Skip to content

GLBAHIPAA crosswalk

A control-by-control mapping between GLBA Safeguards Rule (16 CFR Part 314) and HIPAA Security Rule (45 CFR Part 164, Subpart C). 5 mappings.

GLBAHIPAARelationshipNotes
§314.4(c)(1)
Access controls
§164.312(a)(1)
Access control
EquivalentCurated
Access control & identity
§314.4(c)(3)
Encryption of customer information
§164.312(e)(1)
Transmission security
EquivalentCurated
Cryptography & data protection
§314.4(c)(8)
Monitoring and logging of authorized user activity
§164.312(b)
Audit controls
EquivalentCurated
Logging, monitoring & detection
§314.4(h)
Incident response plan
§164.308(a)(6)
Security incident procedures
PartialCurated
Incident response & breach notification
§314.4(h)
Incident response plan
§164.404
Notification to individuals
RelatedCurated
Incident response & breach notification

Mappings marked “Official” derive from standards-body informative references; “Curated” mappings are authored by Cyber Compliance and provided for guidance only.