| HIPAA Security Rule (45 CFR Part 164) |
All covered entities and business associates handling ePHI — required regardless of organization size. Includes all Greater Washington physician practices, behavioral health providers, dental offices, billing companies, and specialty clinics that transmit health information electronically. |
Security Risk Analysis mapped to 164.308(a)(1); technical safeguard implementation (access control, encryption, audit logging, automatic logoff); workforce training documentation; BAA management for all vendors; incident response planning per 164.308(a)(6) |
Annual SRA report, 164.308-164.312 evidence folder, BAA inventory and executed agreements, training completion records, breach response runbook |
| HIPAA Privacy Rule and Breach Notification Rule |
All covered entities — governs use and disclosure of all PHI (not just electronic), patient rights, and breach notification obligations to HHS OCR and affected individuals. Breach notification to HHS required within 60 days of discovery for breaches affecting 500 or more individuals. |
Breach risk assessment workflow applying OCR’s four-factor test; breach notification letter preparation for affected individuals; HHS OCR breach portal reporting support; minimum necessary access policy documentation |
Breach notification templates for individuals and HHS OCR, four-factor risk assessment documentation, minimum necessary access policies |
| Maryland Breach Law (Md. Code, Com. Law 14-3504) |
Any entity owning or licensing computerized data including personal information of Maryland residents — covers every Greater Washington healthcare organization. Requires notification “without unreasonable delay,” not a fixed number of days. AG notification required for every reportable breach regardless of size. |
Incident response plan with Maryland-specific notification workflow; notification letter preparation for affected residents; Maryland AG Computer Crime Section notification package; breach response coordination covering both HIPAA and Maryland timelines simultaneously |
Incident response plan with dual-track notification workflow, AG notification package template, breach response runbook aligned to both state and federal timelines |
| HHS OCR Risk Analysis Requirement (45 CFR 164.308(a)(1)) |
Every HIPAA covered entity and business associate — required annually or upon significant operational change. OCR’s October 2024 enforcement initiative specifically targets organizations that have failed to conduct adequate, documented risk analyses. This is the most commonly cited missing control in OCR enforcement actions. |
Comprehensive SRA covering all ePHI locations, threat and vulnerability assessment, likelihood and impact ratings, existing safeguard evaluation, and risk management plan — specific to each Greater Washington organization’s environment, not a generic template |
Documented SRA report meeting OCR’s guidance requirements, risk management plan with prioritized remediation items, annual SRA refresh schedule |
| Cyber Insurance Requirements |
Every Greater Washington healthcare organization carrying cyber liability coverage — or seeking renewal at standard premiums. Carriers now require documented MFA, EDR deployment, tested backups, and security awareness training as conditions of coverage and claim payment. |
MFA implementation and documentation, EDR deployment (SentinelOne), tested backup with recovery evidence, patch management documentation, security awareness training records — all maintained in a format that survives post-claim carrier audit |
Controls attestation package with evidence documentation, renewal-ready questionnaire support, gap remediation for coverage requirements |
| 42 CFR Part 2 (Substance Use Disorder Records) |
Behavioral health practices and treatment providers handling substance use disorder records — applies in addition to HIPAA with stricter confidentiality requirements and patient consent rules. Relevant for Greater Washington providers serving the region’s veteran and active-duty military population. |
Separate access control architecture for SUD records, logical segregation from general PHI, consent tracking implementation, staff training on Part 2 vs. HIPAA distinction, prohibition on re-disclosure enforcement |
Compliant record segregation architecture, consent audit trail documentation, Part 2 policy documentation, workforce training records covering both frameworks |