HIPAA Security Rule
The HIPAA Security Rule catalog covers the audit, integrity, access and authentication provisions the gateway can recompute, plus the Breach Notification Rule’s 60-day clock. PHI never enters an action record — identities, headers and bodies are in the never-enters class and content is digest-only — which is usually the first thing a HIPAA reviewer asks about.
| Registry id | hipaa |
| Kind | regulation |
| Jurisdiction | US |
| Instrument | 45 CFR Part 164 Subpart C; Breach Notification Rule §164.404 |
| Catalog versions | 2026-09 from 2005-04-20 (current) — Security Rule as in force |
| Verified against instrument | yes |
| Tagging key (compliance tags) | hipaa |
Roles (frameworks.hipaa.role) |
business_associate, covered_entity |
| Incident deadline rules | standard: 60 days |
| Retention floors | none at classification level |
| Obligations | 7 |
The six-year documentation floor (§164.316(b)(2)) is expressed as a retention.floor statement scoped to documentation artefacts (reports, declarations, documentation exports), not to every log record; the catalog therefore carries no classification-level retention floor.
Deadline rules
Section titled “Deadline rules”Alternative rules: the incident’s classification picks the rule when it names one, else standard applies.
| Rule | Deadline from became_aware_at |
|---|---|
standard |
60 days |
Deadlines are computed and shown, never enforced — see incidents.
Obligations and their evidence
Section titled “Obligations and their evidence”Each obligation lists the statements it is shown against. The basis is one of recomputed, judged, indicator or declared (what the bases mean); the resolver is from the shared library.
Information system activity review
Section titled “Information system activity review”164-308-a1-activity-review · 45 CFR §164.308(a)(1)(ii)(D) · applies from 2005-04-20
Records of information system activity (audit logs, access reports) are regularly reviewed. Applies to every system for which the framework is active.
| Statement | Basis | Resolver | Does not show |
|---|---|---|---|
| Every action on a resource tagged as holding PHI produced a sealed record. | recomputed | access.sensitive_reads_recorded {"tag": "hipaa.phi"} |
Counts actions the tagging engine marked; untagged traffic is not in the denominator. |
| Liveness, drift and health were evaluated every day. | recomputed | monitoring.daily_health |
Shows the monitoring ran; what a human did with its findings is shown in the inbox trail. |
Security incident procedures
Section titled “Security incident procedures”164-308-a6-incident-procedures · 45 CFR §164.308(a)(6); Breach Notification Rule §164.404 · applies from 2005-04-20
Security incidents are identified, responded to and documented; breaches of unsecured PHI are notified without unreasonable delay and within 60 days of discovery. Applies to every system for which the framework is active.
What the gateway cannot show: The 60-day breach deadline applies from 2009-09-23 (Breach Notification Rule).
| Statement | Basis | Resolver | Does not show |
|---|---|---|---|
| An incident register is kept and no open incident is past its deadline. | recomputed | incidents.register_exists |
Shows incidents someone entered; an incident nobody recorded cannot be counted. |
| Breaches were notified within 60 days of discovery. | recomputed | incidents.reported_within_deadline {"framework": "hipaa"} |
Deadlines are computed and shown, not enforced; awareness time is operator-entered. |
Access control
Section titled “Access control”164-312-a1-access-control · 45 CFR §164.312(a)(1) · applies from 2005-04-20
Access to ePHI is limited to persons or software programs that have been granted access rights. Applies to every system for which the framework is active.
| Statement | Basis | Resolver | Does not show |
|---|---|---|---|
| Grants, capability filters and argument policies are bound and sealed. | declared | authz.least_privilege_declared |
Whether the grants are the least the system needs is the operator’s judgement, not evaluated. |
| Every action outside the contract or grant was refused. | recomputed | authz.out_of_grant_refused |
Covers actions the gateway observed; the grant itself is a declaration. |
Audit controls
Section titled “Audit controls”164-312-b-audit-controls · 45 CFR §164.312(b) · applies from 2005-04-20
Mechanisms record and examine activity in systems that contain or use ePHI. Applies to every system for which the framework is active.
| Statement | Basis | Resolver | Does not show |
|---|---|---|---|
| Every governed action produced a sealed record, including refusals. | recomputed | records.every_verdict_sealed |
Integrity is not completeness: covers actions routed through the gateway only; records sealed late by backfill are reported separately. |
| The tenant log’s tree heads covering the window were countersigned by an independent witness. | recomputed | records.witnessed |
A receipt shows inclusion at a tree size, not a witness-observed time; a same-operator witness is self-attested. |
Integrity
Section titled “Integrity”164-312-c1-integrity · 45 CFR §164.312(c)(1) · applies from 2005-04-20
ePHI is protected from improper alteration or destruction. Applies to every system for which the framework is active.
What the gateway cannot show: Covers the gateway’s records of access to ePHI; the ePHI stores themselves are outside it.
| Statement | Basis | Resolver | Does not show |
|---|---|---|---|
| The audit row chain over the window recomputes intact, or every gap is a declared prune. | recomputed | records.integrity_verified |
Detects alteration after the fact; it cannot show that a row was accurate when written. |
| Record chains are closed and epoch boundaries match the contract history. | recomputed | records.chain_complete |
Checks the chains the gateway opened; actions that never reached the gateway cannot be counted. |
Person or entity authentication
Section titled “Person or entity authentication”164-312-d-authentication · 45 CFR §164.312(d) · applies from 2005-04-20
The identity of a person or entity seeking access to ePHI is authenticated. Applies to every system for which the framework is active.
| Statement | Basis | Resolver | Does not show |
|---|---|---|---|
| Approvals were decided by authenticated principals (2FA where policy requires it). | recomputed | authz.human_identity_verified |
Authentication is of the console account; who sat at the keyboard is not observable. |
Documentation retention (six years)
Section titled “Documentation retention (six years)”164-316-b2-documentation-retention · 45 CFR §164.316(b)(2) · applies from 2005-04-20
Documentation required by the Security Rule is retained for six years from creation or last effective date. Applies to every system for which the framework is active.
| Statement | Basis | Resolver | Does not show |
|---|---|---|---|
| Documentation artefacts (reports, declarations, documentation exports) are kept for six years. | recomputed | retention.floor {"floor_days": 2190, "scope": "documentation"} |
Applies to documentation artefacts only, not to every log record; policies kept outside the platform are not covered. |
Related
Section titled “Related”- Framework registry & evidence bases — how catalogs, resolvers and the version in force work
- The Compliance console — the Obligations matrix for this framework
- Incidents, reports & documentation

