Loading Vaultize
Skip to main content

Compliance/Global/HIPAA

Forty-one sections: eighteen leave evidence in the file.

HIPAA makes covered entities and business associates responsible for protected health information wherever it is created, received, maintained or transmitted. Vaultize adds records that stay with the file.

  • 45 CFR Part 164
  • Security Rule, Subpart C
  • Breach Notification Rule, Subpart D
  • Capability mapping, not legal advice

306(a)(1)Security Rule

Ensure the confidentiality, integrity, and availability of all electronic protected health information the covered entity or business associate creates, receives, maintains, or transmits.

Discover & Classify · Vaultize Seal · Vaultize Secure

  1. A

    General provisions

    0 of 5

    • 102
    • 103
    • 104
    • 105
    • 106
  2. C

    Security Rule

    4 of 9

    • 302
    • 304
    • 306
    • 308
    • 310
    • 312
    • 314
    • 316
    • 318
  3. D

    Breach Notification Rule

    2 of 8

    • 400
    • 402
    • 404
    • 406
    • 408
    • 410
    • 412
    • 414
  4. E

    Privacy Rule

    1 of 19

    • 500
    • 501
    • 502
    • 504
    • 506
    • 508
    • 509
    • 510
    • 512
    • 514
    • 520
    • 522
    • 524
    • 526
    • 528
    • 530
    • 532
    • 534
    • 535
Read against45 CFR Part 164, Security and Privacy45 CFR Part 164 · 3 September 2026
18of 41 sections, in 3 of 4 subparts

The answer in 30 seconds

Vaultize adds file-level records to eighteen provisions across seven sections in three of Part 164's four subparts: the Security Rule's administrative, physical and technical safeguards, the Breach Notification Rule's duty to notify and its burden of proof, and the Privacy Rule's six-year documentation retention. Risk analysis, workforce training, business associate agreements, breach risk assessment, and notification to individuals, the media or the Secretary sit outside a governed file, with the covered entity or business associate.

Part 164 in one view

Four subparts. Forty-one sections. Where file evidence lands.

Part 164 runs in four subparts. Subpart B is reserved and carries no sections. Section numbers on this page drop the “164.” prefix. Subpart summaries are in our words. Select a subpart to see which of its sections a governed file can evidence.

AGENERALPROVISIONSCSECURITYRULEDBREACH NOTIFICATIONRULEEPRIVACY RULE

A

General provisions

Sections 164.102 to 164.106. The statutory basis for the Rules, who they apply to, and how a hybrid entity or affiliated covered entity organises itself under them.

Outcomes the file can evidence

None on this page.

    How Vaultize contributes
    Statutory basis, applicability and organisational structure are matters for counsel. A governed file adds no evidence here.
    Evidence to retain
    None from Vaultize.

    Section by section

    What each provision asks. What the file can answer.

    Wording is quoted from 45 CFR Part 164 as published on the eCFR. Longer provisions are excerpted. Section numbers drop the “164.” prefix. Each row is a capability mapping, not legal advice. Read the Rules and take advice on applicability, roles and risk analysis.

    Using this page

    Where these rows fit in a HIPAA programme.

    The rows above are evidence for the obligations that touch documents. They assume the analysis and process work below is already in place.

    1. 1

      Confirm covered status

      45 CFR 160.103. Whether the organisation is a covered entity or a business associate, and which of its functions bring it into scope.

    2. 2

      Run the risk analysis

      164.308(a)(1)(ii)(A). An accurate and thorough assessment of risks and vulnerabilities to electronic protected health information, before safeguards are selected.

    3. 3

      Apply the technical safeguards

      164.312. Access control, audit controls, integrity, authentication and transmission security. These rows belong here.

      Bring the eighteen rows above as evidence of the technical safeguards and the records that back them.

    4. 4

      Determine and notify on a breach

      Subpart D. Whether an impermissible use or disclosure is a breach, and notification to individuals, the media and the Secretary on the required timelines.

    5. 5

      Retain the documentation

      164.530(j). Policies, procedures and required records, kept for six years from creation or last effect.

    Responsibility boundary

    Controls support compliance. They are not legal advice.

    Vaultize contributes technical safeguards and evidence for electronic protected health information held in documents. It does not determine covered entity or business associate status, carry out the risk analysis, deliver workforce training, agree business associate contracts, decide whether an impermissible use or disclosure is a breach, assess breach risk, or send notifications to individuals, the media or the Secretary. Read the Rules and take qualified advice before relying on this page.

    “Ensure the confidentiality, integrity, and availability of all electronic protected health information the covered entity or business associate creates, receives, maintains, or transmits.”

    45 CFR 164.306(a)(1)

    A practical next step

    Bring one document that carries electronic protected health information.

    We will show which sections the governed document can evidence today. We will name the owner responsible for the rest.

    Request a compliance mapping session