Skip to content

HIPAAPCI DSS crosswalk

A control-by-control mapping between HIPAA Security Rule (45 CFR Part 164, Subpart C) and PCI DSS v4.0. 5 mappings.

HIPAAPCI DSSRelationshipNotes
§164.312(a)(1)
Access control
Req. 7
Restrict access by business need to know
EquivalentCurated
Access control & identity
§164.312(a)(1)
Access control
Req. 8
Identify users and authenticate access
EquivalentCurated
Access control & identity
§164.312(b)
Audit controls
Req. 10
Log and monitor all access to system components and cardholder data
EquivalentCurated
Logging, monitoring & detection
§164.312(e)(1)
Transmission security
Req. 3
Protect stored account data
EquivalentCurated
Cryptography & data protection
§164.312(e)(1)
Transmission security
Req. 4
Protect cardholder data with strong cryptography during transmission
EquivalentCurated
Cryptography & data protection

Mappings marked “Official” derive from standards-body informative references; “Curated” mappings are authored by Cyber Compliance and provided for guidance only.