Skip to content

HIPAANIS2 crosswalk

A control-by-control mapping between HIPAA Security Rule (45 CFR Part 164, Subpart C) and NIS2 Directive (EU 2022/2555). 7 mappings.

HIPAANIS2RelationshipNotes
§164.308(a)(1)
Security management process
Art. 21(2)(a)
Risk analysis and information system security policies
RelatedCurated
Risk assessment & management
§164.308(a)(6)
Security incident procedures
Art. 21(2)(b)
Incident handling
PartialCurated
Incident response & breach notification
§164.308(a)(6)
Security incident procedures
Art. 23
Reporting obligations
PartialCurated
Incident response & breach notification
§164.312(a)(1)
Access control
Art. 21(2)(i)
Access control and asset management
PartialCurated
Access control & identity
§164.312(e)(1)
Transmission security
Art. 21(2)(h)
Cryptography and encryption
EquivalentCurated
Cryptography & data protection
§164.404
Notification to individuals
Art. 21(2)(b)
Incident handling
RelatedCurated
Incident response & breach notification
§164.404
Notification to individuals
Art. 23
Reporting obligations
RelatedCurated
Incident response & breach notification

Mappings marked “Official” derive from standards-body informative references; “Curated” mappings are authored by Cyber Compliance and provided for guidance only.