Security Risk Management for Confidentiality, v1.0

Specifies that a health care related organization must ensure the confidentiality, integrity, and availability of all electronic protected health information the organization handles.
The artifacts for the assessment steps should include policy and/or procedure documents or excerpts that show the criteria being satisfied.

Assessment Step

1
Confidentiality Integrity and Availability (ConfidentialityIntegrityandAvailability)
Does the covered entity or business associate ensure, in accordance with Section 164.306 (Security standards: General rules), the confidentiality, integrity, and availability of all electronic protected health information the organization creates, receives, maintains, or transmits?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) that support the assessor's response to this assessment step.
The organization must implement security measures sufficient to reduce risks and vulnerabilities to a reasonable and appropriate level to comply with Section 164.306(a).

Conformance Criteria (1)

Ensure Confidentiality
The covered entity or business associate must, in accordance with Section 164.306 (Security standards: General rules), ensure the confidentiality, integrity, and availability of all electronic protected health information the organization creates, receives, maintains, or transmits.
Citations
HIPAA-Security-Rule
45 CFR Section 164.308(a)(1)(ii)(B)
HIPAA-Security-Rule
45 CFR Section 164.306(a)(1)