Control frameworkCompliance & Audit

HITECH policy template

Review this template's scope and control areas. Then, open it in the Verdictan console to adapt and test the configuration for your environment.

Map HITECH controls that extend HIPAA for breach notices, enforcement and direct business-associate liability. The template covers unsecured protected health information, notices to individuals and federal health authorities, encryption and audit evidence. Confirm each legal and operational duty separately.

Use this template as a starting configuration and control map. It does not provide certification, legal advice or a compliance guarantee. Confirm your obligations, adapt the configuration and test every outcome before deployment.

Regions

US

Source references

3 source references

Control areas

6 mapped control areas

Deployment options

Clinical zero-retention, Private cloud

Source frameworks, standards and obligations

Health Information Technology for Economic and Clinical Health Act (42 U.S.C. § 17901 et seq.)HITECH Act § 13402 (Breach Notification)HHS Breach Notification Rule (45 CFR §§ 164.400-414)

Control areas mapped by this template

PHI protection
Breach notification
Audit logging
Access control
Data encryption
Incident response

Deployment options

Clinical zero-retention
Private cloud

Adapt the template in three steps

1

Review the scope

Confirm that the regions, source references, control areas and deployment options fit your use case.

2

Adapt the configuration

Open the template in the Verdictan console. Set its policies, thresholds, routing and review requirements for your environment.

3

Test before deployment

Test each policy outcome. Confirm that allowed, redacted, blocked and reviewed requests behave as expected.