General requirements and flexibility of approach
Summary
Covered entities and business associates must ensure the confidentiality, integrity, and availability of all ePHI they create, receive, maintain, or transmit, protecting against reasonably anticipated threats and impermissible uses/disclosures.
general requirementssecurity rule
Read the full official text: https://www.law.cornell.edu/cfr/text/45/164.306
Track HIPAA section 164.306 as evidence
eurocompliant maps this obligation to a checklist task and the evidence that satisfies it, alongside every other framework you follow.
Start free trial