Skip to content

HIPAA Security Rule

The HIPAA Security Rule catalog covers the audit, integrity, access and authentication provisions the gateway can recompute, plus the Breach Notification Rule’s 60-day clock. PHI never enters an action record — identities, headers and bodies are in the never-enters class and content is digest-only — which is usually the first thing a HIPAA reviewer asks about.

Registry id hipaa
Kind regulation
Jurisdiction US
Instrument 45 CFR Part 164 Subpart C; Breach Notification Rule §164.404
Catalog versions 2026-09 from 2005-04-20 (current) — Security Rule as in force
Verified against instrument yes
Tagging key (compliance tags) hipaa
Roles (frameworks.hipaa.role) business_associate, covered_entity
Incident deadline rules standard: 60 days
Retention floors none at classification level
Obligations 7

The six-year documentation floor (§164.316(b)(2)) is expressed as a retention.floor statement scoped to documentation artefacts (reports, declarations, documentation exports), not to every log record; the catalog therefore carries no classification-level retention floor.

Alternative rules: the incident’s classification picks the rule when it names one, else standard applies.

Rule Deadline from became_aware_at
standard 60 days

Deadlines are computed and shown, never enforced — see incidents.

Each obligation lists the statements it is shown against. The basis is one of recomputed, judged, indicator or declared (what the bases mean); the resolver is from the shared library.

164-308-a1-activity-review · 45 CFR §164.308(a)(1)(ii)(D) · applies from 2005-04-20

Records of information system activity (audit logs, access reports) are regularly reviewed. Applies to every system for which the framework is active.

Statement Basis Resolver Does not show
Every action on a resource tagged as holding PHI produced a sealed record. recomputed access.sensitive_reads_recorded {"tag": "hipaa.phi"} Counts actions the tagging engine marked; untagged traffic is not in the denominator.
Liveness, drift and health were evaluated every day. recomputed monitoring.daily_health Shows the monitoring ran; what a human did with its findings is shown in the inbox trail.

164-308-a6-incident-procedures · 45 CFR §164.308(a)(6); Breach Notification Rule §164.404 · applies from 2005-04-20

Security incidents are identified, responded to and documented; breaches of unsecured PHI are notified without unreasonable delay and within 60 days of discovery. Applies to every system for which the framework is active.

What the gateway cannot show: The 60-day breach deadline applies from 2009-09-23 (Breach Notification Rule).

Statement Basis Resolver Does not show
An incident register is kept and no open incident is past its deadline. recomputed incidents.register_exists Shows incidents someone entered; an incident nobody recorded cannot be counted.
Breaches were notified within 60 days of discovery. recomputed incidents.reported_within_deadline {"framework": "hipaa"} Deadlines are computed and shown, not enforced; awareness time is operator-entered.

164-312-a1-access-control · 45 CFR §164.312(a)(1) · applies from 2005-04-20

Access to ePHI is limited to persons or software programs that have been granted access rights. Applies to every system for which the framework is active.

Statement Basis Resolver Does not show
Grants, capability filters and argument policies are bound and sealed. declared authz.least_privilege_declared Whether the grants are the least the system needs is the operator’s judgement, not evaluated.
Every action outside the contract or grant was refused. recomputed authz.out_of_grant_refused Covers actions the gateway observed; the grant itself is a declaration.

164-312-b-audit-controls · 45 CFR §164.312(b) · applies from 2005-04-20

Mechanisms record and examine activity in systems that contain or use ePHI. Applies to every system for which the framework is active.

Statement Basis Resolver Does not show
Every governed action produced a sealed record, including refusals. recomputed records.every_verdict_sealed Integrity is not completeness: covers actions routed through the gateway only; records sealed late by backfill are reported separately.
The tenant log’s tree heads covering the window were countersigned by an independent witness. recomputed records.witnessed A receipt shows inclusion at a tree size, not a witness-observed time; a same-operator witness is self-attested.

164-312-c1-integrity · 45 CFR §164.312(c)(1) · applies from 2005-04-20

ePHI is protected from improper alteration or destruction. Applies to every system for which the framework is active.

What the gateway cannot show: Covers the gateway’s records of access to ePHI; the ePHI stores themselves are outside it.

Statement Basis Resolver Does not show
The audit row chain over the window recomputes intact, or every gap is a declared prune. recomputed records.integrity_verified Detects alteration after the fact; it cannot show that a row was accurate when written.
Record chains are closed and epoch boundaries match the contract history. recomputed records.chain_complete Checks the chains the gateway opened; actions that never reached the gateway cannot be counted.

164-312-d-authentication · 45 CFR §164.312(d) · applies from 2005-04-20

The identity of a person or entity seeking access to ePHI is authenticated. Applies to every system for which the framework is active.

Statement Basis Resolver Does not show
Approvals were decided by authenticated principals (2FA where policy requires it). recomputed authz.human_identity_verified Authentication is of the console account; who sat at the keyboard is not observable.

164-316-b2-documentation-retention · 45 CFR §164.316(b)(2) · applies from 2005-04-20

Documentation required by the Security Rule is retained for six years from creation or last effective date. Applies to every system for which the framework is active.

Statement Basis Resolver Does not show
Documentation artefacts (reports, declarations, documentation exports) are kept for six years. recomputed retention.floor {"floor_days": 2190, "scope": "documentation"} Applies to documentation artefacts only, not to every log record; policies kept outside the platform are not covered.