Security Risk Management Against Disclosures, v1.0

Specifies that a health care related organization must protect against any reasonably anticipated uses or disclosures of protected health information that are not allowed under the Privacy Rule.

Assessment Step

1
Uses or Disclosures (UsesorDisclosures)
Does the covered entity or business associate have policies and procedures to protect, in accordance with Section 164.306 (Security standards: General rules), against any reasonably anticipated uses or disclosures of such information that are not permitted or required under Section 164.500-599 (Privacy of Individually Identifiable Health Information, i.e., subpart E of this part)?
Artifact
A3
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) that support the assessor's response to this assessment step.
Standard: Security management process. Implement policies and procedures to prevent, detect, contain, and correct security violations.

Conformance Criteria (1)

Protect Against Disclosures
The covered entity or business associate must, in accordance with Section 164.306 (Security standards: General rules), protect against any reasonably anticipated uses or disclosures of such information that are not permitted or required under Section 164.500-599 (Privacy of Individually Identifiable Health Information).
Citations
HIPAA-Security-Rule
45 CFR Section 164.308(a)(1)(ii)(B)
HIPAA-Security-Rule
45 CFR Section 164.306(a)(3)
HIPAA-Security-Rule
45 CFR Section 164.500-599 (aka. subpart E)