Security Incident - Mitigation Procedures, v1.0

Specifies that a health care related organization must implement procedures to mitigate, to the extent practicable, harmful effects of known security incidents.

Assessment Step

1
Procedures to Mitigate (ProcedurestoMitigate)
Does the covered entity or business associate have procedures to mitigate, to the extent practicable, harmful effects of security incidents that are known to the covered entity or business associate?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) that support the assessor's response to this assessment step.
A covered entity or business associate must perform these requirements in accordance with Section 164.306 (Security standards: General rules).

Conformance Criteria (1)

Procedures to Mitigate
The covered entity or business associate must implement procedures to mitigate, to the extent practicable, harmful effects of security incidents that are known to the covered entity or business associate.
Citations
HIPAA-Security-Rule
45 CFR Section 164.308(a)(6)(ii)
HIPAA-Security-Rule
45 CFR Section 164.306