Security Incident - Identification Policies, v1.0

Specifies that a health care related organization must have policies to identify suspected or known security incidents.

Assessment Step

1
Policies to Identify (PoliciestoIdentify)
Does the health care provider have policies to identify suspected or known security incidents?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) that support the assessor's response to this assessment step.
A covered entity or business associate must perform these requirements in accordance with Section 164.306 (Security standards: General rules).

Conformance Criteria (1)

Policies to Identify
The organization must have policies to identify suspected or known security incidents.
Citations
HIPAA-Security-Rule
45 CFR Section 164.308(a)(6)(ii)
HIPAA-Security-Rule
45 CFR Section 164.306