Skip to content

HIPAANIST 800-53 crosswalk

A control-by-control mapping between HIPAA Security Rule (45 CFR Part 164, Subpart C) and NIST SP 800-53 Rev. 5. 9 mappings.

HIPAANIST 800-53RelationshipNotes
§164.308(a)(1)
Security management process
RA-3
Risk assessment
EquivalentOfficial mapping
Évaluation et gestion des risques
§164.308(a)(6)
Security incident procedures
IR-4
Incident handling
EquivalentOfficial mapping
Réponse aux incidents et notification des violations
§164.308(a)(6)
Security incident procedures
IR-6
Incident reporting
PartialCurated
Réponse aux incidents et notification des violations
§164.312(a)(1)
Access control
AC-2
Account management
EquivalentOfficial mapping
Contrôle d'accès et identité
§164.312(b)
Audit controls
AU-2
Event logging
EquivalentOfficial mapping
Journalisation, surveillance et détection
§164.312(e)(1)
Transmission security
SC-8
Transmission confidentiality and integrity
EquivalentOfficial mapping
Cryptographie et protection des données
§164.312(e)(1)
Transmission security
SC-28
Protection of information at rest
EquivalentCurated
Cryptographie et protection des données
§164.404
Notification to individuals
IR-4
Incident handling
RelatedCurated
Réponse aux incidents et notification des violations
§164.404
Notification to individuals
IR-6
Incident reporting
EquivalentOfficial mapping
Réponse aux incidents et notification des violations

Mappings marked “Official” derive from standards-body informative references; “Curated” mappings are authored by Cyber Compliance and provided for guidance only.