Skip to content

Essential EightHIPAA crosswalk

A control-by-control mapping between ACSC Essential Eight and HIPAA Security Rule (45 CFR Part 164, Subpart C). 2 mappings.

Essential EightHIPAARelationshipNotes
E8-3
Multi-factor authentication
§164.312(a)(1)
Access control
PartialCurated
Access control & identity
E8-4
Restrict administrative privileges
§164.312(a)(1)
Access control
PartialCurated
Access control & identity

Mappings marked “Official” derive from standards-body informative references; “Curated” mappings are authored by Cyber Compliance and provided for guidance only.