Security - Authorized Entities, v1.0

Defines privacy requirements related to providing safeguards to ensure only authorized access to sensitive information.

Assessment Step

1
Security - Authorized Entities (Security-AuthorizedEntities)
Does the organization require persons and entities, that participate in a network for the purpose of electronic exchange of sensitive information, to implement administrative, technical, and physical safeguards to protect information, including assuring that only authorized persons and entities and employees of such persons or entities have access to sensitive information?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) that support the assessor's response to this assessment step.
Parameter
Information Typesrequired
ENUM_MULTI : Select the type(s) of sensitive information that apply.
  • PII
  • PHI
  • III
  • IIHI
  • Other

Conformance Criteria (1)

C-1
Persons and entities, that participate in a network for the purpose of electronic exchange of individually identifiable health information, should implement administrative, technical, and physical safeguards to protect information, including assuring that only authorized persons and entities and employees of such persons or entities have access to individually identifiable health information.
Citation
HHS-PSF
Section II, Safeguards