GAISSF to HIPAA Crosswalk
Public crosswalk publication mapping GAISSF v1.0 to HIPAA, with scope, method, limitations and traceability.
Executive Summary
This crosswalk maps all 59 GAISSF controls to operationally material provisions of the HIPAA Privacy, Security, Breach Notification, and Enforcement Rules. It contains 163 forward mapping records and a reverse coverage register for 39 provisions.
The mapping supports gap analysis and evidence reuse. It does not determine whether an organization is a covered entity or business associate, whether information is PHI or ePHI, whether a use or disclosure is permitted, or whether HIPAA compliance has been achieved.
1. Source Baseline
GAISSF-NOR-001 v1.0 and GAISSF-NOR-004 v1.0, 59-control baseline.
45 CFR Parts 160 and 164, current enforceable HIPAA Rules verified 29 June 2026.
HHS OCR guidance is informative and subordinate to the regulations.
The proposed HIPAA Security Rule modernization is excluded from the normative mapping because it is not final.
2. Methodology
Mappings compare control outcomes, scope, evidence, responsible actors, and operating effect. Relationship codes are SP (strong partial), P (partial), S (supporting), C (contextual), N (no material mapping), O (outside scope), and U (unable to determine). No mapping is treated as legal equivalence.
3. Rule-Level Coverage
| HIPAA provision | Title | Rule group | Mapped GAISSF controls | Coverage |
|---|---|---|---|---|
| 160.103 | Definitions | General Provisions | 0 | Not Addressed |
| 160.203 | General rule and exceptions | Preemption | 0 | Not Addressed |
| 164.105 | Organizational requirements | General Requirements | 0 | Not Addressed |
| 164.306 | Security standards: general rules | Security Rule | 0 | Not Addressed |
| 164.308(a)(1) | Security management process | Administrative Safeguards | 24 | Partially Addressed |
| 164.308(a)(2) | Assigned security responsibility | Administrative Safeguards | 7 | Partially Addressed |
| 164.308(a)(3) | Workforce security | Administrative Safeguards | 6 | Partially Addressed |
| 164.308(a)(4) | Information access management | Administrative Safeguards | 0 | Not Addressed |
| 164.308(a)(5) | Security awareness and training | Administrative Safeguards | 3 | Partially Addressed |
| 164.308(a)(6) | Security incident procedures | Administrative Safeguards | 10 | Partially Addressed |
| 164.308(a)(7) | Contingency plan | Administrative Safeguards | 1 | Partially Addressed |
| 164.308(a)(8) | Evaluation | Administrative Safeguards | 3 | Partially Addressed |
| 164.308(b) | Business associate contracts and arrangements | Administrative Safeguards | 8 | Partially Addressed |
| 164.310(a) | Facility access controls | Physical Safeguards | 7 | Partially Addressed |
| 164.310(b) | Workstation use | Physical Safeguards | 6 | Partially Addressed |
| 164.310(c) | Workstation security | Physical Safeguards | 0 | Not Addressed |
| 164.310(d) | Device and media controls | Physical Safeguards | 1 | Partially Addressed |
| 164.312(a) | Access control | Technical Safeguards | 1 | Partially Addressed |
| 164.312(b) | Audit controls | Technical Safeguards | 2 | Partially Addressed |
| 164.312(c) | Integrity | Technical Safeguards | 16 | Partially Addressed |
| 164.312(d) | Person or entity authentication | Technical Safeguards | 1 | Partially Addressed |
| 164.312(e) | Transmission security | Technical Safeguards | 1 | Partially Addressed |
| 164.314 | Organizational requirements | Security Rule | 0 | Not Addressed |
| 164.316 | Policies, procedures and documentation | Security Rule | 10 | Partially Addressed |
| 164.502 | Uses and disclosures of PHI: general rules | Privacy Rule | 6 | Partially Addressed |
| 164.504 | Organizational requirements | Privacy Rule | 11 | Partially Addressed |
| 164.506 | Uses and disclosures for treatment, payment, operations | Privacy Rule | 0 | Not Addressed |
| 164.508 | Uses and disclosures requiring authorization | Privacy Rule | 0 | Not Addressed |
| 164.514 | Other requirements relating to uses and disclosures | Privacy Rule | 1 | Partially Addressed |
| 164.520 | Notice of privacy practices | Privacy Rule | 0 | Not Addressed |
| 164.522 | Rights to request privacy protection | Privacy Rule | 0 | Not Addressed |
| 164.524 | Access of individuals to PHI | Privacy Rule | 0 | Not Addressed |
| 164.526 | Amendment of PHI | Privacy Rule | 16 | Partially Addressed |
| 164.528 | Accounting of disclosures | Privacy Rule | 0 | Not Addressed |
| 164.530 | Administrative requirements | Privacy Rule | 13 | Partially Addressed |
| 164.532 | Transition provisions | Privacy Rule | 0 | Not Addressed |
| 164.534 | Compliance dates | Privacy Rule | 0 | Not Addressed |
| 164.400-414 | Breach notification requirements | Breach Notification Rule | 4 | Partially Addressed |
| 160.300-552 | Compliance, investigations and penalties | Enforcement Rule | 5 | Partially Addressed |
4. GAISSF-to-HIPAA Mapping Register
| GAISSF | Control title | HIPAA | Provision | Rel. | Confidence | Rationale / residual gap |
|---|---|---|---|---|---|---|
| D1-CTL-01 | DATASET PROVENANCE & POISONING PREVENTION | 164.526 | Amendment of PHI | P | Medium | D1-CTL-01 supports the security, governance, privacy, resilience, or evidence objective represented by 164.526. The relationship is functional, not legal equivalence. Entity status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, and legal determinations remain HIPAA-specific. |
| D1-CTL-01 | DATASET PROVENANCE & POISONING PREVENTION | 164.312(c) | Integrity | P | Medium | D1-CTL-01 supports the security, governance, privacy, resilience, or evidence objective represented by 164.312(c). The relationship is functional, not legal equivalence. Entity status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, and legal determinations remain HIPAA-specific. |
| D1-CTL-01 | DATASET PROVENANCE & POISONING PREVENTION | 164.310(d) | Device and media controls | P | Medium | D1-CTL-01 supports the security, governance, privacy, resilience, or evidence objective represented by 164.310(d). The relationship is functional, not legal equivalence. Entity status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, and legal determinations remain HIPAA-specific. |
| D1-CTL-01 | DATASET PROVENANCE & POISONING PREVENTION | 164.308(a)(1) | Security management process | P | Medium | D1-CTL-01 supports the security, governance, privacy, resilience, or evidence objective represented by 164.308(a)(1). The relationship is functional, not legal equivalence. Entity status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, and legal determinations remain HIPAA-specific. |
| D1-CTL-02 | MODEL EXTRACTION RESISTANCE | 164.526 | Amendment of PHI | P | Medium | D1-CTL-02 supports the security, governance, privacy, resilience, or evidence objective represented by 164.526. The relationship is functional, not legal equivalence. Entity status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, and legal determinations remain HIPAA-specific. |
| D1-CTL-02 | MODEL EXTRACTION RESISTANCE | 164.312(c) | Integrity | P | Medium | D1-CTL-02 supports the security, governance, privacy, resilience, or evidence objective represented by 164.312(c). The relationship is functional, not legal equivalence. Entity status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, and legal determinations remain HIPAA-specific. |
5. Implementation Guidance
Confirm regulated-entity status and identify all PHI/ePHI flows before applying the mapping.
Treat required and addressable Security Rule implementation specifications according to the regulatory text and documented risk analysis.
Maintain HIPAA-specific policies, business associate agreements, privacy notices, rights workflows, breach assessments, and documentation.
Validate state-law, FTC, substance-use-disorder, genetic-information, and sector-specific obligations separately.
6. Notably Absent
No HHS endorsement; no HIPAA certification; no automatic safe harbor; no determination of covered-entity or business-associate status; no proof that all PHI uses and disclosures are lawful; no substitute for a Security Risk Analysis; no incorporation of the unfinalized proposed Security Rule.
7. Limitations
Mapping does not establish HIPAA compliance.
Covered entity or business associate status is not determined.
PHI/ePHI scope and permitted uses/disclosures require legal analysis.
State health privacy laws may impose additional duties.
The proposed Security Rule modernization is not treated as binding.
© 2026 ODA3 Pvt Ltd. Published by ODA3 Institute.