Accountability - Notification of Violations, v1.0

Defines privacy requirements related to monitoring for providing notice of privacy violations or security breaches.

Assessment Step

1
Accountability - Notification Of Violations (Accountability-NotificationOfViolations)
Does the organization require persons and entities, that participate in a network for the purpose of electronic exchange of sensitive information, to address monitoring including notice to individuals of privacy violations or security breaches that pose substantial risk of harm to such individuals?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) that support the assessor's response to this assessment step.
Parameter
Information Typesrequired
ENUM_MULTI : Select the type(s) of sensitive information that apply.
  • PII
  • PHI
  • III
  • IIHI
  • Other

Conformance Criteria (1)

C-1
Persons and entities, that participate in a network for the purpose of electronic exchange of individually identifiable health information, should address monitoring including notice to individuals of privacy violations or security breaches that pose substantial risk of harm to such individuals.
Citation
HHS-PSF
Section II, Accountability