Compliance/Global/HIPAA
Forty-one sections: eighteen leave evidence in the file.
HIPAA makes covered entities and business associates responsible for protected health information wherever it is created, received, maintained or transmitted. Vaultize adds records that stay with the file.
- 45 CFR Part 164
- Security Rule, Subpart C
- Breach Notification Rule, Subpart D
- Capability mapping, not legal advice
306(a)(1)Security Rule
Ensure the confidentiality, integrity, and availability of all electronic protected health information the covered entity or business associate creates, receives, maintains, or transmits.
Discover & Classify · Vaultize Seal · Vaultize Secure
A
General provisions
0 of 5
- 102
- 103
- 104
- 105
- 106
C
Security Rule
4 of 9
- 302
- 304
- 306
- 308
- 310
- 312
- 314
- 316
- 318
D
Breach Notification Rule
2 of 8
- 400
- 402
- 404
- 406
- 408
- 410
- 412
- 414
E
Privacy Rule
1 of 19
- 500
- 501
- 502
- 504
- 506
- 508
- 509
- 510
- 512
- 514
- 520
- 522
- 524
- 526
- 528
- 530
- 532
- 534
- 535
The answer in 30 seconds
Vaultize adds file-level records to eighteen provisions across seven sections in three of Part 164's four subparts: the Security Rule's administrative, physical and technical safeguards, the Breach Notification Rule's duty to notify and its burden of proof, and the Privacy Rule's six-year documentation retention. Risk analysis, workforce training, business associate agreements, breach risk assessment, and notification to individuals, the media or the Secretary sit outside a governed file, with the covered entity or business associate.
Part 164 in one view
Four subparts. Forty-one sections. Where file evidence lands.
Part 164 runs in four subparts. Subpart B is reserved and carries no sections. Section numbers on this page drop the “164.” prefix. Subpart summaries are in our words. Select a subpart to see which of its sections a governed file can evidence.
A
General provisions
Sections 164.102 to 164.106. The statutory basis for the Rules, who they apply to, and how a hybrid entity or affiliated covered entity organises itself under them.
Outcomes the file can evidence
None on this page.
- How Vaultize contributes
- Statutory basis, applicability and organisational structure are matters for counsel. A governed file adds no evidence here.
- Evidence to retain
- None from Vaultize.
Section by section
What each provision asks. What the file can answer.
Wording is quoted from 45 CFR Part 164 as published on the eCFR. Longer provisions are excerpted. Section numbers drop the “164.” prefix. Each row is a capability mapping, not legal advice. Read the Rules and take advice on applicability, roles and risk analysis.
Using this page
Where these rows fit in a HIPAA programme.
The rows above are evidence for the obligations that touch documents. They assume the analysis and process work below is already in place.
- 1
Confirm covered status
45 CFR 160.103. Whether the organisation is a covered entity or a business associate, and which of its functions bring it into scope.
- 2
Run the risk analysis
164.308(a)(1)(ii)(A). An accurate and thorough assessment of risks and vulnerabilities to electronic protected health information, before safeguards are selected.
- 3
Apply the technical safeguards
164.312. Access control, audit controls, integrity, authentication and transmission security. These rows belong here.
Bring the eighteen rows above as evidence of the technical safeguards and the records that back them.
- 4
Determine and notify on a breach
Subpart D. Whether an impermissible use or disclosure is a breach, and notification to individuals, the media and the Secretary on the required timelines.
- 5
Retain the documentation
164.530(j). Policies, procedures and required records, kept for six years from creation or last effect.
Responsibility boundary
Controls support compliance. They are not legal advice.
Vaultize contributes technical safeguards and evidence for electronic protected health information held in documents. It does not determine covered entity or business associate status, carry out the risk analysis, deliver workforce training, agree business associate contracts, decide whether an impermissible use or disclosure is a breach, assess breach risk, or send notifications to individuals, the media or the Secretary. Read the Rules and take qualified advice before relying on this page.
“Ensure the confidentiality, integrity, and availability of all electronic protected health information the covered entity or business associate creates, receives, maintains, or transmits.”
45 CFR 164.306(a)(1)
Official references
Read the source before relying on the mapping.
Section wording comes from the first item. The second is HHS guidance on the Security Rule.
- 45 CFR Part 164, Security and Privacy (eCFR)Displayed by the Electronic Code of Federal Regulations as up to date as of 3 September 2026, title 45 last amended 31 August 2026. Every section quoted on this page is from it.
- HHS: The Security RuleThe Department of Health and Human Services' guidance on the Security Rule, including risk analysis and the addressable versus required distinction.
A practical next step
Bring one document that carries electronic protected health information.
We will show which sections the governed document can evidence today. We will name the owner responsible for the rest.
