Security Risk Management Workforce Compliance, v1.0

Specifies that a health care related organization must ensure compliance with the requirements in the Security Rule for the Protection of Electronic Protected Health Information by its workforce.
Artifacts might include proof of workforce training procedures or training certifications.

Assessment Step

1
Workforce Compliance (WorkforceCompliance)
Does the covered entity or business associatehave policies and procedures to ensure in accordance with Section 164.306 (Security standards: General rules), compliance with the requirements in Section 164.300-399 (Subpart C - Security Standards for the Protection of Electronic Protected Health Information) by its workforce?
Artifact
A4
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) that support the assessor's response to this assessment step.
Standard: Security management process. Implement policies and procedures to prevent, detect, contain, and correct security violations.

Conformance Criteria (1)

Ensure Workforce Compliance
The covered entity or business associate must, in accordance with Section 164.306 (Security standards: General rules), ensure compliance with the requirements in Section 164.300-399 (Subpart C - Security Standards for the Protection of Electronic Protected Health Information) by its workforce.
Citations
HIPAA-Security-Rule
45 CFR Section 164.308(a)(1)(ii)(B)
HIPAA-Security-Rule
45 CFR Section 164.306(a)(4)