Skip to main content

Control Evidence Mappings

Each control mapping documents what evidence Vallum produces to support your compliance program, what it does not produce, known limitations, and what remains your responsibility.

In Progress (30)

These mappings are under editorial review and will be published after quality verification.

HIPAA-164.308(a)(1): Implement security management process with risk analysis and management

HIPAA · Under review

HIPAA-164.308(a)(2): Designate a security official responsible for security policies and procedures

HIPAA · Under review

HIPAA-164.308(a)(3): Implement workforce security with authorization and clearance procedures

HIPAA · Under review

HIPAA-164.308(a)(4): Implement information access management with access establishment and modification

HIPAA · Under review

HIPAA-164.308(a)(5): Implement security awareness training with periodic security reminders

HIPAA · Under review

HIPAA-164.308(a)(6): Implement security incident procedures with response and reporting

HIPAA · Under review

HIPAA-164.308(a)(7): Implement contingency plan with data backup, disaster recovery, and emergency operations

HIPAA · Under review

HIPAA-164.308(a)(8): Perform periodic technical and non-technical evaluations

HIPAA · Under review

HIPAA-164.310(a)(1): Implement facility access controls with contingency operations and access control

HIPAA · Under review

HIPAA-164.310(a)(2): Implement workstation use policies with appropriate physical safeguards

HIPAA · Under review

HIPAA-164.310(b): Implement workstation security with physical access restrictions

HIPAA · Under review

HIPAA-164.310(c): Implement device and media controls with disposal and re-use procedures

HIPAA · Under review

HIPAA-164.310(d)(1): Implement device and media controls with accountability and data backup

HIPAA · Under review

HIPAA-164.310(d)(2): Implement media movement tracking with data backup and storage

HIPAA · Under review

HIPAA-164.312(a)(1): Implement access control with unique user identification

HIPAA · Under review

HIPAA-164.312(a)(2): Implement emergency access procedures for protected health information

HIPAA · Under review

HIPAA-164.312(b): Implement audit controls with hardware, software, and procedural mechanisms

HIPAA · Under review

HIPAA-164.312(c)(1): Implement integrity controls with mechanisms to authenticate electronic PHI

HIPAA · Under review

HIPAA-164.312(c)(2): Implement integrity controls with electronic mechanisms to corroborate information

HIPAA · Under review

HIPAA-164.312(d): Implement person or entity authentication for PHI access

HIPAA · Under review

HIPAA-164.312(e)(1): Implement transmission security with integrity controls

HIPAA · Under review

HIPAA-164.312(e)(2): Implement transmission security with encryption for PHI in transit

HIPAA · Under review

HIPAA-164.314(a)(1): Implement business associate contracts with satisfactory assurances

HIPAA · Under review

HIPAA-164.314(b)(1): Implement requirements for group health plans with implementation specifications

HIPAA · Under review

HIPAA-164.316(b)(1): Implement documentation requirements with retention and availability

HIPAA · Under review

HIPAA-164.404(a): Implement breach notification procedures with required timelines and content

HIPAA · Under review

HIPAA-164.308(a)(1)(ii)(C): Implement sanctions policy for workforce members who violate security policies

HIPAA · Under review

HIPAA-164.308(a)(1)(ii)(D): Implement information system activity review with regular log analysis

HIPAA · Under review

HIPAA-164.312(a)(2)(iv): Implement encryption and decryption mechanisms for PHI at rest

HIPAA · Under review

HIPAA-164.312(a)(2)(iii): Implement automatic logoff for electronic sessions after inactivity period

HIPAA · Under review