Draft · internal validation

HIPAA Security Rule

45 CFR Part 164 · Department of Health and Human Services

Draft policy wording checks for US medical and dental HIPAA covered entities. Upload policies without patient data only. Privacy, Breach Notification, health-plan and clearinghouse-specific duties are outside this preview; addressable safeguards allow documented alternatives where appropriate.

This pack is a draft.Every requirement traces to official text, but it has not had independent compliance or legal review. You can get a quote and aggregate policy pre-scan today; cited reports open after review.
Requirements63atomic checksCRITICAL3severityHIGH60severityWith official link63/63eCFR section URLRule effectiveMar 26, 2013current textPack version0.1.0-draft.1authored Oct 6, 2026

Requirements

Showing 8 of 63 · official summaries
45 CFR 164.306(d)(3)

Assess each addressable safeguard for reasonableness and appropriateness. Implement it when appropriate; otherwise document the decision and an equivalent alternative measure when appropriate. Addressable: implement when reasonable and appropriate; otherwise document why and an equivalent alternative measure when appropriate under 45 CFR 164.306(d)(3).

HIGHeCFR
45 CFR 164.306(e)

Review and modify security measures when needed and update the corresponding documentation.

HIGHeCFR
45 CFR 164.308(a)(1)(ii)(A)

Conduct an accurate and thorough risk analysis covering potential threats and vulnerabilities across all systems, devices, and media holding ePHI.

CRITICALeCFR
45 CFR 164.308(a)(2)

Identify the Security Official responsible for developing and implementing security policies.

HIGHeCFR
All 63 requirements are versioned in the draft pack. Full evidence and remediation guidance remain inside the product.