and appropriate; otherwise document why and an equivalent alternative measure when appropriate under 45 CFR 164.306(d)(3).
Department of Health and Human Services · official source
Automated text screen found no eligible passage matching at least 30% of this requirement's wording concepts or weighted terms (best match 28.3%).
Suggested fix: Rank applications and data by criticality and record how the ranking informs contingency priorities. Addressable: implement when reasonable and appropriate; otherwise document why and an equivalent alternative measure when appropriate under 45 CFR 164.306(d)(3). Verify implementation separately without uploading patient data.
- 45 CFR 164.308(b)(1)No matching language · high
Obtain satisfactory business associate assurances before vendors handle ePHI on behalf of the covered entity.
Department of Health and Human Services · official source
An explicit gap, negation, planned control or conflicting statement prevents any credit for this check. The best remaining wording match is 51.4%; overlapping positive wording does not override an admitted gap. Review the source document's statements for this control.
Suggested fix: Identify business associates handling ePHI and the satisfactory assurances to obtain before access begins; assign ownership of the review. Verify implementation separately without uploading patient data.
- 45 CFR 164.310(a)(1)No matching language · high
Limit physical access to facilities and electronic systems to authorized persons.
Department of Health and Human Services · official source
Automated text screen found no eligible passage matching at least 30% of this requirement's wording concepts or weighted terms (best match 27.7%).
Suggested fix: Identify protected facilities and systems, authorized physical-access roles and the controls for restricting entry. Verify implementation separately without uploading patient data.
- 45 CFR 164.310(a)(2)(ii)No matching language · high
Protect facilities and equipment against unauthorized physical access, tampering, and theft. Addressable: implement when reasonable and appropriate; otherwise document why and an equivalent alternative measure when appropriate under 45 CFR 164.306(d)(3).
Department of Health and Human Services · official source
Automated text screen found no eligible passage matching at least 30% of this requirement's wording concepts or weighted terms (best match 15.2%).
Suggested fix: Document facility and equipment protection against unauthorized entry, tampering and theft, with assigned responsibilities. Addressable: implement when reasonable and appropriate; otherwise document why and an equivalent alternative measure when appropriate under 45 CFR 164.306(d)(3). Verify implementation separately without uploading patient data.
- 45 CFR 164.310(a)(2)(iv)No matching language · high
Document security-related facility repairs and modifications to hardware, doors, walls, and locks. Addressable: implement when reasonable and appropriate; otherwise document why and an equivalent alternative measure when appropriate under 45 CFR 164.306(d)(3).
Department of Health and Human Services · official source
Automated text screen found no eligible passage matching at least 30% of this requirement's wording concepts or weighted terms (best match 24.8%).
Suggested fix: Add a maintenance record process for security-related repairs and modifications to hardware, doors, walls and locks. Addressable: implement when reasonable and appropriate; otherwise document why and an equivalent alternative measure when appropriate under 45 CFR 164.306(d)(3). Verify implementation separately without uploading patient data.
- 45 CFR 164.310(b)No matching language · high
Specify authorized workstation functions, acceptable use, and safe physical surroundings.
Department of Health and Human Services · official source
Automated text screen found no eligible passage matching at least 30% of this requirement's wording concepts or weighted terms (best match 21.7%).
Suggested fix: Specify allowed workstation functions, acceptable use and physical surroundings for workstations accessing ePHI. Verify implementation separately without uploading patient data.
- 45 CFR 164.310(d)(2)(iv)No matching language · high
Create a retrievable exact backup when needed before equipment movement. Addressable: implement when reasonable and appropriate; otherwise document why and an equivalent alternative measure when appropriate under 45 CFR 164.306(d)(3).
Department of Health and Human Services · official source
Automated text screen found no eligible passage matching at least 30% of this requirement's wording concepts or weighted terms (best match 29.9%).
Suggested fix: Describe when a retrievable exact backup is needed before equipment moves and who creates and verifies its availability. Addressable: implement when reasonable and appropriate; otherwise document why and an equivalent alternative measure when appropriate under 45 CFR 164.306(d)(3). Verify implementation separately without uploading patient data.
- 45 CFR 164.312(a)(2)(iv)No matching language · high
Encrypt and decrypt stored ePHI through an implemented mechanism. Addressable: implement when reasonable and appropriate; otherwise document why and an equivalent alternative measure when appropriate under 45 CFR 164.306(d)(3).
Department of Health and Human Services · official source
Automated text screen found no eligible passage matching at least 30% of this requirement's wording concepts or weighted terms (best match 20.7%).
Suggested fix: Document the selected encryption and decryption mechanism for stored ePHI and the roles responsible for its operation. Addressable: implement when reasonable and appropriate; otherwise document why and an equivalent alternative measure when appropriate under 45 CFR 164.306(d)(3). Verify implementation separately without uploading patient data.
- 45 CFR 164.312(c)(1)No matching language · high
Protect ePHI against improper alteration or destruction.
Department of Health and Human Services · official source
Automated text screen found no eligible passage matching at least 30% of this requirement's wording concepts or weighted terms (best match 24.4%).
Suggested fix: Describe controls protecting ePHI against improper alteration or destruction and the responsible owner. Verify implementation separately without uploading patient data.
- 45 CFR 164.312(c)(2)No matching language · high
Authenticate ePHI integrity through mechanisms that detect unauthorized alteration or destruction. Addressable: implement when reasonable and appropriate; otherwise document why and an equivalent alternative measure when appropriate under 45 CFR 164.306(d)(3).
Department of Health and Human Services · official source
Automated text screen found no eligible passage matching at least 30% of this requirement's wording concepts or weighted terms (best match 17.6%).
Suggested fix: Document the electronic mechanisms used to corroborate ePHI integrity and detect unauthorized alteration or destruction. Addressable: implement when reasonable and appropriate; otherwise document why and an equivalent alternative measure when appropriate under 45 CFR 164.306(d)(3). Verify implementation separately without uploading patient data.
- 45 CFR 164.312(d)No matching language · high
Verify the identity of persons or entities seeking access.
Department of Health and Human Services · official source
Automated text screen found no eligible passage matching at least 30% of this requirement's wording concepts or weighted terms (best match 27.2%).
Suggested fix: Describe how identity is verified before persons or entities receive access and who maintains the authentication process. Verify implementation separately without uploading patient data.
- 45 CFR 164.312(e)(1)No matching language · high
Protect transmitted ePHI against unauthorized access across communication networks.
Department of Health and Human Services · official source
Automated text screen found no eligible passage matching at least 30% of this requirement's wording concepts or weighted terms (best match 20.1%).
Suggested fix: Identify ePHI transmission paths and controls preventing unauthorized access across those networks. Verify implementation separately without uploading patient data.
- 45 CFR 164.312(e)(2)(i)No matching language · high
Detect improper modification of electronically transmitted ePHI. Addressable: implement when reasonable and appropriate; otherwise document why and an equivalent alternative measure when appropriate under 45 CFR 164.306(d)(3).
Department of Health and Human Services · official source
Automated text screen found no eligible passage matching at least 30% of this requirement's wording concepts or weighted terms (best match 14.9%).
Suggested fix: Describe transmission integrity controls and how improper modification is detected. Addressable: implement when reasonable and appropriate; otherwise document why and an equivalent alternative measure when appropriate under 45 CFR 164.306(d)(3). Verify implementation separately without uploading patient data.
- 45 CFR 164.314(a)(2)(i)(B)No matching language · high
Business associate agreements require subcontractors handling ePHI to accept applicable security obligations in contracts.
Department of Health and Human Services · official source
An explicit gap, negation, planned control or conflicting statement prevents any credit for this check. The best remaining wording match is 65.2%; overlapping positive wording does not override an admitted gap. Review the source document's statements for this control.
Suggested fix: Add contract terms requiring business associates to obtain applicable security obligations from subcontractors handling ePHI. Verify implementation separately without uploading patient data.
- 45 CFR 164.308(a)(1)(i)Partial matching language · high
Security policies prevent, detect, contain, and correct security violations.
Department of Health and Human Services · official source
Coverage is below the strong-match threshold. Automated text screen found only a partial match (30.4% of wording concepts or weighted terms). Review the cited passage against the full requirement; weighted term overlap is not a measure of implementation.
“This document contains policy descriptions and fictional operational facts only.”
Suggested fix: Describe how staff detect and escalate security violations, who contains them, and how corrective actions are assigned and tracked. Verify implementation separately without uploading patient data.
- 45 CFR 164.308(a)(1)(ii)(D)Partial matching language · high
Regularly review audit logs, access reports, and security incident tracking records with assigned reviewers.
Department of Health and Human Services · official source
Coverage is below the strong-match threshold. Automated text screen found only a partial match (47.9% of wording concepts or weighted terms). Review the cited passage against the full requirement; weighted term overlap is not a measure of implementation.
“The service desk records the report time, reporter role, affected system, observed facts, and urgent patient-care impact. Staff must avoid copying clinical content into a general support ticket. An incident identifier connects the ticket to a restricted evidence record. The Security Official leads the incident response team and assigns containment, evidence preservation, and recovery tasks. Technical staff isolate an affected account or device when appropriate, preserve logs, and document every action.”
Suggested fix: Identify audit logs, access reports and incident records to review; name reviewers, set a review cadence and describe escalation of suspicious activity. Verify implementation separately without uploading patient data.
- 45 CFR 164.308(a)(2)Partial matching language · high
Identify the Security Official responsible for developing and implementing security policies.
Department of Health and Human Services · official source
Coverage is below the strong-match threshold. Automated text screen found only a partial match (50.7% of wording concepts or weighted terms). Review the cited passage against the full requirement; weighted term overlap is not a measure of implementation.
“Review, evidence, and change control The Clinic Administrator maintains the controlled policy copy and makes the current version available to workforce members responsible for its procedures. Each revision records the author role, approval date, change description, and superseded version. An annual review is scheduled for October, and an additional review follows material system changes, a serious incident, or a change in the services used to handle ePHI. The Security Official performs a periodic technical and nontechnical evaluation and records the scope, methods, findings, owners, and closure decisions.”
Suggested fix: Identify the Security Official by name or role and assign development and implementation responsibility for security policies. Verify implementation separately without uploading patient data.
- 45 CFR 164.308(a)(3)(i)Partial matching language · high
Limit workforce access to authorized personnel and prevent unauthorized workforce access.
Department of Health and Human Services · official source
Coverage is below the strong-match threshold. Automated text screen found only a partial match (45.9% of wording concepts or weighted terms). Review the cited passage against the full requirement; weighted term overlap is not a measure of implementation.
“Supervisors report policy violations to the Clinic Administrator, who records investigation outcomes and any disciplinary action under the personnel procedure. The access ticket, quarterly review, and departure record are retained in the security evidence library. Policy topics include workforce security, authorization, and security awareness under 45 CFR 164.308(a)(3)-(5).”
Suggested fix: Define workforce access approvals, supervision and removal steps, with responsibility for preventing unauthorized access to ePHI. Verify implementation separately without uploading patient data.
- 45 CFR 164.308(a)(3)(ii)(B)Partial matching language · high
Determine that each workforce member has appropriate access based on the assigned job role. Addressable: implement when reasonable and appropriate; otherwise document why and an equivalent alternative measure when appropriate under 45 CFR 164.306(d)(3).
Department of Health and Human Services · official source
Coverage is below the strong-match threshold. Automated text screen found only a partial match (54.8% of wording concepts or weighted terms). Review the cited passage against the full requirement; weighted term overlap is not a measure of implementation.
“Department supervisors approve job-based access. Technical staff operate accounts, backups, logging, and device controls. Each role is assigned to a position rather than an unnamed group.”
Suggested fix: Add a clearance process that checks job duties against requested ePHI access before permissions are granted. Addressable: implement when reasonable and appropriate; otherwise document why and an equivalent alternative measure when appropriate under 45 CFR 164.306(d)(3). Verify implementation separately without uploading patient data.
- 45 CFR 164.308(a)(4)(ii)(B)Partial matching language · high
Approve access rights to workstations, applications, transactions, and processes. Addressable: implement when reasonable and appropriate; otherwise document why and an equivalent alternative measure when appropriate under 45 CFR 164.306(d)(3).
Department of Health and Human Services · official source
Coverage is below the strong-match threshold. Automated text screen found only a partial match (35.0% of wording concepts or weighted terms). Review the cited passage against the full requirement; weighted term overlap is not a measure of implementation.
“The Security Official approves the access group, and technical staff create a unique account. Front-desk staff receive scheduling functions; clinicians receive treatment functions appropriate to their assignments; billing staff receive claim-processing functions.”
Suggested fix: List how workstation, application, transaction and process access requests are approved, provisioned and recorded. Addressable: implement when reasonable and appropriate; otherwise document why and an equivalent alternative measure when appropriate under 45 CFR 164.306(d)(3). Verify implementation separately without uploading patient data.
- 45 CFR 164.308(a)(5)(ii)(D)Partial matching language · high
Create, change, and safeguard passwords through documented password procedures. Addressable: implement when reasonable and appropriate; otherwise document why and an equivalent alternative measure when appropriate under 45 CFR 164.306(d)(3).
Department of Health and Human Services · official source
Coverage is below the strong-match threshold. Automated text screen found only a partial match (50.0% of wording concepts or weighted terms). Review the cited passage against the full requirement; weighted term overlap is not a measure of implementation.
“Technical staff verify these settings at enrollment and after a security-related configuration change. Device compliance reports identify machines missing the approved configuration; a nonconforming device cannot reconnect to clinical systems until the issue is resolved or a documented temporary decision is approved. Clinic policy requires encryption on managed laptops and approved transport protection for electronic health record, portal, and vendor connections. Configuration records identify the system, enabled settings, verification date, and owner. The clinic chooses these technical measures as part of its own risk-management process; this fictional procedure does not present every chosen technology as a universal statutory requirement.”
Suggested fix: Write password creation, change and safeguarding procedures, including owner responsibilities and how credentials are protected. Addressable: implement when reasonable and appropriate; otherwise document why and an equivalent alternative measure when appropriate under 45 CFR 164.306(d)(3). Verify implementation separately without uploading patient data.
- 45 CFR 164.308(a)(7)(ii)(A)Partial matching language · high
Create and maintain retrievable exact backup copies of ePHI.
Department of Health and Human Services · official source
Coverage is below the strong-match threshold. Automated text screen found only a partial match (44.5% of wording concepts or weighted terms). Review the cited passage against the full requirement; weighted term overlap is not a measure of implementation.
“Business associates and information exchanges The Privacy Officer maintains a register of organizations that create, receive, maintain, or transmit ePHI on the clinic’s behalf. Each entry identifies the service, exchanged information, approved connection, contract owner, and review date. The electronic health record host, claims clearinghouse, portal operator, and backup operator are listed.”
Suggested fix: Define backup scope and procedures for maintaining retrievable exact copies of ePHI, with responsible roles and retrieval steps. Verify implementation separately without uploading patient data.
- 45 CFR 164.310(a)(2)(i)Partial matching language · high
Allow authorized facility access for restoration and emergency mode operations. Addressable: implement when reasonable and appropriate; otherwise document why and an equivalent alternative measure when appropriate under 45 CFR 164.306(d)(3).
Department of Health and Human Services · official source
Coverage is below the strong-match threshold. Automated text screen found only a partial match (50.8% of wording concepts or weighted terms). Review the cited passage against the full requirement; weighted term overlap is not a measure of implementation.
“The emergency-mode procedure directs the Clinic Administrator to declare an outage, assign a clinical coordinator, and decide which appointments can safely continue. Staff use approved downtime forms kept in a secured cabinet. When the electronic health record is restored, authorized staff reconcile the downtime entries and document the reconciliation review. The outage record includes decisions, start and recovery times, and unresolved operational issues.”
Suggested fix: Describe how authorized personnel gain facility access for restoring lost data and supporting emergency operation. Addressable: implement when reasonable and appropriate; otherwise document why and an equivalent alternative measure when appropriate under 45 CFR 164.306(d)(3). Verify implementation separately without uploading patient data.
- 45 CFR 164.310(a)(2)(iii)Partial matching language · high
Validate facility access based on role, control visitors, and control software testing access. Addressable: implement when reasonable and appropriate; otherwise document why and an equivalent alternative measure when appropriate under 45 CFR 164.306(d)(3).
Department of Health and Human Services · official source
Coverage is below the strong-match threshold. Automated text screen found only a partial match (37.4% of wording concepts or weighted terms). Review the cited passage against the full requirement; weighted term overlap is not a measure of implementation.
“Department supervisors approve job-based access. Technical staff operate accounts, backups, logging, and device controls. Each role is assigned to a position rather than an unnamed group.”
Suggested fix: Write procedures for validating role-based facility access, managing visitors and controlling software-testing access. Addressable: implement when reasonable and appropriate; otherwise document why and an equivalent alternative measure when appropriate under 45 CFR 164.306(d)(3). Verify implementation separately without uploading patient data.
- 45 CFR 164.310(c)Partial matching language · high
Physically protect workstations to restrict access to authorized users.
Department of Health and Human Services · official source
One or more required control concepts, scope details or contractual duties are missing from this passage; overlapping words alone cannot earn a strong label. Automated text screen found only a partial match (66.7% of wording concepts or weighted terms). Review the cited passage against the full requirement; weighted term overlap is not a measure of implementation.
“Workstations, authentication, and audit records Each managed workstation requires a named account and locks after five minutes without activity.”
Suggested fix: Describe physical workstation protections, authorized-user restrictions and responsibility for applying them. Verify implementation separately without uploading patient data.
- 45 CFR 164.310(d)(1)Partial matching language · high
Control receipt, removal, and movement of hardware and electronic media containing ePHI.
Department of Health and Human Services · official source
Coverage is below the strong-match threshold. Automated text screen found only a partial match (33.0% of wording concepts or weighted terms). Review the cited passage against the full requirement; weighted term overlap is not a measure of implementation.
“System inventory and risk analysis The Security Official maintains an inventory covering the hosted electronic health record, patient portal, claims interface, laboratory messaging, staff laptops, front-desk workstations, network equipment, removable media, and encrypted backups. Each entry identifies its business owner, system location, data flows, access groups, and recovery dependency. Technical staff update entries before a new application enters service and within five business days after a material change. The annual risk analysis considers potential threats to the confidentiality, integrity, and availability of ePHI. Reviewers record threat likelihood, operational impact, existing controls, residual risk, an action owner, and the target date for each corrective action.”
Suggested fix: Add receipt, movement and removal procedures for hardware and media containing ePHI, including accountable roles. Verify implementation separately without uploading patient data.
- 45 CFR 164.310(d)(2)(i)Partial matching language · high
Securely dispose of ePHI and the devices or media storing it.
Department of Health and Human Services · official source
Coverage is below the strong-match threshold. Automated text screen found only a partial match (37.6% of wording concepts or weighted terms). Review the cited passage against the full requirement; weighted term overlap is not a measure of implementation.
“Before a device leaves clinic control, technical staff record its asset identifier and verify approved sanitization or physical destruction.”
Suggested fix: Specify approved ePHI and media disposal methods, authorization steps and responsibility for carrying them out. Verify implementation separately without uploading patient data.
- 45 CFR 164.310(d)(2)(ii)Partial matching language · high
Remove ePHI from electronic media before reuse.
Department of Health and Human Services · official source
Coverage is below the strong-match threshold. Automated text screen found only a partial match (40.6% of wording concepts or weighted terms). Review the cited passage against the full requirement; weighted term overlap is not a measure of implementation.
“System inventory and risk analysis The Security Official maintains an inventory covering the hosted electronic health record, patient portal, claims interface, laboratory messaging, staff laptops, front-desk workstations, network equipment, removable media, and encrypted backups.”
Suggested fix: Define removal of ePHI before electronic media is reused; identify the method and responsible role. Verify implementation separately without uploading patient data.
- 45 CFR 164.310(d)(2)(iii)Partial matching language · high
Record device and media movements and the person responsible. Addressable: implement when reasonable and appropriate; otherwise document why and an equivalent alternative measure when appropriate under 45 CFR 164.306(d)(3).
Department of Health and Human Services · official source
Coverage is below the strong-match threshold. Automated text screen found only a partial match (51.4% of wording concepts or weighted terms). Review the cited passage against the full requirement; weighted term overlap is not a measure of implementation.
“Review, evidence, and change control The Clinic Administrator maintains the controlled policy copy and makes the current version available to workforce members responsible for its procedures. Each revision records the author role, approval date, change description, and superseded version. An annual review is scheduled for October, and an additional review follows material system changes, a serious incident, or a change in the services used to handle ePHI. The Security Official performs a periodic technical and nontechnical evaluation and records the scope, methods, findings, owners, and closure decisions. Evaluations must consider the examination-room devices omitted from the September review.”
Suggested fix: Add a device and media movement log with the item, movement and person responsible. Addressable: implement when reasonable and appropriate; otherwise document why and an equivalent alternative measure when appropriate under 45 CFR 164.306(d)(3). Verify implementation separately without uploading patient data.
- 45 CFR 164.312(a)(2)(iii)Partial matching language · high
Automatically end electronic sessions after a defined period of inactivity. Addressable: implement when reasonable and appropriate; otherwise document why and an equivalent alternative measure when appropriate under 45 CFR 164.306(d)(3).
Department of Health and Human Services · official source
Coverage is below the strong-match threshold. Automated text screen found only a partial match (30.2% of wording concepts or weighted terms). Review the cited passage against the full requirement; weighted term overlap is not a measure of implementation.
“Technical staff disable a departing employee account by the end of the final work shift and revoke portal, remote-access, and vendor-console sessions.”
Suggested fix: Specify inactivity periods and mechanisms for automatically terminating electronic sessions, and who configures them. Addressable: implement when reasonable and appropriate; otherwise document why and an equivalent alternative measure when appropriate under 45 CFR 164.306(d)(3). Verify implementation separately without uploading patient data.
- 45 CFR 164.312(b)Partial matching language · high
Record and examine system activity using audit logs and review mechanisms.
Department of Health and Human Services · official source
Coverage is below the strong-match threshold. Automated text screen found only a partial match (48.2% of wording concepts or weighted terms). Review the cited passage against the full requirement; weighted term overlap is not a measure of implementation.
“Workstations, authentication, and audit records Each managed workstation requires a named account and locks after five minutes without activity. Remote access and privileged administration require multi-factor authentication under clinic policy. Technical staff verify these settings at enrollment and after a security-related configuration change. Device compliance reports identify machines missing the approved configuration; a nonconforming device cannot reconnect to clinical systems until the issue is resolved or a documented temporary decision is approved.”
Suggested fix: Identify system activity to record, the audit mechanisms, review roles and follow-up procedures. Verify implementation separately without uploading patient data.
- 45 CFR 164.312(e)(2)(ii)Partial matching language · high
Encrypt ePHI during transmission when appropriate. Addressable: implement when reasonable and appropriate; otherwise document why and an equivalent alternative measure when appropriate under 45 CFR 164.306(d)(3).
Department of Health and Human Services · official source
Coverage is below the strong-match threshold. Automated text screen found only a partial match (34.5% of wording concepts or weighted terms). Review the cited passage against the full requirement; weighted term overlap is not a measure of implementation.
“Clinic policy requires encryption on managed laptops and approved transport protection for electronic health record, portal, and vendor connections.”
Suggested fix: Document the transmission encryption decision and the selected mechanism when appropriate, with responsible roles. Addressable: implement when reasonable and appropriate; otherwise document why and an equivalent alternative measure when appropriate under 45 CFR 164.306(d)(3). Verify implementation separately without uploading patient data.
- 45 CFR 164.314(a)(2)(i)(A)Partial matching language · high
Business associate agreements require compliance with applicable Security Rule safeguards.
Department of Health and Human Services · official source
Coverage is below the strong-match threshold. Automated text screen found only a partial match (49.9% of wording concepts or weighted terms). Review the cited passage against the full requirement; weighted term overlap is not a measure of implementation.
“A business associate agreement and security review are required by clinic procedure before an approved service begins handling ePHI. The contract review records safeguards, incident reporting arrangements, restrictions on use, subcontractor responsibilities, and the return or destruction arrangements at service termination.”
Suggested fix: Add the applicable Security Rule safeguard obligations to the business associate agreement and assign responsibility for checking contract terms. Verify implementation separately without uploading patient data.
- 45 CFR 164.316(a)Partial matching language · high
Implement reasonable and appropriate written security policies and document policy changes.
Department of Health and Human Services · official source
Coverage is below the strong-match threshold. Automated text screen found only a partial match (38.0% of wording concepts or weighted terms). Review the cited passage against the full requirement; weighted term overlap is not a measure of implementation.
“The governing partners approved this fictional policy on October 6, 2026; policy approval does not close the outstanding implementation issues described below. This document contains policy descriptions and fictional operational facts only.”
Suggested fix: Describe approval, implementation and change control for written security policies appropriate to the organization. Verify implementation separately without uploading patient data.
- 45 CFR 164.316(b)(1)Partial matching language · high
Maintain written security policies and records of actions, activities, and assessments that require documentation.
Department of Health and Human Services · official source
Coverage is below the strong-match threshold. Automated text screen found only a partial match (53.2% of wording concepts or weighted terms). Review the cited passage against the full requirement; weighted term overlap is not a measure of implementation.
“The evidence library keeps policy versions and documentation of required security actions for six years after creation or the last date in effect, whichever is later. This security-documentation rule is separate from the clinic’s medical-record retention schedule and does not set a blanket six-year retention period for patient records.”
Suggested fix: Identify the repository and owner for written policies and required action, activity and assessment records, including electronic records. Verify implementation separately without uploading patient data.
- 45 CFR 164.306(e)Matching language found · high
Review and modify security measures when needed and update the corresponding documentation.
Department of Health and Human Services · official source
Automated text screen found a passage matching 100.0% of this requirement's wording concepts or weighted terms. A document statement is not proof that a control operates.
“Review, evidence, and change control The Clinic Administrator maintains the controlled policy copy and makes the current version available to workforce members responsible for its procedures.”
- 45 CFR 164.308(a)(1)(ii)(B)Matching language found · high
Reduce identified risks and vulnerabilities through security measures, corrective actions, and accountable owners.
Department of Health and Human Services · official source
Automated text screen found a passage matching 59.7% of this requirement's wording concepts or weighted terms. A document statement is not proof that a control operates.
“Each needs an accountable owner, corrective-action date, and verification evidence. Acknowledgment of an open issue does not resolve it. Policy topics: 45 CFR 164.308(a)(8) and 164.316. Reference materials checked October 6, 2026: HHS Summary of the HIPAA Security Rule; HHS Guidance on Risk Analysis; HHS Breach Notification Rule.”
- 45 CFR 164.308(a)(1)(ii)(C)Matching language found · high
Apply appropriate sanctions and disciplinary action for workforce security policy violations.
Department of Health and Human Services · official source
Automated text screen found a passage matching 59.2% of this requirement's wording concepts or weighted terms. A document statement is not proof that a control operates.
“Supervisors report policy violations to the Clinic Administrator, who records investigation outcomes and any disciplinary action under the personnel procedure. The access ticket, quarterly review, and departure record are retained in the security evidence library. Policy topics include workforce security, authorization, and security awareness under 45 CFR 164.308(a)(3)-(5).”
- 45 CFR 164.308(a)(3)(ii)(A)Matching language found · high
Authorize and supervise workforce members who handle ePHI. Addressable: implement when reasonable and appropriate; otherwise document why and an equivalent alternative measure when appropriate under 45 CFR 164.306(d)(3).
Department of Health and Human Services · official source
Automated text screen found a passage matching 100.0% of this requirement's wording concepts or weighted terms. A document statement is not proof that a control operates.
“Department supervisors approve job-based access. Technical staff operate accounts, backups, logging, and device controls. Each role is assigned to a position rather than an unnamed group.”
- 45 CFR 164.308(a)(3)(ii)(C)Matching language found · high
Terminate access when employment ends or workforce access is no longer appropriate. Addressable: implement when reasonable and appropriate; otherwise document why and an equivalent alternative measure when appropriate under 45 CFR 164.306(d)(3).
Department of Health and Human Services · official source
Automated text screen found a passage matching 100.0% of this requirement's wording concepts or weighted terms. A document statement is not proof that a control operates.
“Technical staff disable a departing employee account by the end of the final work shift and revoke portal, remote-access, and vendor-console sessions.”
- 45 CFR 164.308(a)(4)(i)Matching language found · high
Authorize access consistently with permitted uses and disclosures under the Privacy Rule.
Department of Health and Human Services · official source
Automated text screen found a passage matching 55.9% of this requirement's wording concepts or weighted terms. A document statement is not proof that a control operates.
“The Privacy Officer reviews permitted uses, disclosures, and possible breach notices.”
- 45 CFR 164.308(a)(4)(ii)(C)Matching language found · high
Establish, document, review, and modify user access rights. Addressable: implement when reasonable and appropriate; otherwise document why and an equivalent alternative measure when appropriate under 45 CFR 164.306(d)(3).
Department of Health and Human Services · official source
Automated text screen found a passage matching 100.0% of this requirement's wording concepts or weighted terms. A document statement is not proof that a control operates.
“The Security Official approves the access group, and technical staff create a unique account. Front-desk staff receive scheduling functions; clinicians receive treatment functions appropriate to their assignments; billing staff receive claim-processing functions. Shared clinical accounts are prohibited. Access reviews occur quarterly, with unnecessary permissions removed and the decision retained.”
- 45 CFR 164.308(a)(5)(ii)(A)Matching language found · high
Provide periodic security reminders and updates to workforce members. Addressable: implement when reasonable and appropriate; otherwise document why and an equivalent alternative measure when appropriate under 45 CFR 164.306(d)(3).
Department of Health and Human Services · official source
Automated text screen found a passage matching 58.4% of this requirement's wording concepts or weighted terms. A document statement is not proof that a control operates.
“Review, evidence, and change control The Clinic Administrator maintains the controlled policy copy and makes the current version available to workforce members responsible for its procedures. Each revision records the author role, approval date, change description, and superseded version. An annual review is scheduled for October, and an additional review follows material system changes, a serious incident, or a change in the services used to handle ePHI. The Security Official performs a periodic technical and nontechnical evaluation and records the scope, methods, findings, owners, and closure decisions.”
- 45 CFR 164.308(a)(6)(i)Matching language found · high
Maintain procedures for addressing security incidents.
Department of Health and Human Services · official source
Automated text screen found a passage matching 77.3% of this requirement's wording concepts or weighted terms. A document statement is not proof that a control operates.
“For this scenario, the clinic is a HIPAA covered entity and its policy addresses the HIPAA Security Rule, 45 CFR Part 164, Subpart C. The clinic operates only in the United States. The clinic creates, receives, maintains, and transmits electronic protected health information (ePHI) through its electronic health record, patient portal, electronic prescribing workflow, laboratory interface, and claims clearinghouse. Patient records, appointment histories, clinical notes, and referral messages are within the policy scope. Paper records are handled under a companion privacy procedure; the electronic security controls here apply to ePHI.”
- 45 CFR 164.308(a)(6)(ii)Matching language found · high
Identify and respond to security incidents, mitigate harmful effects, and document incidents and outcomes.
Department of Health and Human Services · official source
Automated text screen found a passage matching 100.0% of this requirement's wording concepts or weighted terms. A document statement is not proof that a control operates.
“An incident identifier connects the ticket to a restricted evidence record. The Security Official leads the incident response team and assigns containment, evidence preservation, and recovery tasks.”
- 45 CFR 164.308(a)(7)(ii)(B)Matching language found · high
Maintain disaster recovery procedures to restore lost data.
Department of Health and Human Services · official source
Automated text screen found a passage matching 56.1% of this requirement's wording concepts or weighted terms. A document statement is not proof that a control operates.
“The inventory records the protected data, backup destination, approved retention setting, restore dependencies, and the staff authorized to begin recovery. The emergency-mode procedure directs the Clinic Administrator to declare an outage, assign a clinical coordinator, and decide which appointments can safely continue.”
- 45 CFR 164.308(a)(7)(ii)(C)Matching language found · high
Continue critical business processes while protecting ePHI during emergency mode operations.
Department of Health and Human Services · official source
Automated text screen found a passage matching 67.5% of this requirement's wording concepts or weighted terms. A document statement is not proof that a control operates.
“The inventory records the protected data, backup destination, approved retention setting, restore dependencies, and the staff authorized to begin recovery. The emergency-mode procedure directs the Clinic Administrator to declare an outage, assign a clinical coordinator, and decide which appointments can safely continue. Staff use approved downtime forms kept in a secured cabinet. When the electronic health record is restored, authorized staff reconcile the downtime entries and document the reconciliation review. The outage record includes decisions, start and recovery times, and unresolved operational issues.”
- 45 CFR 164.308(a)(8)Matching language found · high
Perform periodic technical and nontechnical security evaluations and reassess after environmental or operational changes.
Department of Health and Human Services · official source
Automated text screen found a passage matching 67.8% of this requirement's wording concepts or weighted terms. A document statement is not proof that a control operates.
“An annual review is scheduled for October, and an additional review follows material system changes, a serious incident, or a change in the services used to handle ePHI. The Security Official performs a periodic technical and nontechnical evaluation and records the scope, methods, findings, owners, and closure decisions.”
- 45 CFR 164.312(a)(2)(i)Matching language found · high
Assign unique user accounts or identifiers to identify and track each user.
Department of Health and Human Services · official source
Automated text screen found a passage matching 57.0% of this requirement's wording concepts or weighted terms. A document statement is not proof that a control operates.
“Workforce access and training Supervisors request access through a documented ticket identifying the employee role, required patient-record functions, and requested start date. The Security Official approves the access group, and technical staff create a unique account. Front-desk staff receive scheduling functions; clinicians receive treatment functions appropriate to their assignments; billing staff receive claim-processing functions.”
- 45 CFR 164.312(a)(2)(ii)Matching language found · high
Provide controlled emergency access to necessary ePHI.
Department of Health and Human Services · official source
Automated text screen found a passage matching 100.0% of this requirement's wording concepts or weighted terms. A document statement is not proof that a control operates.
“Emergency access uses a named emergency account, a recorded reason, and review by the Security Official on the next business day. Clinic policy requires security orientation before routine access to ePHI and a yearly refresher covering phishing, screen locking, incident reporting, and acceptable handling of patient records.”
- 45 CFR 164.314(a)(2)(i)(C)Matching language found · high
Business associate agreements require reporting security incidents and breaches to the covered entity.
Department of Health and Human Services · official source
Automated text screen found a passage matching 65.7% of this requirement's wording concepts or weighted terms. A document statement is not proof that a control operates.
“A business associate agreement and security review are required by clinic procedure before an approved service begins handling ePHI. The contract review records safeguards, incident reporting arrangements, restrictions on use, subcontractor responsibilities, and the return or destruction arrangements at service termination.”
- 45 CFR 164.316(b)(2)(i)Matching language found · high
Retain security documentation for six years from creation or last effective date, whichever is later.
Department of Health and Human Services · official source
Automated text screen found a passage matching 89.3% of this requirement's wording concepts or weighted terms. A document statement is not proof that a control operates.
“The evidence library keeps policy versions and documentation of required security actions for six years after creation or the last date in effect, whichever is later. This security-documentation rule is separate from the clinic’s medical-record retention schedule and does not set a blanket six-year retention period for patient records.”
- 45 CFR 164.316(b)(2)(ii)Matching language found · high
Make security documentation available to the personnel responsible for implementing its procedures.
Department of Health and Human Services · official source
Automated text screen found a passage matching 62.1% of this requirement's wording concepts or weighted terms. A document statement is not proof that a control operates.
“Review, evidence, and change control The Clinic Administrator maintains the controlled policy copy and makes the current version available to workforce members responsible for its procedures.”
- 45 CFR 164.316(b)(2)(iii)Matching language found · high
Periodically review and update security documentation after environmental or operational changes.
Department of Health and Human Services · official source
Automated text screen found a passage matching 55.1% of this requirement's wording concepts or weighted terms. A document statement is not proof that a control operates.
“Technical staff update entries before a new application enters service and within five business days after a material change. The annual risk analysis considers potential threats to the confidentiality, integrity, and availability of ePHI. Reviewers record threat likelihood, operational impact, existing controls, residual risk, an action owner, and the target date for each corrective action. The Security Official reviews the risk register with the governing partners each quarter.”
Limitations
- Preview built on DRAFT rule packs that have not completed independent legal review.
- Produced by a deterministic keyword screen, not by AI and not by a human reviewer; it can miss evidence phrased differently and can match text that does not satisfy the requirement.
- Readiness screening only; not legal advice, an audit, or a certification of compliance.
- Items marked applicability unresolved depend on facts that have not been collected or confirmed yet.
Legal Notice & Disclaimer
This report is provided for informational and readiness-assessment purposes only. It is intended to help identify potential gaps, inconsistencies, or areas for improvement within policies, procedures, SOPs, manuals, and related documentation.
AuditReady does not provide legal advice, regulatory certification, audit opinions, or assurances that an organization is compliant with any law, regulation, standard, or contractual obligation. The presence or absence of a finding in this report does not establish compliance, non-compliance, operational effectiveness, or the adequacy of an organization’s actual practices.
AuditReady is not responsible for the implementation, operation, enforcement, interpretation, or failure to implement any policy, procedure, control, process, or recommendation. Responsibility for business operations, legal compliance, regulatory obligations, internal controls, and organizational decisions remains solely with the organization and its authorized personnel.
AuditReady and its operators disclaim liability, to the fullest extent permitted by applicable law, for any loss, damage, penalty, regulatory action, business interruption, claim, or other consequence arising from reliance on this report, the organization’s operations, or any action or inaction taken in response to the report.
Organizations should consult qualified legal, compliance, security, financial, or other professional advisers where appropriate before making decisions based on this report.