Skip to content

HIPAANIST 800-171 crosswalk

A control-by-control mapping between HIPAA Security Rule (45 CFR Part 164, Subpart C) and NIST SP 800-171 Rev. 2. 6 mappings.

HIPAANIST 800-171RelationshipNotes
§164.308(a)(1)
Security management process
3.11.1
Periodically assess risk
RelatedCurated
Risk assessment & management
§164.308(a)(6)
Security incident procedures
3.6.1
Establish an incident-handling capability
PartialCurated
Incident response & breach notification
§164.312(a)(1)
Access control
3.1.1
Limit system access to authorized users
EquivalentCurated
Access control & identity
§164.312(b)
Audit controls
3.3.1
Create and retain audit logs
EquivalentCurated
Logging, monitoring & detection
§164.312(e)(1)
Transmission security
3.13.11
Employ FIPS-validated cryptography
EquivalentCurated
Cryptography & data protection
§164.404
Notification to individuals
3.6.1
Establish an incident-handling capability
RelatedCurated
Incident response & breach notification

Mappings marked “Official” derive from standards-body informative references; “Curated” mappings are authored by Cyber Compliance and provided for guidance only.