CROSSWALKS

GAISSF to HIPAA Crosswalk

Public crosswalk publication mapping GAISSF v1.0 to HIPAA, with scope, method, limitations and traceability.

Executive Summary

This crosswalk maps all 59 GAISSF controls to operationally material provisions of the HIPAA Privacy, Security, Breach Notification, and Enforcement Rules. It contains 163 forward mapping records and a reverse coverage register for 39 provisions.

The mapping supports gap analysis and evidence reuse. It does not determine whether an organization is a covered entity or business associate, whether information is PHI or ePHI, whether a use or disclosure is permitted, or whether HIPAA compliance has been achieved.

1. Source Baseline

  • GAISSF-NOR-001 v1.0 and GAISSF-NOR-004 v1.0, 59-control baseline.

  • 45 CFR Parts 160 and 164, current enforceable HIPAA Rules verified 29 June 2026.

  • HHS OCR guidance is informative and subordinate to the regulations.

  • The proposed HIPAA Security Rule modernization is excluded from the normative mapping because it is not final.

2. Methodology

Mappings compare control outcomes, scope, evidence, responsible actors, and operating effect. Relationship codes are SP (strong partial), P (partial), S (supporting), C (contextual), N (no material mapping), O (outside scope), and U (unable to determine). No mapping is treated as legal equivalence.

3. Rule-Level Coverage

HIPAA provision Title Rule group Mapped GAISSF controls Coverage
160.103 Definitions General Provisions 0 Not Addressed
160.203 General rule and exceptions Preemption 0 Not Addressed
164.105 Organizational requirements General Requirements 0 Not Addressed
164.306 Security standards: general rules Security Rule 0 Not Addressed
164.308(a)(1) Security management process Administrative Safeguards 24 Partially Addressed
164.308(a)(2) Assigned security responsibility Administrative Safeguards 7 Partially Addressed
164.308(a)(3) Workforce security Administrative Safeguards 6 Partially Addressed
164.308(a)(4) Information access management Administrative Safeguards 0 Not Addressed
164.308(a)(5) Security awareness and training Administrative Safeguards 3 Partially Addressed
164.308(a)(6) Security incident procedures Administrative Safeguards 10 Partially Addressed
164.308(a)(7) Contingency plan Administrative Safeguards 1 Partially Addressed
164.308(a)(8) Evaluation Administrative Safeguards 3 Partially Addressed
164.308(b) Business associate contracts and arrangements Administrative Safeguards 8 Partially Addressed
164.310(a) Facility access controls Physical Safeguards 7 Partially Addressed
164.310(b) Workstation use Physical Safeguards 6 Partially Addressed
164.310(c) Workstation security Physical Safeguards 0 Not Addressed
164.310(d) Device and media controls Physical Safeguards 1 Partially Addressed
164.312(a) Access control Technical Safeguards 1 Partially Addressed
164.312(b) Audit controls Technical Safeguards 2 Partially Addressed
164.312(c) Integrity Technical Safeguards 16 Partially Addressed
164.312(d) Person or entity authentication Technical Safeguards 1 Partially Addressed
164.312(e) Transmission security Technical Safeguards 1 Partially Addressed
164.314 Organizational requirements Security Rule 0 Not Addressed
164.316 Policies, procedures and documentation Security Rule 10 Partially Addressed
164.502 Uses and disclosures of PHI: general rules Privacy Rule 6 Partially Addressed
164.504 Organizational requirements Privacy Rule 11 Partially Addressed
164.506 Uses and disclosures for treatment, payment, operations Privacy Rule 0 Not Addressed
164.508 Uses and disclosures requiring authorization Privacy Rule 0 Not Addressed
164.514 Other requirements relating to uses and disclosures Privacy Rule 1 Partially Addressed
164.520 Notice of privacy practices Privacy Rule 0 Not Addressed
164.522 Rights to request privacy protection Privacy Rule 0 Not Addressed
164.524 Access of individuals to PHI Privacy Rule 0 Not Addressed
164.526 Amendment of PHI Privacy Rule 16 Partially Addressed
164.528 Accounting of disclosures Privacy Rule 0 Not Addressed
164.530 Administrative requirements Privacy Rule 13 Partially Addressed
164.532 Transition provisions Privacy Rule 0 Not Addressed
164.534 Compliance dates Privacy Rule 0 Not Addressed
164.400-414 Breach notification requirements Breach Notification Rule 4 Partially Addressed
160.300-552 Compliance, investigations and penalties Enforcement Rule 5 Partially Addressed

4. GAISSF-to-HIPAA Mapping Register

Controlled Publication. The table below shows a representative sample (6 of 163 total records). The complete control-by-control mapping register — full requirement-level traceability, evidence guidance and machine-readable export — is a Controlled Publication. Contact ODA3 Institute for access.
GAISSF Control title HIPAA Provision Rel. Confidence Rationale / residual gap
D1-CTL-01 DATASET PROVENANCE & POISONING PREVENTION 164.526 Amendment of PHI P Medium D1-CTL-01 supports the security, governance, privacy, resilience, or evidence objective represented by 164.526. The relationship is functional, not legal equivalence. Entity status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, and legal determinations remain HIPAA-specific.
D1-CTL-01 DATASET PROVENANCE & POISONING PREVENTION 164.312(c) Integrity P Medium D1-CTL-01 supports the security, governance, privacy, resilience, or evidence objective represented by 164.312(c). The relationship is functional, not legal equivalence. Entity status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, and legal determinations remain HIPAA-specific.
D1-CTL-01 DATASET PROVENANCE & POISONING PREVENTION 164.310(d) Device and media controls P Medium D1-CTL-01 supports the security, governance, privacy, resilience, or evidence objective represented by 164.310(d). The relationship is functional, not legal equivalence. Entity status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, and legal determinations remain HIPAA-specific.
D1-CTL-01 DATASET PROVENANCE & POISONING PREVENTION 164.308(a)(1) Security management process P Medium D1-CTL-01 supports the security, governance, privacy, resilience, or evidence objective represented by 164.308(a)(1). The relationship is functional, not legal equivalence. Entity status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, and legal determinations remain HIPAA-specific.
D1-CTL-02 MODEL EXTRACTION RESISTANCE 164.526 Amendment of PHI P Medium D1-CTL-02 supports the security, governance, privacy, resilience, or evidence objective represented by 164.526. The relationship is functional, not legal equivalence. Entity status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, and legal determinations remain HIPAA-specific.
D1-CTL-02 MODEL EXTRACTION RESISTANCE 164.312(c) Integrity P Medium D1-CTL-02 supports the security, governance, privacy, resilience, or evidence objective represented by 164.312(c). The relationship is functional, not legal equivalence. Entity status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, and legal determinations remain HIPAA-specific.

5. Implementation Guidance

  • Confirm regulated-entity status and identify all PHI/ePHI flows before applying the mapping.

  • Treat required and addressable Security Rule implementation specifications according to the regulatory text and documented risk analysis.

  • Maintain HIPAA-specific policies, business associate agreements, privacy notices, rights workflows, breach assessments, and documentation.

  • Validate state-law, FTC, substance-use-disorder, genetic-information, and sector-specific obligations separately.

6. Notably Absent

No HHS endorsement; no HIPAA certification; no automatic safe harbor; no determination of covered-entity or business-associate status; no proof that all PHI uses and disclosures are lawful; no substitute for a Security Risk Analysis; no incorporation of the unfinalized proposed Security Rule.

7. Limitations

  • Mapping does not establish HIPAA compliance.

  • Covered entity or business associate status is not determined.

  • PHI/ePHI scope and permitted uses/disclosures require legal analysis.

  • State health privacy laws may impose additional duties.

  • The proposed Security Rule modernization is not treated as binding.

© 2026 ODA3 Pvt Ltd. Published by ODA3 Institute.