Control Evidence Mappings
Each control mapping documents what evidence Vallum produces to support your compliance program, what it does not produce, known limitations, and what remains your responsibility.
In Progress (30)
These mappings are under editorial review and will be published after quality verification.
HIPAA-164.308(a)(1): Implement security management process with risk analysis and management
HIPAA · Under review
HIPAA-164.308(a)(2): Designate a security official responsible for security policies and procedures
HIPAA · Under review
HIPAA-164.308(a)(3): Implement workforce security with authorization and clearance procedures
HIPAA · Under review
HIPAA-164.308(a)(4): Implement information access management with access establishment and modification
HIPAA · Under review
HIPAA-164.308(a)(5): Implement security awareness training with periodic security reminders
HIPAA · Under review
HIPAA-164.308(a)(6): Implement security incident procedures with response and reporting
HIPAA · Under review
HIPAA-164.308(a)(7): Implement contingency plan with data backup, disaster recovery, and emergency operations
HIPAA · Under review
HIPAA-164.308(a)(8): Perform periodic technical and non-technical evaluations
HIPAA · Under review
HIPAA-164.310(a)(1): Implement facility access controls with contingency operations and access control
HIPAA · Under review
HIPAA-164.310(a)(2): Implement workstation use policies with appropriate physical safeguards
HIPAA · Under review
HIPAA-164.310(b): Implement workstation security with physical access restrictions
HIPAA · Under review
HIPAA-164.310(c): Implement device and media controls with disposal and re-use procedures
HIPAA · Under review
HIPAA-164.310(d)(1): Implement device and media controls with accountability and data backup
HIPAA · Under review
HIPAA-164.310(d)(2): Implement media movement tracking with data backup and storage
HIPAA · Under review
HIPAA-164.312(a)(1): Implement access control with unique user identification
HIPAA · Under review
HIPAA-164.312(a)(2): Implement emergency access procedures for protected health information
HIPAA · Under review
HIPAA-164.312(b): Implement audit controls with hardware, software, and procedural mechanisms
HIPAA · Under review
HIPAA-164.312(c)(1): Implement integrity controls with mechanisms to authenticate electronic PHI
HIPAA · Under review
HIPAA-164.312(c)(2): Implement integrity controls with electronic mechanisms to corroborate information
HIPAA · Under review
HIPAA-164.312(d): Implement person or entity authentication for PHI access
HIPAA · Under review
HIPAA-164.312(e)(1): Implement transmission security with integrity controls
HIPAA · Under review
HIPAA-164.312(e)(2): Implement transmission security with encryption for PHI in transit
HIPAA · Under review
HIPAA-164.314(a)(1): Implement business associate contracts with satisfactory assurances
HIPAA · Under review
HIPAA-164.314(b)(1): Implement requirements for group health plans with implementation specifications
HIPAA · Under review
HIPAA-164.316(b)(1): Implement documentation requirements with retention and availability
HIPAA · Under review
HIPAA-164.404(a): Implement breach notification procedures with required timelines and content
HIPAA · Under review
HIPAA-164.308(a)(1)(ii)(C): Implement sanctions policy for workforce members who violate security policies
HIPAA · Under review
HIPAA-164.308(a)(1)(ii)(D): Implement information system activity review with regular log analysis
HIPAA · Under review
HIPAA-164.312(a)(2)(iv): Implement encryption and decryption mechanisms for PHI at rest
HIPAA · Under review
HIPAA-164.312(a)(2)(iii): Implement automatic logoff for electronic sessions after inactivity period
HIPAA · Under review