{
  "document": {
    "id": "GAISSF-CRO-035",
    "title": "GAISSF-HIPAA Mapping",
    "version": "1.0",
    "status": "Draft for Publication",
    "publisher": "ODA3 Institute",
    "publication_date": "2026-06-29",
    "updated": "2026-10-06",
    "classification": "Informative crosswalk / public"
  },
  "baseline": {
    "gaissf": "GAISSF-NOR-001 v1.0 and GAISSF-NOR-004 v1.0; 59 controls / 9 domains; Applicable-Control Baseline = all 52 controls in D1-D8 plus D9 where Physical AI or cyber-physical actuation is in scope.",
    "hipaa": "45 CFR Parts 160 and 164; current binding HIPAA regulatory baseline. HHS states the current Security Rule remains in effect while the 2024 Security Rule NPRM is pending. The 2024 reproductive-health Privacy Rule was largely vacated on 2025-06-18; remaining Notice of Privacy Practices modifications remain in effect.",
    "excluded": "The 2024 HIPAA Security Rule NPRM is non-binding and excluded from normative mapping. Court-vacated provisions of the 2024 reproductive-health Privacy Rule are not treated as binding."
  },
  "controls": [
    {
      "id": "D1-CTL-01",
      "title": "DATASET PROVENANCE & POISONING PREVENTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D1-CTL-02",
      "title": "MODEL EXTRACTION RESISTANCE",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D1-CTL-03",
      "title": "BEHAVIORAL DRIFT DETECTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D1-CTL-04",
      "title": "FEDERATED LEARNING POISONING PREVENTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D1-CTL-05",
      "title": "EMBEDDING SPACE ROBUSTNESS",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D1-CTL-06",
      "title": "POST-QUANTUM MODEL SIGNING & CRYPTO HARDENING",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D1-CTL-07",
      "title": "LORA/ADAPTER INTEGRITY VERIFICATION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D1-CTL-08",
      "title": "MODEL MERGE ATTACK DETECTION",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D1-CTL-09",
      "title": "QUANTIZATION BACKDOOR SCREENING",
      "domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D2-CTL-01",
      "title": "DIRECT PROMPT INJECTION PREVENTION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D2-CTL-02",
      "title": "INDIRECT PROMPT INJECTION PREVENTION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D2-CTL-03",
      "title": "JAILBREAK RESISTANCE TESTING",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D2-CTL-04",
      "title": "MULTI-MODAL INJECTION DEFENSE",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D2-CTL-05",
      "title": "FUNCTION CALL/TOOL CALL INJECTION PREVENTION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D2-CTL-06",
      "title": "CROSS-CONTEXT HIJACKING MITIGATION",
      "domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D3-CTL-01",
      "title": "LEAST AGENCY ENFORCEMENT",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D3-CTL-02",
      "title": "INTER-AGENT COMMUNICATION SECURITY",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D3-CTL-03",
      "title": "AGENTIC PROMPT CHAINING DETECTION",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D3-CTL-04",
      "title": "EMBODIED AI SAFETY CONTROLS",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D3-CTL-05",
      "title": "MULTI-AGENT TRUST CHAIN ATTESTATION",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D3-CTL-06",
      "title": "PERSISTENT MEMORY EXFILTRATION PREVENTION",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D3-CTL-07",
      "title": "SECURE MEMORY LIFECYCLE MANAGEMENT",
      "domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D4-CTL-01",
      "title": "AI BILL OF MATERIALS (AI BOM) MAINTENANCE",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D4-CTL-02",
      "title": "MODEL FILE & ARTIFACT SCANNING",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D4-CTL-03",
      "title": "MODEL HUB & REGISTRY VETTING",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D4-CTL-04",
      "title": "MCP SERVER BEHAVIORAL MONITORING",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D4-CTL-05",
      "title": "THIRD-PARTY AI API SECURITY ASSESSMENT",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D4-CTL-06",
      "title": "SHADOW AI DISCOVERY & GOVERNANCE",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D4-CTL-07",
      "title": "AI SOFTWARE COMPOSITION ANALYSIS (SCA)",
      "domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D5-CTL-01",
      "title": "HARMFUL CONTENT BLOCKING",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D5-CTL-02",
      "title": "PII LEAKAGE PREVENTION",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D5-CTL-03",
      "title": "COPYRIGHT DETECTION",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D5-CTL-04",
      "title": "AI WATERMARKING ROBUSTNESS",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D5-CTL-05",
      "title": "PRIVACY-BY-DESIGN VERIFICATION",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D5-CTL-06",
      "title": "PRIVACY-PRESERVING ML VALIDATION",
      "domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D6-CTL-01",
      "title": "HUMAN-IN-THE-LOOP FOR HIGH-RISK ACTIONS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D6-CTL-02",
      "title": "AUDIT TRAIL COMPLETENESS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D6-CTL-03",
      "title": "AI MODEL CARD COMPLETENESS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D6-CTL-04",
      "title": "AI INCIDENT RESPONSE READINESS",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D6-CTL-05",
      "title": "MODEL DEPRECATION & DECOMMISSIONING",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D6-CTL-06",
      "title": "THIRD-PARTY AI VENDOR GOVERNANCE",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D6-CTL-07",
      "title": "AI RESILIENCE & BUSINESS CONTINUITY",
      "domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D7-CTL-H01",
      "title": "AI-GENERATED PHISHING SIMULATION",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D7-CTL-H02",
      "title": "DEEPFAKE DETECTION TRAINING",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D7-CTL-H03",
      "title": "OUT-OF-BAND AUTHENTICATION",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D7-CTL-H04",
      "title": "AI SOCIAL ENGINEERING IR",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D7-CTL-H05",
      "title": "AI-ENHANCED EXTERNAL ATTACK DEFENSE",
      "domain": "D7: HUMAN & SOCIETAL HARMS",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D8-CTL-01",
      "title": "EU AI ACT RISK TIER MAPPING",
      "domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D8-CTL-02",
      "title": "ISO 42001 GAP ANALYSIS",
      "domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D8-CTL-03",
      "title": "GPAI TECHNICAL DOCUMENTATION VERIFICATION",
      "domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D8-CTL-04",
      "title": "DORA ICT INCIDENT REPORTING (FINANCIAL SECTOR)",
      "domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D8-CTL-05",
      "title": "NIST SP 800-218A COMPLIANCE CHECK",
      "domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "applicable_control_baseline": "Canonical D1-D8 Applicable-Control Baseline"
    },
    {
      "id": "D9-CTL-01",
      "title": "PHYSICAL HARM BOUNDARY ENFORCEMENT",
      "domain": "D9: PHYSICAL AI SAFETY",
      "applicable_control_baseline": "Additional / conditional; include where Physical AI or cyber-physical actuation is in scope"
    },
    {
      "id": "D9-CTL-02",
      "title": "SAFE STATE AND GRACEFUL DEGRADATION",
      "domain": "D9: PHYSICAL AI SAFETY",
      "applicable_control_baseline": "Additional / conditional; include where Physical AI or cyber-physical actuation is in scope"
    },
    {
      "id": "D9-CTL-03",
      "title": "HUMAN OVERRIDE AND EMERGENCY STOP",
      "domain": "D9: PHYSICAL AI SAFETY",
      "applicable_control_baseline": "Additional / conditional; include where Physical AI or cyber-physical actuation is in scope"
    },
    {
      "id": "D9-CTL-04",
      "title": "CYBER-PHYSICAL ATTACK DETECTION",
      "domain": "D9: PHYSICAL AI SAFETY",
      "applicable_control_baseline": "Additional / conditional; include where Physical AI or cyber-physical actuation is in scope"
    },
    {
      "id": "D9-CTL-05",
      "title": "PHYSICAL ENVIRONMENT INTEGRITY MONITORING",
      "domain": "D9: PHYSICAL AI SAFETY",
      "applicable_control_baseline": "Additional / conditional; include where Physical AI or cyber-physical actuation is in scope"
    },
    {
      "id": "D9-CTL-06",
      "title": "ACTUATOR COMMAND VERIFICATION",
      "domain": "D9: PHYSICAL AI SAFETY",
      "applicable_control_baseline": "Additional / conditional; include where Physical AI or cyber-physical actuation is in scope"
    },
    {
      "id": "D9-CTL-07",
      "title": "PHYSICAL INCIDENT EVIDENCE PRESERVATION",
      "domain": "D9: PHYSICAL AI SAFETY",
      "applicable_control_baseline": "Additional / conditional; include where Physical AI or cyber-physical actuation is in scope"
    }
  ],
  "hipaa_provisions": [
    {
      "section": "160.103",
      "title": "Definitions",
      "group": "General Provisions"
    },
    {
      "section": "160.203",
      "title": "General rule and exceptions",
      "group": "Preemption"
    },
    {
      "section": "164.105",
      "title": "Organizational requirements",
      "group": "General Requirements"
    },
    {
      "section": "164.306",
      "title": "Security standards: general rules",
      "group": "Security Rule"
    },
    {
      "section": "164.308(a)(1)",
      "title": "Security management process",
      "group": "Administrative Safeguards"
    },
    {
      "section": "164.308(a)(2)",
      "title": "Assigned security responsibility",
      "group": "Administrative Safeguards"
    },
    {
      "section": "164.308(a)(3)",
      "title": "Workforce security",
      "group": "Administrative Safeguards"
    },
    {
      "section": "164.308(a)(4)",
      "title": "Information access management",
      "group": "Administrative Safeguards"
    },
    {
      "section": "164.308(a)(5)",
      "title": "Security awareness and training",
      "group": "Administrative Safeguards"
    },
    {
      "section": "164.308(a)(6)",
      "title": "Security incident procedures",
      "group": "Administrative Safeguards"
    },
    {
      "section": "164.308(a)(7)",
      "title": "Contingency plan",
      "group": "Administrative Safeguards"
    },
    {
      "section": "164.308(a)(8)",
      "title": "Evaluation",
      "group": "Administrative Safeguards"
    },
    {
      "section": "164.308(b)",
      "title": "Business associate contracts and arrangements",
      "group": "Administrative Safeguards"
    },
    {
      "section": "164.310(a)",
      "title": "Facility access controls",
      "group": "Physical Safeguards"
    },
    {
      "section": "164.310(b)",
      "title": "Workstation use",
      "group": "Physical Safeguards"
    },
    {
      "section": "164.310(c)",
      "title": "Workstation security",
      "group": "Physical Safeguards"
    },
    {
      "section": "164.310(d)",
      "title": "Device and media controls",
      "group": "Physical Safeguards"
    },
    {
      "section": "164.312(a)",
      "title": "Access control",
      "group": "Technical Safeguards"
    },
    {
      "section": "164.312(b)",
      "title": "Audit controls",
      "group": "Technical Safeguards"
    },
    {
      "section": "164.312(c)",
      "title": "Integrity",
      "group": "Technical Safeguards"
    },
    {
      "section": "164.312(d)",
      "title": "Person or entity authentication",
      "group": "Technical Safeguards"
    },
    {
      "section": "164.312(e)",
      "title": "Transmission security",
      "group": "Technical Safeguards"
    },
    {
      "section": "164.314",
      "title": "Organizational requirements",
      "group": "Security Rule"
    },
    {
      "section": "164.316",
      "title": "Policies, procedures and documentation",
      "group": "Security Rule"
    },
    {
      "section": "164.502",
      "title": "Uses and disclosures of PHI: general rules",
      "group": "Privacy Rule"
    },
    {
      "section": "164.504",
      "title": "Organizational requirements",
      "group": "Privacy Rule"
    },
    {
      "section": "164.506",
      "title": "Uses and disclosures for treatment, payment, operations",
      "group": "Privacy Rule"
    },
    {
      "section": "164.508",
      "title": "Uses and disclosures requiring authorization",
      "group": "Privacy Rule"
    },
    {
      "section": "164.514",
      "title": "Other requirements relating to uses and disclosures",
      "group": "Privacy Rule"
    },
    {
      "section": "164.520",
      "title": "Notice of privacy practices",
      "group": "Privacy Rule"
    },
    {
      "section": "164.522",
      "title": "Rights to request privacy protection",
      "group": "Privacy Rule"
    },
    {
      "section": "164.524",
      "title": "Access of individuals to PHI",
      "group": "Privacy Rule"
    },
    {
      "section": "164.526",
      "title": "Amendment of PHI",
      "group": "Privacy Rule"
    },
    {
      "section": "164.528",
      "title": "Accounting of disclosures",
      "group": "Privacy Rule"
    },
    {
      "section": "164.530",
      "title": "Administrative requirements",
      "group": "Privacy Rule"
    },
    {
      "section": "164.532",
      "title": "Transition provisions",
      "group": "Privacy Rule"
    },
    {
      "section": "164.534",
      "title": "Compliance dates",
      "group": "Privacy Rule"
    },
    {
      "section": "164.400-414",
      "title": "Breach notification requirements",
      "group": "Breach Notification Rule"
    },
    {
      "section": "160.300-552",
      "title": "Compliance, investigations and penalties",
      "group": "Enforcement Rule"
    }
  ],
  "mappings": [
    {
      "record_id": "GAISSF-CRO-035-MAP-0001",
      "gaissf_id": "D1-CTL-01",
      "gaissf_title": "DATASET PROVENANCE & POISONING PREVENTION",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "hipaa_section": "164.526",
      "hipaa_title": "Amendment of PHI",
      "rule_group": "Privacy Rule",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D1-CTL-01 supports the security, governance, privacy, resilience, or evidence objective represented by 164.526. The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0002",
      "gaissf_id": "D1-CTL-01",
      "gaissf_title": "DATASET PROVENANCE & POISONING PREVENTION",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "hipaa_section": "164.312(c)",
      "hipaa_title": "Integrity",
      "rule_group": "Technical Safeguards",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D1-CTL-01 supports the security, governance, privacy, resilience, or evidence objective represented by 164.312(c). The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0003",
      "gaissf_id": "D1-CTL-01",
      "gaissf_title": "DATASET PROVENANCE & POISONING PREVENTION",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "hipaa_section": "164.310(d)",
      "hipaa_title": "Device and media controls",
      "rule_group": "Physical Safeguards",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D1-CTL-01 supports the security, governance, privacy, resilience, or evidence objective represented by 164.310(d). The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0004",
      "gaissf_id": "D1-CTL-01",
      "gaissf_title": "DATASET PROVENANCE & POISONING PREVENTION",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "hipaa_section": "164.308(a)(1)",
      "hipaa_title": "Security management process",
      "rule_group": "Administrative Safeguards",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D1-CTL-01 supports the security, governance, privacy, resilience, or evidence objective represented by 164.308(a)(1). The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0005",
      "gaissf_id": "D1-CTL-02",
      "gaissf_title": "MODEL EXTRACTION RESISTANCE",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "hipaa_section": "164.526",
      "hipaa_title": "Amendment of PHI",
      "rule_group": "Privacy Rule",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D1-CTL-02 supports the security, governance, privacy, resilience, or evidence objective represented by 164.526. The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0006",
      "gaissf_id": "D1-CTL-02",
      "gaissf_title": "MODEL EXTRACTION RESISTANCE",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "hipaa_section": "164.312(c)",
      "hipaa_title": "Integrity",
      "rule_group": "Technical Safeguards",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D1-CTL-02 supports the security, governance, privacy, resilience, or evidence objective represented by 164.312(c). The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0007",
      "gaissf_id": "D1-CTL-02",
      "gaissf_title": "MODEL EXTRACTION RESISTANCE",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "hipaa_section": "164.308(a)(1)",
      "hipaa_title": "Security management process",
      "rule_group": "Administrative Safeguards",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D1-CTL-02 supports the security, governance, privacy, resilience, or evidence objective represented by 164.308(a)(1). The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0008",
      "gaissf_id": "D1-CTL-03",
      "gaissf_title": "BEHAVIORAL DRIFT DETECTION",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "hipaa_section": "164.312(c)",
      "hipaa_title": "Integrity",
      "rule_group": "Technical Safeguards",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D1-CTL-03 supports the security, governance, privacy, resilience, or evidence objective represented by 164.312(c). The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0009",
      "gaissf_id": "D1-CTL-03",
      "gaissf_title": "BEHAVIORAL DRIFT DETECTION",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "hipaa_section": "164.308(a)(1)",
      "hipaa_title": "Security management process",
      "rule_group": "Administrative Safeguards",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D1-CTL-03 supports the security, governance, privacy, resilience, or evidence objective represented by 164.308(a)(1). The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0010",
      "gaissf_id": "D1-CTL-03",
      "gaissf_title": "BEHAVIORAL DRIFT DETECTION",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "hipaa_section": "164.526",
      "hipaa_title": "Amendment of PHI",
      "rule_group": "Privacy Rule",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D1-CTL-03 supports the security, governance, privacy, resilience, or evidence objective represented by 164.526. The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0011",
      "gaissf_id": "D1-CTL-03",
      "gaissf_title": "BEHAVIORAL DRIFT DETECTION",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "hipaa_section": "164.308(a)(6)",
      "hipaa_title": "Security incident procedures",
      "rule_group": "Administrative Safeguards",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D1-CTL-03 supports the security, governance, privacy, resilience, or evidence objective represented by 164.308(a)(6). The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0012",
      "gaissf_id": "D1-CTL-04",
      "gaissf_title": "FEDERATED LEARNING POISONING PREVENTION",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "hipaa_section": "164.312(c)",
      "hipaa_title": "Integrity",
      "rule_group": "Technical Safeguards",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D1-CTL-04 supports the security, governance, privacy, resilience, or evidence objective represented by 164.312(c). The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0013",
      "gaissf_id": "D1-CTL-04",
      "gaissf_title": "FEDERATED LEARNING POISONING PREVENTION",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "hipaa_section": "164.308(a)(1)",
      "hipaa_title": "Security management process",
      "rule_group": "Administrative Safeguards",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D1-CTL-04 supports the security, governance, privacy, resilience, or evidence objective represented by 164.308(a)(1). The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0014",
      "gaissf_id": "D1-CTL-04",
      "gaissf_title": "FEDERATED LEARNING POISONING PREVENTION",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "hipaa_section": "164.526",
      "hipaa_title": "Amendment of PHI",
      "rule_group": "Privacy Rule",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D1-CTL-04 supports the security, governance, privacy, resilience, or evidence objective represented by 164.526. The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0015",
      "gaissf_id": "D1-CTL-05",
      "gaissf_title": "EMBEDDING SPACE ROBUSTNESS",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "hipaa_section": "164.526",
      "hipaa_title": "Amendment of PHI",
      "rule_group": "Privacy Rule",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D1-CTL-05 supports the security, governance, privacy, resilience, or evidence objective represented by 164.526. The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0016",
      "gaissf_id": "D1-CTL-05",
      "gaissf_title": "EMBEDDING SPACE ROBUSTNESS",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "hipaa_section": "164.312(c)",
      "hipaa_title": "Integrity",
      "rule_group": "Technical Safeguards",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D1-CTL-05 supports the security, governance, privacy, resilience, or evidence objective represented by 164.312(c). The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0017",
      "gaissf_id": "D1-CTL-05",
      "gaissf_title": "EMBEDDING SPACE ROBUSTNESS",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "hipaa_section": "164.308(a)(1)",
      "hipaa_title": "Security management process",
      "rule_group": "Administrative Safeguards",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D1-CTL-05 supports the security, governance, privacy, resilience, or evidence objective represented by 164.308(a)(1). The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0018",
      "gaissf_id": "D1-CTL-06",
      "gaissf_title": "POST-QUANTUM MODEL SIGNING & CRYPTO HARDENING",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "hipaa_section": "164.526",
      "hipaa_title": "Amendment of PHI",
      "rule_group": "Privacy Rule",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D1-CTL-06 supports the security, governance, privacy, resilience, or evidence objective represented by 164.526. The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0019",
      "gaissf_id": "D1-CTL-06",
      "gaissf_title": "POST-QUANTUM MODEL SIGNING & CRYPTO HARDENING",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "hipaa_section": "164.312(c)",
      "hipaa_title": "Integrity",
      "rule_group": "Technical Safeguards",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D1-CTL-06 supports the security, governance, privacy, resilience, or evidence objective represented by 164.312(c). The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0020",
      "gaissf_id": "D1-CTL-06",
      "gaissf_title": "POST-QUANTUM MODEL SIGNING & CRYPTO HARDENING",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "hipaa_section": "164.308(a)(1)",
      "hipaa_title": "Security management process",
      "rule_group": "Administrative Safeguards",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D1-CTL-06 supports the security, governance, privacy, resilience, or evidence objective represented by 164.308(a)(1). The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0021",
      "gaissf_id": "D1-CTL-07",
      "gaissf_title": "LORA/ADAPTER INTEGRITY VERIFICATION",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "hipaa_section": "164.526",
      "hipaa_title": "Amendment of PHI",
      "rule_group": "Privacy Rule",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D1-CTL-07 supports the security, governance, privacy, resilience, or evidence objective represented by 164.526. The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0022",
      "gaissf_id": "D1-CTL-07",
      "gaissf_title": "LORA/ADAPTER INTEGRITY VERIFICATION",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "hipaa_section": "164.312(c)",
      "hipaa_title": "Integrity",
      "rule_group": "Technical Safeguards",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D1-CTL-07 supports the security, governance, privacy, resilience, or evidence objective represented by 164.312(c). The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0023",
      "gaissf_id": "D1-CTL-07",
      "gaissf_title": "LORA/ADAPTER INTEGRITY VERIFICATION",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "hipaa_section": "164.308(a)(1)",
      "hipaa_title": "Security management process",
      "rule_group": "Administrative Safeguards",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D1-CTL-07 supports the security, governance, privacy, resilience, or evidence objective represented by 164.308(a)(1). The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0024",
      "gaissf_id": "D1-CTL-08",
      "gaissf_title": "MODEL MERGE ATTACK DETECTION",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "hipaa_section": "164.526",
      "hipaa_title": "Amendment of PHI",
      "rule_group": "Privacy Rule",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D1-CTL-08 supports the security, governance, privacy, resilience, or evidence objective represented by 164.526. The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0025",
      "gaissf_id": "D1-CTL-08",
      "gaissf_title": "MODEL MERGE ATTACK DETECTION",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "hipaa_section": "164.312(c)",
      "hipaa_title": "Integrity",
      "rule_group": "Technical Safeguards",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D1-CTL-08 supports the security, governance, privacy, resilience, or evidence objective represented by 164.312(c). The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0026",
      "gaissf_id": "D1-CTL-08",
      "gaissf_title": "MODEL MERGE ATTACK DETECTION",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "hipaa_section": "164.308(a)(6)",
      "hipaa_title": "Security incident procedures",
      "rule_group": "Administrative Safeguards",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D1-CTL-08 supports the security, governance, privacy, resilience, or evidence objective represented by 164.308(a)(6). The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0027",
      "gaissf_id": "D1-CTL-08",
      "gaissf_title": "MODEL MERGE ATTACK DETECTION",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "hipaa_section": "164.308(a)(1)",
      "hipaa_title": "Security management process",
      "rule_group": "Administrative Safeguards",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D1-CTL-08 supports the security, governance, privacy, resilience, or evidence objective represented by 164.308(a)(1). The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0028",
      "gaissf_id": "D1-CTL-09",
      "gaissf_title": "QUANTIZATION BACKDOOR SCREENING",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "hipaa_section": "164.526",
      "hipaa_title": "Amendment of PHI",
      "rule_group": "Privacy Rule",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D1-CTL-09 supports the security, governance, privacy, resilience, or evidence objective represented by 164.526. The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0029",
      "gaissf_id": "D1-CTL-09",
      "gaissf_title": "QUANTIZATION BACKDOOR SCREENING",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "hipaa_section": "164.312(c)",
      "hipaa_title": "Integrity",
      "rule_group": "Technical Safeguards",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D1-CTL-09 supports the security, governance, privacy, resilience, or evidence objective represented by 164.312(c). The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0030",
      "gaissf_id": "D1-CTL-09",
      "gaissf_title": "QUANTIZATION BACKDOOR SCREENING",
      "gaissf_domain": "D1: MODEL INTEGRITY & ADVERSARIAL ROBUSTNESS",
      "hipaa_section": "164.308(a)(1)",
      "hipaa_title": "Security management process",
      "rule_group": "Administrative Safeguards",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D1-CTL-09 supports the security, governance, privacy, resilience, or evidence objective represented by 164.308(a)(1). The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0031",
      "gaissf_id": "D2-CTL-01",
      "gaissf_title": "DIRECT PROMPT INJECTION PREVENTION",
      "gaissf_domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "hipaa_section": "164.310(b)",
      "hipaa_title": "Workstation use",
      "rule_group": "Physical Safeguards",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D2-CTL-01 supports the security, governance, privacy, resilience, or evidence objective represented by 164.310(b). The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0032",
      "gaissf_id": "D2-CTL-01",
      "gaissf_title": "DIRECT PROMPT INJECTION PREVENTION",
      "gaissf_domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "hipaa_section": "164.308(a)(1)",
      "hipaa_title": "Security management process",
      "rule_group": "Administrative Safeguards",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D2-CTL-01 supports the security, governance, privacy, resilience, or evidence objective represented by 164.308(a)(1). The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0033",
      "gaissf_id": "D2-CTL-02",
      "gaissf_title": "INDIRECT PROMPT INJECTION PREVENTION",
      "gaissf_domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "hipaa_section": "164.310(b)",
      "hipaa_title": "Workstation use",
      "rule_group": "Physical Safeguards",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D2-CTL-02 supports the security, governance, privacy, resilience, or evidence objective represented by 164.310(b). The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0034",
      "gaissf_id": "D2-CTL-02",
      "gaissf_title": "INDIRECT PROMPT INJECTION PREVENTION",
      "gaissf_domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "hipaa_section": "164.308(a)(1)",
      "hipaa_title": "Security management process",
      "rule_group": "Administrative Safeguards",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D2-CTL-02 supports the security, governance, privacy, resilience, or evidence objective represented by 164.308(a)(1). The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0035",
      "gaissf_id": "D2-CTL-03",
      "gaissf_title": "JAILBREAK RESISTANCE TESTING",
      "gaissf_domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "hipaa_section": "164.310(b)",
      "hipaa_title": "Workstation use",
      "rule_group": "Physical Safeguards",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D2-CTL-03 supports the security, governance, privacy, resilience, or evidence objective represented by 164.310(b). The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0036",
      "gaissf_id": "D2-CTL-03",
      "gaissf_title": "JAILBREAK RESISTANCE TESTING",
      "gaissf_domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "hipaa_section": "164.308(a)(8)",
      "hipaa_title": "Evaluation",
      "rule_group": "Administrative Safeguards",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D2-CTL-03 supports the security, governance, privacy, resilience, or evidence objective represented by 164.308(a)(8). The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0037",
      "gaissf_id": "D2-CTL-03",
      "gaissf_title": "JAILBREAK RESISTANCE TESTING",
      "gaissf_domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "hipaa_section": "164.308(a)(1)",
      "hipaa_title": "Security management process",
      "rule_group": "Administrative Safeguards",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D2-CTL-03 supports the security, governance, privacy, resilience, or evidence objective represented by 164.308(a)(1). The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0038",
      "gaissf_id": "D2-CTL-04",
      "gaissf_title": "MULTI-MODAL INJECTION DEFENSE",
      "gaissf_domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "hipaa_section": "164.310(b)",
      "hipaa_title": "Workstation use",
      "rule_group": "Physical Safeguards",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D2-CTL-04 supports the security, governance, privacy, resilience, or evidence objective represented by 164.310(b). The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0039",
      "gaissf_id": "D2-CTL-04",
      "gaissf_title": "MULTI-MODAL INJECTION DEFENSE",
      "gaissf_domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "hipaa_section": "164.308(a)(1)",
      "hipaa_title": "Security management process",
      "rule_group": "Administrative Safeguards",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D2-CTL-04 supports the security, governance, privacy, resilience, or evidence objective represented by 164.308(a)(1). The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0040",
      "gaissf_id": "D2-CTL-05",
      "gaissf_title": "FUNCTION CALL/TOOL CALL INJECTION PREVENTION",
      "gaissf_domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "hipaa_section": "164.310(b)",
      "hipaa_title": "Workstation use",
      "rule_group": "Physical Safeguards",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D2-CTL-05 supports the security, governance, privacy, resilience, or evidence objective represented by 164.310(b). The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0041",
      "gaissf_id": "D2-CTL-05",
      "gaissf_title": "FUNCTION CALL/TOOL CALL INJECTION PREVENTION",
      "gaissf_domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "hipaa_section": "164.308(a)(1)",
      "hipaa_title": "Security management process",
      "rule_group": "Administrative Safeguards",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D2-CTL-05 supports the security, governance, privacy, resilience, or evidence objective represented by 164.308(a)(1). The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0042",
      "gaissf_id": "D2-CTL-06",
      "gaissf_title": "CROSS-CONTEXT HIJACKING MITIGATION",
      "gaissf_domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "hipaa_section": "164.310(b)",
      "hipaa_title": "Workstation use",
      "rule_group": "Physical Safeguards",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D2-CTL-06 supports the security, governance, privacy, resilience, or evidence objective represented by 164.310(b). The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0043",
      "gaissf_id": "D2-CTL-06",
      "gaissf_title": "CROSS-CONTEXT HIJACKING MITIGATION",
      "gaissf_domain": "D2: RUNTIME SECURITY & ADVERSARIAL DEFENSE",
      "hipaa_section": "164.308(a)(1)",
      "hipaa_title": "Security management process",
      "rule_group": "Administrative Safeguards",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D2-CTL-06 supports the security, governance, privacy, resilience, or evidence objective represented by 164.308(a)(1). The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0044",
      "gaissf_id": "D3-CTL-01",
      "gaissf_title": "LEAST AGENCY ENFORCEMENT",
      "gaissf_domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "hipaa_section": "164.308(a)(1)",
      "hipaa_title": "Security management process",
      "rule_group": "Administrative Safeguards",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D3-CTL-01 supports the security, governance, privacy, resilience, or evidence objective represented by 164.308(a)(1). The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0045",
      "gaissf_id": "D3-CTL-02",
      "gaissf_title": "INTER-AGENT COMMUNICATION SECURITY",
      "gaissf_domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "hipaa_section": "164.308(a)(1)",
      "hipaa_title": "Security management process",
      "rule_group": "Administrative Safeguards",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D3-CTL-02 supports the security, governance, privacy, resilience, or evidence objective represented by 164.308(a)(1). The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0046",
      "gaissf_id": "D3-CTL-03",
      "gaissf_title": "AGENTIC PROMPT CHAINING DETECTION",
      "gaissf_domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "hipaa_section": "164.308(a)(6)",
      "hipaa_title": "Security incident procedures",
      "rule_group": "Administrative Safeguards",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D3-CTL-03 supports the security, governance, privacy, resilience, or evidence objective represented by 164.308(a)(6). The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0047",
      "gaissf_id": "D3-CTL-03",
      "gaissf_title": "AGENTIC PROMPT CHAINING DETECTION",
      "gaissf_domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "hipaa_section": "164.308(a)(1)",
      "hipaa_title": "Security management process",
      "rule_group": "Administrative Safeguards",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D3-CTL-03 supports the security, governance, privacy, resilience, or evidence objective represented by 164.308(a)(1). The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0048",
      "gaissf_id": "D3-CTL-04",
      "gaissf_title": "EMBODIED AI SAFETY CONTROLS",
      "gaissf_domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "hipaa_section": "164.308(a)(1)",
      "hipaa_title": "Security management process",
      "rule_group": "Administrative Safeguards",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D3-CTL-04 supports the security, governance, privacy, resilience, or evidence objective represented by 164.308(a)(1). The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0049",
      "gaissf_id": "D3-CTL-05",
      "gaissf_title": "MULTI-AGENT TRUST CHAIN ATTESTATION",
      "gaissf_domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "hipaa_section": "164.308(a)(8)",
      "hipaa_title": "Evaluation",
      "rule_group": "Administrative Safeguards",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D3-CTL-05 supports the security, governance, privacy, resilience, or evidence objective represented by 164.308(a)(8). The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0050",
      "gaissf_id": "D3-CTL-05",
      "gaissf_title": "MULTI-AGENT TRUST CHAIN ATTESTATION",
      "gaissf_domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "hipaa_section": "164.308(a)(1)",
      "hipaa_title": "Security management process",
      "rule_group": "Administrative Safeguards",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D3-CTL-05 supports the security, governance, privacy, resilience, or evidence objective represented by 164.308(a)(1). The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0051",
      "gaissf_id": "D3-CTL-06",
      "gaissf_title": "PERSISTENT MEMORY EXFILTRATION PREVENTION",
      "gaissf_domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "hipaa_section": "164.400-414",
      "hipaa_title": "Breach notification requirements",
      "rule_group": "Breach Notification Rule",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D3-CTL-06 supports the security, governance, privacy, resilience, or evidence objective represented by 164.400-414. The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0052",
      "gaissf_id": "D3-CTL-06",
      "gaissf_title": "PERSISTENT MEMORY EXFILTRATION PREVENTION",
      "gaissf_domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "hipaa_section": "164.312(e)",
      "hipaa_title": "Transmission security",
      "rule_group": "Technical Safeguards",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D3-CTL-06 supports the security, governance, privacy, resilience, or evidence objective represented by 164.312(e). The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0053",
      "gaissf_id": "D3-CTL-06",
      "gaissf_title": "PERSISTENT MEMORY EXFILTRATION PREVENTION",
      "gaissf_domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "hipaa_section": "164.308(a)(1)",
      "hipaa_title": "Security management process",
      "rule_group": "Administrative Safeguards",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D3-CTL-06 supports the security, governance, privacy, resilience, or evidence objective represented by 164.308(a)(1). The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0054",
      "gaissf_id": "D3-CTL-07",
      "gaissf_title": "SECURE MEMORY LIFECYCLE MANAGEMENT",
      "gaissf_domain": "D3: AGENTIC RISK & AUTONOMOUS SYSTEM SECURITY",
      "hipaa_section": "164.308(a)(1)",
      "hipaa_title": "Security management process",
      "rule_group": "Administrative Safeguards",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D3-CTL-07 supports the security, governance, privacy, resilience, or evidence objective represented by 164.308(a)(1). The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0055",
      "gaissf_id": "D4-CTL-01",
      "gaissf_title": "AI BILL OF MATERIALS (AI BOM) MAINTENANCE",
      "gaissf_domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "hipaa_section": "164.308(b)",
      "hipaa_title": "Business associate contracts and arrangements",
      "rule_group": "Administrative Safeguards",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D4-CTL-01 supports the security, governance, privacy, resilience, or evidence objective represented by 164.308(b). The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0056",
      "gaissf_id": "D4-CTL-01",
      "gaissf_title": "AI BILL OF MATERIALS (AI BOM) MAINTENANCE",
      "gaissf_domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "hipaa_section": "164.504",
      "hipaa_title": "Organizational requirements",
      "rule_group": "Privacy Rule",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D4-CTL-01 supports the security, governance, privacy, resilience, or evidence objective represented by 164.504. The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0057",
      "gaissf_id": "D4-CTL-02",
      "gaissf_title": "MODEL FILE & ARTIFACT SCANNING",
      "gaissf_domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "hipaa_section": "164.308(b)",
      "hipaa_title": "Business associate contracts and arrangements",
      "rule_group": "Administrative Safeguards",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D4-CTL-02 supports the security, governance, privacy, resilience, or evidence objective represented by 164.308(b). The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0058",
      "gaissf_id": "D4-CTL-02",
      "gaissf_title": "MODEL FILE & ARTIFACT SCANNING",
      "gaissf_domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "hipaa_section": "164.504",
      "hipaa_title": "Organizational requirements",
      "rule_group": "Privacy Rule",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D4-CTL-02 supports the security, governance, privacy, resilience, or evidence objective represented by 164.504. The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0059",
      "gaissf_id": "D4-CTL-03",
      "gaissf_title": "MODEL HUB & REGISTRY VETTING",
      "gaissf_domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "hipaa_section": "164.308(b)",
      "hipaa_title": "Business associate contracts and arrangements",
      "rule_group": "Administrative Safeguards",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D4-CTL-03 supports the security, governance, privacy, resilience, or evidence objective represented by 164.308(b). The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0060",
      "gaissf_id": "D4-CTL-03",
      "gaissf_title": "MODEL HUB & REGISTRY VETTING",
      "gaissf_domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "hipaa_section": "164.504",
      "hipaa_title": "Organizational requirements",
      "rule_group": "Privacy Rule",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D4-CTL-03 supports the security, governance, privacy, resilience, or evidence objective represented by 164.504. The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0061",
      "gaissf_id": "D4-CTL-04",
      "gaissf_title": "MCP SERVER BEHAVIORAL MONITORING",
      "gaissf_domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "hipaa_section": "164.308(b)",
      "hipaa_title": "Business associate contracts and arrangements",
      "rule_group": "Administrative Safeguards",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D4-CTL-04 supports the security, governance, privacy, resilience, or evidence objective represented by 164.308(b). The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0062",
      "gaissf_id": "D4-CTL-04",
      "gaissf_title": "MCP SERVER BEHAVIORAL MONITORING",
      "gaissf_domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "hipaa_section": "164.504",
      "hipaa_title": "Organizational requirements",
      "rule_group": "Privacy Rule",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D4-CTL-04 supports the security, governance, privacy, resilience, or evidence objective represented by 164.504. The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0063",
      "gaissf_id": "D4-CTL-04",
      "gaissf_title": "MCP SERVER BEHAVIORAL MONITORING",
      "gaissf_domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "hipaa_section": "164.312(b)",
      "hipaa_title": "Audit controls",
      "rule_group": "Technical Safeguards",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D4-CTL-04 supports the security, governance, privacy, resilience, or evidence objective represented by 164.312(b). The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0064",
      "gaissf_id": "D4-CTL-04",
      "gaissf_title": "MCP SERVER BEHAVIORAL MONITORING",
      "gaissf_domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "hipaa_section": "164.308(a)(6)",
      "hipaa_title": "Security incident procedures",
      "rule_group": "Administrative Safeguards",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D4-CTL-04 supports the security, governance, privacy, resilience, or evidence objective represented by 164.308(a)(6). The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0065",
      "gaissf_id": "D4-CTL-05",
      "gaissf_title": "THIRD-PARTY AI API SECURITY ASSESSMENT",
      "gaissf_domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "hipaa_section": "164.308(b)",
      "hipaa_title": "Business associate contracts and arrangements",
      "rule_group": "Administrative Safeguards",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D4-CTL-05 supports the security, governance, privacy, resilience, or evidence objective represented by 164.308(b). The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0066",
      "gaissf_id": "D4-CTL-05",
      "gaissf_title": "THIRD-PARTY AI API SECURITY ASSESSMENT",
      "gaissf_domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "hipaa_section": "164.504",
      "hipaa_title": "Organizational requirements",
      "rule_group": "Privacy Rule",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D4-CTL-05 supports the security, governance, privacy, resilience, or evidence objective represented by 164.504. The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0067",
      "gaissf_id": "D4-CTL-05",
      "gaissf_title": "THIRD-PARTY AI API SECURITY ASSESSMENT",
      "gaissf_domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "hipaa_section": "164.308(a)(8)",
      "hipaa_title": "Evaluation",
      "rule_group": "Administrative Safeguards",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D4-CTL-05 supports the security, governance, privacy, resilience, or evidence objective represented by 164.308(a)(8). The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0068",
      "gaissf_id": "D4-CTL-06",
      "gaissf_title": "SHADOW AI DISCOVERY & GOVERNANCE",
      "gaissf_domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "hipaa_section": "164.504",
      "hipaa_title": "Organizational requirements",
      "rule_group": "Privacy Rule",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D4-CTL-06 supports the security, governance, privacy, resilience, or evidence objective represented by 164.504. The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0069",
      "gaissf_id": "D4-CTL-06",
      "gaissf_title": "SHADOW AI DISCOVERY & GOVERNANCE",
      "gaissf_domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "hipaa_section": "164.308(b)",
      "hipaa_title": "Business associate contracts and arrangements",
      "rule_group": "Administrative Safeguards",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D4-CTL-06 supports the security, governance, privacy, resilience, or evidence objective represented by 164.308(b). The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0070",
      "gaissf_id": "D4-CTL-06",
      "gaissf_title": "SHADOW AI DISCOVERY & GOVERNANCE",
      "gaissf_domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "hipaa_section": "164.530",
      "hipaa_title": "Administrative requirements",
      "rule_group": "Privacy Rule",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D4-CTL-06 supports the security, governance, privacy, resilience, or evidence objective represented by 164.530. The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0071",
      "gaissf_id": "D4-CTL-06",
      "gaissf_title": "SHADOW AI DISCOVERY & GOVERNANCE",
      "gaissf_domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "hipaa_section": "164.316",
      "hipaa_title": "Policies, procedures and documentation",
      "rule_group": "Security Rule",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D4-CTL-06 supports the security, governance, privacy, resilience, or evidence objective represented by 164.316. The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0072",
      "gaissf_id": "D4-CTL-07",
      "gaissf_title": "AI SOFTWARE COMPOSITION ANALYSIS (SCA)",
      "gaissf_domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "hipaa_section": "164.308(b)",
      "hipaa_title": "Business associate contracts and arrangements",
      "rule_group": "Administrative Safeguards",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D4-CTL-07 supports the security, governance, privacy, resilience, or evidence objective represented by 164.308(b). The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0073",
      "gaissf_id": "D4-CTL-07",
      "gaissf_title": "AI SOFTWARE COMPOSITION ANALYSIS (SCA)",
      "gaissf_domain": "D4: SUPPLY CHAIN & THIRD-PARTY AI SECURITY",
      "hipaa_section": "164.504",
      "hipaa_title": "Organizational requirements",
      "rule_group": "Privacy Rule",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D4-CTL-07 supports the security, governance, privacy, resilience, or evidence objective represented by 164.504. The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0074",
      "gaissf_id": "D5-CTL-01",
      "gaissf_title": "HARMFUL CONTENT BLOCKING",
      "gaissf_domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "hipaa_section": "164.312(c)",
      "hipaa_title": "Integrity",
      "rule_group": "Technical Safeguards",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D5-CTL-01 supports the security, governance, privacy, resilience, or evidence objective represented by 164.312(c). The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0075",
      "gaissf_id": "D5-CTL-01",
      "gaissf_title": "HARMFUL CONTENT BLOCKING",
      "gaissf_domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "hipaa_section": "164.526",
      "hipaa_title": "Amendment of PHI",
      "rule_group": "Privacy Rule",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D5-CTL-01 supports the security, governance, privacy, resilience, or evidence objective represented by 164.526. The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0076",
      "gaissf_id": "D5-CTL-01",
      "gaissf_title": "HARMFUL CONTENT BLOCKING",
      "gaissf_domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "hipaa_section": "164.502",
      "hipaa_title": "Uses and disclosures of PHI: general rules",
      "rule_group": "Privacy Rule",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D5-CTL-01 supports the security, governance, privacy, resilience, or evidence objective represented by 164.502. The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0077",
      "gaissf_id": "D5-CTL-02",
      "gaissf_title": "PII LEAKAGE PREVENTION",
      "gaissf_domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "hipaa_section": "164.502",
      "hipaa_title": "Uses and disclosures of PHI: general rules",
      "rule_group": "Privacy Rule",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D5-CTL-02 supports the security, governance, privacy, resilience, or evidence objective represented by 164.502. The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0078",
      "gaissf_id": "D5-CTL-02",
      "gaissf_title": "PII LEAKAGE PREVENTION",
      "gaissf_domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "hipaa_section": "164.312(c)",
      "hipaa_title": "Integrity",
      "rule_group": "Technical Safeguards",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D5-CTL-02 supports the security, governance, privacy, resilience, or evidence objective represented by 164.312(c). The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0079",
      "gaissf_id": "D5-CTL-02",
      "gaissf_title": "PII LEAKAGE PREVENTION",
      "gaissf_domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "hipaa_section": "164.526",
      "hipaa_title": "Amendment of PHI",
      "rule_group": "Privacy Rule",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D5-CTL-02 supports the security, governance, privacy, resilience, or evidence objective represented by 164.526. The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0080",
      "gaissf_id": "D5-CTL-02",
      "gaissf_title": "PII LEAKAGE PREVENTION",
      "gaissf_domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "hipaa_section": "164.514",
      "hipaa_title": "Other requirements relating to uses and disclosures",
      "rule_group": "Privacy Rule",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D5-CTL-02 supports the security, governance, privacy, resilience, or evidence objective represented by 164.514. The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0081",
      "gaissf_id": "D5-CTL-03",
      "gaissf_title": "COPYRIGHT DETECTION",
      "gaissf_domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "hipaa_section": "164.312(c)",
      "hipaa_title": "Integrity",
      "rule_group": "Technical Safeguards",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D5-CTL-03 supports the security, governance, privacy, resilience, or evidence objective represented by 164.312(c). The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0082",
      "gaissf_id": "D5-CTL-03",
      "gaissf_title": "COPYRIGHT DETECTION",
      "gaissf_domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "hipaa_section": "164.526",
      "hipaa_title": "Amendment of PHI",
      "rule_group": "Privacy Rule",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D5-CTL-03 supports the security, governance, privacy, resilience, or evidence objective represented by 164.526. The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0083",
      "gaissf_id": "D5-CTL-03",
      "gaissf_title": "COPYRIGHT DETECTION",
      "gaissf_domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "hipaa_section": "164.502",
      "hipaa_title": "Uses and disclosures of PHI: general rules",
      "rule_group": "Privacy Rule",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D5-CTL-03 supports the security, governance, privacy, resilience, or evidence objective represented by 164.502. The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0084",
      "gaissf_id": "D5-CTL-03",
      "gaissf_title": "COPYRIGHT DETECTION",
      "gaissf_domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "hipaa_section": "164.308(a)(6)",
      "hipaa_title": "Security incident procedures",
      "rule_group": "Administrative Safeguards",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D5-CTL-03 supports the security, governance, privacy, resilience, or evidence objective represented by 164.308(a)(6). The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0085",
      "gaissf_id": "D5-CTL-04",
      "gaissf_title": "AI WATERMARKING ROBUSTNESS",
      "gaissf_domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "hipaa_section": "164.312(c)",
      "hipaa_title": "Integrity",
      "rule_group": "Technical Safeguards",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D5-CTL-04 supports the security, governance, privacy, resilience, or evidence objective represented by 164.312(c). The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0086",
      "gaissf_id": "D5-CTL-04",
      "gaissf_title": "AI WATERMARKING ROBUSTNESS",
      "gaissf_domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "hipaa_section": "164.526",
      "hipaa_title": "Amendment of PHI",
      "rule_group": "Privacy Rule",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D5-CTL-04 supports the security, governance, privacy, resilience, or evidence objective represented by 164.526. The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0087",
      "gaissf_id": "D5-CTL-04",
      "gaissf_title": "AI WATERMARKING ROBUSTNESS",
      "gaissf_domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "hipaa_section": "164.502",
      "hipaa_title": "Uses and disclosures of PHI: general rules",
      "rule_group": "Privacy Rule",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D5-CTL-04 supports the security, governance, privacy, resilience, or evidence objective represented by 164.502. The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0088",
      "gaissf_id": "D5-CTL-05",
      "gaissf_title": "PRIVACY-BY-DESIGN VERIFICATION",
      "gaissf_domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "hipaa_section": "164.502",
      "hipaa_title": "Uses and disclosures of PHI: general rules",
      "rule_group": "Privacy Rule",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "D5-CTL-05 supports the security, governance, privacy, resilience, or evidence objective represented by 164.502. The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0089",
      "gaissf_id": "D5-CTL-05",
      "gaissf_title": "PRIVACY-BY-DESIGN VERIFICATION",
      "gaissf_domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "hipaa_section": "164.312(c)",
      "hipaa_title": "Integrity",
      "rule_group": "Technical Safeguards",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "D5-CTL-05 supports the security, governance, privacy, resilience, or evidence objective represented by 164.312(c). The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0090",
      "gaissf_id": "D5-CTL-05",
      "gaissf_title": "PRIVACY-BY-DESIGN VERIFICATION",
      "gaissf_domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "hipaa_section": "164.530",
      "hipaa_title": "Administrative requirements",
      "rule_group": "Privacy Rule",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "D5-CTL-05 supports the security, governance, privacy, resilience, or evidence objective represented by 164.530. The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0091",
      "gaissf_id": "D5-CTL-05",
      "gaissf_title": "PRIVACY-BY-DESIGN VERIFICATION",
      "gaissf_domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "hipaa_section": "164.526",
      "hipaa_title": "Amendment of PHI",
      "rule_group": "Privacy Rule",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "D5-CTL-05 supports the security, governance, privacy, resilience, or evidence objective represented by 164.526. The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0092",
      "gaissf_id": "D5-CTL-06",
      "gaissf_title": "PRIVACY-PRESERVING ML VALIDATION",
      "gaissf_domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "hipaa_section": "164.502",
      "hipaa_title": "Uses and disclosures of PHI: general rules",
      "rule_group": "Privacy Rule",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "D5-CTL-06 supports the security, governance, privacy, resilience, or evidence objective represented by 164.502. The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0093",
      "gaissf_id": "D5-CTL-06",
      "gaissf_title": "PRIVACY-PRESERVING ML VALIDATION",
      "gaissf_domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "hipaa_section": "164.312(c)",
      "hipaa_title": "Integrity",
      "rule_group": "Technical Safeguards",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "D5-CTL-06 supports the security, governance, privacy, resilience, or evidence objective represented by 164.312(c). The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0094",
      "gaissf_id": "D5-CTL-06",
      "gaissf_title": "PRIVACY-PRESERVING ML VALIDATION",
      "gaissf_domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "hipaa_section": "164.530",
      "hipaa_title": "Administrative requirements",
      "rule_group": "Privacy Rule",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "D5-CTL-06 supports the security, governance, privacy, resilience, or evidence objective represented by 164.530. The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0095",
      "gaissf_id": "D5-CTL-06",
      "gaissf_title": "PRIVACY-PRESERVING ML VALIDATION",
      "gaissf_domain": "D5: CONTENT SAFETY & OUTPUT INTEGRITY",
      "hipaa_section": "164.526",
      "hipaa_title": "Amendment of PHI",
      "rule_group": "Privacy Rule",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "D5-CTL-06 supports the security, governance, privacy, resilience, or evidence objective represented by 164.526. The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0096",
      "gaissf_id": "D6-CTL-01",
      "gaissf_title": "HUMAN-IN-THE-LOOP FOR HIGH-RISK ACTIONS",
      "gaissf_domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "hipaa_section": "164.308(a)(2)",
      "hipaa_title": "Assigned security responsibility",
      "rule_group": "Administrative Safeguards",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D6-CTL-01 supports the security, governance, privacy, resilience, or evidence objective represented by 164.308(a)(2). The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0097",
      "gaissf_id": "D6-CTL-01",
      "gaissf_title": "HUMAN-IN-THE-LOOP FOR HIGH-RISK ACTIONS",
      "gaissf_domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "hipaa_section": "164.530",
      "hipaa_title": "Administrative requirements",
      "rule_group": "Privacy Rule",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D6-CTL-01 supports the security, governance, privacy, resilience, or evidence objective represented by 164.530. The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0098",
      "gaissf_id": "D6-CTL-01",
      "gaissf_title": "HUMAN-IN-THE-LOOP FOR HIGH-RISK ACTIONS",
      "gaissf_domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "hipaa_section": "164.504",
      "hipaa_title": "Organizational requirements",
      "rule_group": "Privacy Rule",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D6-CTL-01 supports the security, governance, privacy, resilience, or evidence objective represented by 164.504. The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0099",
      "gaissf_id": "D6-CTL-01",
      "gaissf_title": "HUMAN-IN-THE-LOOP FOR HIGH-RISK ACTIONS",
      "gaissf_domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "hipaa_section": "164.316",
      "hipaa_title": "Policies, procedures and documentation",
      "rule_group": "Security Rule",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D6-CTL-01 supports the security, governance, privacy, resilience, or evidence objective represented by 164.316. The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0100",
      "gaissf_id": "D6-CTL-02",
      "gaissf_title": "AUDIT TRAIL COMPLETENESS",
      "gaissf_domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "hipaa_section": "164.308(a)(2)",
      "hipaa_title": "Assigned security responsibility",
      "rule_group": "Administrative Safeguards",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "D6-CTL-02 supports the security, governance, privacy, resilience, or evidence objective represented by 164.308(a)(2). The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0101",
      "gaissf_id": "D6-CTL-02",
      "gaissf_title": "AUDIT TRAIL COMPLETENESS",
      "gaissf_domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "hipaa_section": "164.316",
      "hipaa_title": "Policies, procedures and documentation",
      "rule_group": "Security Rule",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "D6-CTL-02 supports the security, governance, privacy, resilience, or evidence objective represented by 164.316. The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0102",
      "gaissf_id": "D6-CTL-02",
      "gaissf_title": "AUDIT TRAIL COMPLETENESS",
      "gaissf_domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "hipaa_section": "160.300-552",
      "hipaa_title": "Compliance, investigations and penalties",
      "rule_group": "Enforcement Rule",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "D6-CTL-02 supports the security, governance, privacy, resilience, or evidence objective represented by 160.300-552. The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0103",
      "gaissf_id": "D6-CTL-02",
      "gaissf_title": "AUDIT TRAIL COMPLETENESS",
      "gaissf_domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "hipaa_section": "164.530",
      "hipaa_title": "Administrative requirements",
      "rule_group": "Privacy Rule",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "D6-CTL-02 supports the security, governance, privacy, resilience, or evidence objective represented by 164.530. The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0104",
      "gaissf_id": "D6-CTL-03",
      "gaissf_title": "AI MODEL CARD COMPLETENESS",
      "gaissf_domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "hipaa_section": "164.308(a)(2)",
      "hipaa_title": "Assigned security responsibility",
      "rule_group": "Administrative Safeguards",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D6-CTL-03 supports the security, governance, privacy, resilience, or evidence objective represented by 164.308(a)(2). The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0105",
      "gaissf_id": "D6-CTL-03",
      "gaissf_title": "AI MODEL CARD COMPLETENESS",
      "gaissf_domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "hipaa_section": "164.316",
      "hipaa_title": "Policies, procedures and documentation",
      "rule_group": "Security Rule",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D6-CTL-03 supports the security, governance, privacy, resilience, or evidence objective represented by 164.316. The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0106",
      "gaissf_id": "D6-CTL-03",
      "gaissf_title": "AI MODEL CARD COMPLETENESS",
      "gaissf_domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "hipaa_section": "164.530",
      "hipaa_title": "Administrative requirements",
      "rule_group": "Privacy Rule",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D6-CTL-03 supports the security, governance, privacy, resilience, or evidence objective represented by 164.530. The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0107",
      "gaissf_id": "D6-CTL-03",
      "gaissf_title": "AI MODEL CARD COMPLETENESS",
      "gaissf_domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "hipaa_section": "164.504",
      "hipaa_title": "Organizational requirements",
      "rule_group": "Privacy Rule",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D6-CTL-03 supports the security, governance, privacy, resilience, or evidence objective represented by 164.504. The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0108",
      "gaissf_id": "D6-CTL-04",
      "gaissf_title": "AI INCIDENT RESPONSE READINESS",
      "gaissf_domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "hipaa_section": "164.308(a)(2)",
      "hipaa_title": "Assigned security responsibility",
      "rule_group": "Administrative Safeguards",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "D6-CTL-04 supports the security, governance, privacy, resilience, or evidence objective represented by 164.308(a)(2). The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0109",
      "gaissf_id": "D6-CTL-04",
      "gaissf_title": "AI INCIDENT RESPONSE READINESS",
      "gaissf_domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "hipaa_section": "164.530",
      "hipaa_title": "Administrative requirements",
      "rule_group": "Privacy Rule",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "D6-CTL-04 supports the security, governance, privacy, resilience, or evidence objective represented by 164.530. The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0110",
      "gaissf_id": "D6-CTL-04",
      "gaissf_title": "AI INCIDENT RESPONSE READINESS",
      "gaissf_domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "hipaa_section": "164.400-414",
      "hipaa_title": "Breach notification requirements",
      "rule_group": "Breach Notification Rule",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "D6-CTL-04 supports the security, governance, privacy, resilience, or evidence objective represented by 164.400-414. The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0111",
      "gaissf_id": "D6-CTL-04",
      "gaissf_title": "AI INCIDENT RESPONSE READINESS",
      "gaissf_domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "hipaa_section": "164.308(a)(6)",
      "hipaa_title": "Security incident procedures",
      "rule_group": "Administrative Safeguards",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "D6-CTL-04 supports the security, governance, privacy, resilience, or evidence objective represented by 164.308(a)(6). The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0112",
      "gaissf_id": "D6-CTL-05",
      "gaissf_title": "MODEL DEPRECATION & DECOMMISSIONING",
      "gaissf_domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "hipaa_section": "164.308(a)(2)",
      "hipaa_title": "Assigned security responsibility",
      "rule_group": "Administrative Safeguards",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D6-CTL-05 supports the security, governance, privacy, resilience, or evidence objective represented by 164.308(a)(2). The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0113",
      "gaissf_id": "D6-CTL-05",
      "gaissf_title": "MODEL DEPRECATION & DECOMMISSIONING",
      "gaissf_domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "hipaa_section": "164.530",
      "hipaa_title": "Administrative requirements",
      "rule_group": "Privacy Rule",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D6-CTL-05 supports the security, governance, privacy, resilience, or evidence objective represented by 164.530. The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0114",
      "gaissf_id": "D6-CTL-05",
      "gaissf_title": "MODEL DEPRECATION & DECOMMISSIONING",
      "gaissf_domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "hipaa_section": "164.504",
      "hipaa_title": "Organizational requirements",
      "rule_group": "Privacy Rule",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D6-CTL-05 supports the security, governance, privacy, resilience, or evidence objective represented by 164.504. The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0115",
      "gaissf_id": "D6-CTL-05",
      "gaissf_title": "MODEL DEPRECATION & DECOMMISSIONING",
      "gaissf_domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "hipaa_section": "164.316",
      "hipaa_title": "Policies, procedures and documentation",
      "rule_group": "Security Rule",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D6-CTL-05 supports the security, governance, privacy, resilience, or evidence objective represented by 164.316. The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0116",
      "gaissf_id": "D6-CTL-06",
      "gaissf_title": "THIRD-PARTY AI VENDOR GOVERNANCE",
      "gaissf_domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "hipaa_section": "164.504",
      "hipaa_title": "Organizational requirements",
      "rule_group": "Privacy Rule",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "D6-CTL-06 supports the security, governance, privacy, resilience, or evidence objective represented by 164.504. The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0117",
      "gaissf_id": "D6-CTL-06",
      "gaissf_title": "THIRD-PARTY AI VENDOR GOVERNANCE",
      "gaissf_domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "hipaa_section": "164.308(a)(2)",
      "hipaa_title": "Assigned security responsibility",
      "rule_group": "Administrative Safeguards",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "D6-CTL-06 supports the security, governance, privacy, resilience, or evidence objective represented by 164.308(a)(2). The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0118",
      "gaissf_id": "D6-CTL-06",
      "gaissf_title": "THIRD-PARTY AI VENDOR GOVERNANCE",
      "gaissf_domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "hipaa_section": "164.308(b)",
      "hipaa_title": "Business associate contracts and arrangements",
      "rule_group": "Administrative Safeguards",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "D6-CTL-06 supports the security, governance, privacy, resilience, or evidence objective represented by 164.308(b). The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0119",
      "gaissf_id": "D6-CTL-06",
      "gaissf_title": "THIRD-PARTY AI VENDOR GOVERNANCE",
      "gaissf_domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "hipaa_section": "164.530",
      "hipaa_title": "Administrative requirements",
      "rule_group": "Privacy Rule",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "D6-CTL-06 supports the security, governance, privacy, resilience, or evidence objective represented by 164.530. The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0120",
      "gaissf_id": "D6-CTL-07",
      "gaissf_title": "AI RESILIENCE & BUSINESS CONTINUITY",
      "gaissf_domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "hipaa_section": "164.308(a)(2)",
      "hipaa_title": "Assigned security responsibility",
      "rule_group": "Administrative Safeguards",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "D6-CTL-07 supports the security, governance, privacy, resilience, or evidence objective represented by 164.308(a)(2). The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0121",
      "gaissf_id": "D6-CTL-07",
      "gaissf_title": "AI RESILIENCE & BUSINESS CONTINUITY",
      "gaissf_domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "hipaa_section": "164.308(a)(7)",
      "hipaa_title": "Contingency plan",
      "rule_group": "Administrative Safeguards",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "D6-CTL-07 supports the security, governance, privacy, resilience, or evidence objective represented by 164.308(a)(7). The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0122",
      "gaissf_id": "D6-CTL-07",
      "gaissf_title": "AI RESILIENCE & BUSINESS CONTINUITY",
      "gaissf_domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "hipaa_section": "164.308(a)(1)",
      "hipaa_title": "Security management process",
      "rule_group": "Administrative Safeguards",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "D6-CTL-07 supports the security, governance, privacy, resilience, or evidence objective represented by 164.308(a)(1). The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0123",
      "gaissf_id": "D6-CTL-07",
      "gaissf_title": "AI RESILIENCE & BUSINESS CONTINUITY",
      "gaissf_domain": "D6: GOVERNANCE, ACCOUNTABILITY & HUMAN OVERSIGHT",
      "hipaa_section": "164.530",
      "hipaa_title": "Administrative requirements",
      "rule_group": "Privacy Rule",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "D6-CTL-07 supports the security, governance, privacy, resilience, or evidence objective represented by 164.530. The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0124",
      "gaissf_id": "D7-CTL-H01",
      "gaissf_title": "AI-GENERATED PHISHING SIMULATION",
      "gaissf_domain": "D7: HUMAN & SOCIETAL HARMS",
      "hipaa_section": "164.308(a)(5)",
      "hipaa_title": "Security awareness and training",
      "rule_group": "Administrative Safeguards",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D7-CTL-H01 supports the security, governance, privacy, resilience, or evidence objective represented by 164.308(a)(5). The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0125",
      "gaissf_id": "D7-CTL-H01",
      "gaissf_title": "AI-GENERATED PHISHING SIMULATION",
      "gaissf_domain": "D7: HUMAN & SOCIETAL HARMS",
      "hipaa_section": "164.308(a)(3)",
      "hipaa_title": "Workforce security",
      "rule_group": "Administrative Safeguards",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D7-CTL-H01 supports the security, governance, privacy, resilience, or evidence objective represented by 164.308(a)(3). The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0126",
      "gaissf_id": "D7-CTL-H02",
      "gaissf_title": "DEEPFAKE DETECTION TRAINING",
      "gaissf_domain": "D7: HUMAN & SOCIETAL HARMS",
      "hipaa_section": "164.308(a)(5)",
      "hipaa_title": "Security awareness and training",
      "rule_group": "Administrative Safeguards",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D7-CTL-H02 supports the security, governance, privacy, resilience, or evidence objective represented by 164.308(a)(5). The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0127",
      "gaissf_id": "D7-CTL-H02",
      "gaissf_title": "DEEPFAKE DETECTION TRAINING",
      "gaissf_domain": "D7: HUMAN & SOCIETAL HARMS",
      "hipaa_section": "164.308(a)(3)",
      "hipaa_title": "Workforce security",
      "rule_group": "Administrative Safeguards",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D7-CTL-H02 supports the security, governance, privacy, resilience, or evidence objective represented by 164.308(a)(3). The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0128",
      "gaissf_id": "D7-CTL-H02",
      "gaissf_title": "DEEPFAKE DETECTION TRAINING",
      "gaissf_domain": "D7: HUMAN & SOCIETAL HARMS",
      "hipaa_section": "164.530",
      "hipaa_title": "Administrative requirements",
      "rule_group": "Privacy Rule",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D7-CTL-H02 supports the security, governance, privacy, resilience, or evidence objective represented by 164.530. The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0129",
      "gaissf_id": "D7-CTL-H02",
      "gaissf_title": "DEEPFAKE DETECTION TRAINING",
      "gaissf_domain": "D7: HUMAN & SOCIETAL HARMS",
      "hipaa_section": "164.308(a)(6)",
      "hipaa_title": "Security incident procedures",
      "rule_group": "Administrative Safeguards",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D7-CTL-H02 supports the security, governance, privacy, resilience, or evidence objective represented by 164.308(a)(6). The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0130",
      "gaissf_id": "D7-CTL-H03",
      "gaissf_title": "OUT-OF-BAND AUTHENTICATION",
      "gaissf_domain": "D7: HUMAN & SOCIETAL HARMS",
      "hipaa_section": "164.312(d)",
      "hipaa_title": "Person or entity authentication",
      "rule_group": "Technical Safeguards",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "D7-CTL-H03 supports the security, governance, privacy, resilience, or evidence objective represented by 164.312(d). The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0131",
      "gaissf_id": "D7-CTL-H03",
      "gaissf_title": "OUT-OF-BAND AUTHENTICATION",
      "gaissf_domain": "D7: HUMAN & SOCIETAL HARMS",
      "hipaa_section": "164.308(a)(3)",
      "hipaa_title": "Workforce security",
      "rule_group": "Administrative Safeguards",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "D7-CTL-H03 supports the security, governance, privacy, resilience, or evidence objective represented by 164.308(a)(3). The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0132",
      "gaissf_id": "D7-CTL-H03",
      "gaissf_title": "OUT-OF-BAND AUTHENTICATION",
      "gaissf_domain": "D7: HUMAN & SOCIETAL HARMS",
      "hipaa_section": "164.312(a)",
      "hipaa_title": "Access control",
      "rule_group": "Technical Safeguards",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "D7-CTL-H03 supports the security, governance, privacy, resilience, or evidence objective represented by 164.312(a). The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0133",
      "gaissf_id": "D7-CTL-H04",
      "gaissf_title": "AI SOCIAL ENGINEERING IR",
      "gaissf_domain": "D7: HUMAN & SOCIETAL HARMS",
      "hipaa_section": "164.308(a)(5)",
      "hipaa_title": "Security awareness and training",
      "rule_group": "Administrative Safeguards",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D7-CTL-H04 supports the security, governance, privacy, resilience, or evidence objective represented by 164.308(a)(5). The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0134",
      "gaissf_id": "D7-CTL-H04",
      "gaissf_title": "AI SOCIAL ENGINEERING IR",
      "gaissf_domain": "D7: HUMAN & SOCIETAL HARMS",
      "hipaa_section": "164.308(a)(3)",
      "hipaa_title": "Workforce security",
      "rule_group": "Administrative Safeguards",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D7-CTL-H04 supports the security, governance, privacy, resilience, or evidence objective represented by 164.308(a)(3). The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0135",
      "gaissf_id": "D7-CTL-H05",
      "gaissf_title": "AI-ENHANCED EXTERNAL ATTACK DEFENSE",
      "gaissf_domain": "D7: HUMAN & SOCIETAL HARMS",
      "hipaa_section": "164.308(a)(3)",
      "hipaa_title": "Workforce security",
      "rule_group": "Administrative Safeguards",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D7-CTL-H05 supports the security, governance, privacy, resilience, or evidence objective represented by 164.308(a)(3). The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0136",
      "gaissf_id": "D8-CTL-01",
      "gaissf_title": "EU AI ACT RISK TIER MAPPING",
      "gaissf_domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "hipaa_section": "164.316",
      "hipaa_title": "Policies, procedures and documentation",
      "rule_group": "Security Rule",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D8-CTL-01 supports the security, governance, privacy, resilience, or evidence objective represented by 164.316. The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0137",
      "gaissf_id": "D8-CTL-01",
      "gaissf_title": "EU AI ACT RISK TIER MAPPING",
      "gaissf_domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "hipaa_section": "164.308(a)(1)",
      "hipaa_title": "Security management process",
      "rule_group": "Administrative Safeguards",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D8-CTL-01 supports the security, governance, privacy, resilience, or evidence objective represented by 164.308(a)(1). The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0138",
      "gaissf_id": "D8-CTL-01",
      "gaissf_title": "EU AI ACT RISK TIER MAPPING",
      "gaissf_domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "hipaa_section": "160.300-552",
      "hipaa_title": "Compliance, investigations and penalties",
      "rule_group": "Enforcement Rule",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D8-CTL-01 supports the security, governance, privacy, resilience, or evidence objective represented by 160.300-552. The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0139",
      "gaissf_id": "D8-CTL-02",
      "gaissf_title": "ISO 42001 GAP ANALYSIS",
      "gaissf_domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "hipaa_section": "164.316",
      "hipaa_title": "Policies, procedures and documentation",
      "rule_group": "Security Rule",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D8-CTL-02 supports the security, governance, privacy, resilience, or evidence objective represented by 164.316. The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0140",
      "gaissf_id": "D8-CTL-02",
      "gaissf_title": "ISO 42001 GAP ANALYSIS",
      "gaissf_domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "hipaa_section": "160.300-552",
      "hipaa_title": "Compliance, investigations and penalties",
      "rule_group": "Enforcement Rule",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D8-CTL-02 supports the security, governance, privacy, resilience, or evidence objective represented by 160.300-552. The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0141",
      "gaissf_id": "D8-CTL-03",
      "gaissf_title": "GPAI TECHNICAL DOCUMENTATION VERIFICATION",
      "gaissf_domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "hipaa_section": "164.316",
      "hipaa_title": "Policies, procedures and documentation",
      "rule_group": "Security Rule",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D8-CTL-03 supports the security, governance, privacy, resilience, or evidence objective represented by 164.316. The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0142",
      "gaissf_id": "D8-CTL-03",
      "gaissf_title": "GPAI TECHNICAL DOCUMENTATION VERIFICATION",
      "gaissf_domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "hipaa_section": "160.300-552",
      "hipaa_title": "Compliance, investigations and penalties",
      "rule_group": "Enforcement Rule",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D8-CTL-03 supports the security, governance, privacy, resilience, or evidence objective represented by 160.300-552. The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0143",
      "gaissf_id": "D8-CTL-04",
      "gaissf_title": "DORA ICT INCIDENT REPORTING (FINANCIAL SECTOR)",
      "gaissf_domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "hipaa_section": "164.530",
      "hipaa_title": "Administrative requirements",
      "rule_group": "Privacy Rule",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "D8-CTL-04 supports the security, governance, privacy, resilience, or evidence objective represented by 164.530. The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0144",
      "gaissf_id": "D8-CTL-04",
      "gaissf_title": "DORA ICT INCIDENT REPORTING (FINANCIAL SECTOR)",
      "gaissf_domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "hipaa_section": "164.400-414",
      "hipaa_title": "Breach notification requirements",
      "rule_group": "Breach Notification Rule",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "D8-CTL-04 supports the security, governance, privacy, resilience, or evidence objective represented by 164.400-414. The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0145",
      "gaissf_id": "D8-CTL-04",
      "gaissf_title": "DORA ICT INCIDENT REPORTING (FINANCIAL SECTOR)",
      "gaissf_domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "hipaa_section": "164.316",
      "hipaa_title": "Policies, procedures and documentation",
      "rule_group": "Security Rule",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "D8-CTL-04 supports the security, governance, privacy, resilience, or evidence objective represented by 164.316. The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0146",
      "gaissf_id": "D8-CTL-04",
      "gaissf_title": "DORA ICT INCIDENT REPORTING (FINANCIAL SECTOR)",
      "gaissf_domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "hipaa_section": "164.308(a)(6)",
      "hipaa_title": "Security incident procedures",
      "rule_group": "Administrative Safeguards",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "D8-CTL-04 supports the security, governance, privacy, resilience, or evidence objective represented by 164.308(a)(6). The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0147",
      "gaissf_id": "D8-CTL-05",
      "gaissf_title": "NIST SP 800-218A COMPLIANCE CHECK",
      "gaissf_domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "hipaa_section": "164.316",
      "hipaa_title": "Policies, procedures and documentation",
      "rule_group": "Security Rule",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D8-CTL-05 supports the security, governance, privacy, resilience, or evidence objective represented by 164.316. The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0148",
      "gaissf_id": "D8-CTL-05",
      "gaissf_title": "NIST SP 800-218A COMPLIANCE CHECK",
      "gaissf_domain": "D8: REGULATORY ALIGNMENT & COMPLIANCE",
      "hipaa_section": "160.300-552",
      "hipaa_title": "Compliance, investigations and penalties",
      "rule_group": "Enforcement Rule",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D8-CTL-05 supports the security, governance, privacy, resilience, or evidence objective represented by 160.300-552. The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0149",
      "gaissf_id": "D9-CTL-01",
      "gaissf_title": "PHYSICAL HARM BOUNDARY ENFORCEMENT",
      "gaissf_domain": "D9: PHYSICAL AI SAFETY",
      "hipaa_section": "164.310(a)",
      "hipaa_title": "Facility access controls",
      "rule_group": "Physical Safeguards",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D9-CTL-01 supports the security, governance, privacy, resilience, or evidence objective represented by 164.310(a). The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0150",
      "gaissf_id": "D9-CTL-02",
      "gaissf_title": "SAFE STATE AND GRACEFUL DEGRADATION",
      "gaissf_domain": "D9: PHYSICAL AI SAFETY",
      "hipaa_section": "164.310(a)",
      "hipaa_title": "Facility access controls",
      "rule_group": "Physical Safeguards",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D9-CTL-02 supports the security, governance, privacy, resilience, or evidence objective represented by 164.310(a). The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0151",
      "gaissf_id": "D9-CTL-03",
      "gaissf_title": "HUMAN OVERRIDE AND EMERGENCY STOP",
      "gaissf_domain": "D9: PHYSICAL AI SAFETY",
      "hipaa_section": "164.310(a)",
      "hipaa_title": "Facility access controls",
      "rule_group": "Physical Safeguards",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D9-CTL-03 supports the security, governance, privacy, resilience, or evidence objective represented by 164.310(a). The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0152",
      "gaissf_id": "D9-CTL-03",
      "gaissf_title": "HUMAN OVERRIDE AND EMERGENCY STOP",
      "gaissf_domain": "D9: PHYSICAL AI SAFETY",
      "hipaa_section": "164.308(a)(3)",
      "hipaa_title": "Workforce security",
      "rule_group": "Administrative Safeguards",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D9-CTL-03 supports the security, governance, privacy, resilience, or evidence objective represented by 164.308(a)(3). The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0153",
      "gaissf_id": "D9-CTL-04",
      "gaissf_title": "CYBER-PHYSICAL ATTACK DETECTION",
      "gaissf_domain": "D9: PHYSICAL AI SAFETY",
      "hipaa_section": "164.310(a)",
      "hipaa_title": "Facility access controls",
      "rule_group": "Physical Safeguards",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D9-CTL-04 supports the security, governance, privacy, resilience, or evidence objective represented by 164.310(a). The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0154",
      "gaissf_id": "D9-CTL-04",
      "gaissf_title": "CYBER-PHYSICAL ATTACK DETECTION",
      "gaissf_domain": "D9: PHYSICAL AI SAFETY",
      "hipaa_section": "164.308(a)(6)",
      "hipaa_title": "Security incident procedures",
      "rule_group": "Administrative Safeguards",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D9-CTL-04 supports the security, governance, privacy, resilience, or evidence objective represented by 164.308(a)(6). The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0155",
      "gaissf_id": "D9-CTL-05",
      "gaissf_title": "PHYSICAL ENVIRONMENT INTEGRITY MONITORING",
      "gaissf_domain": "D9: PHYSICAL AI SAFETY",
      "hipaa_section": "164.526",
      "hipaa_title": "Amendment of PHI",
      "rule_group": "Privacy Rule",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D9-CTL-05 supports the security, governance, privacy, resilience, or evidence objective represented by 164.526. The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0156",
      "gaissf_id": "D9-CTL-05",
      "gaissf_title": "PHYSICAL ENVIRONMENT INTEGRITY MONITORING",
      "gaissf_domain": "D9: PHYSICAL AI SAFETY",
      "hipaa_section": "164.312(c)",
      "hipaa_title": "Integrity",
      "rule_group": "Technical Safeguards",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D9-CTL-05 supports the security, governance, privacy, resilience, or evidence objective represented by 164.312(c). The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0157",
      "gaissf_id": "D9-CTL-05",
      "gaissf_title": "PHYSICAL ENVIRONMENT INTEGRITY MONITORING",
      "gaissf_domain": "D9: PHYSICAL AI SAFETY",
      "hipaa_section": "164.312(b)",
      "hipaa_title": "Audit controls",
      "rule_group": "Technical Safeguards",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D9-CTL-05 supports the security, governance, privacy, resilience, or evidence objective represented by 164.312(b). The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0158",
      "gaissf_id": "D9-CTL-05",
      "gaissf_title": "PHYSICAL ENVIRONMENT INTEGRITY MONITORING",
      "gaissf_domain": "D9: PHYSICAL AI SAFETY",
      "hipaa_section": "164.310(a)",
      "hipaa_title": "Facility access controls",
      "rule_group": "Physical Safeguards",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D9-CTL-05 supports the security, governance, privacy, resilience, or evidence objective represented by 164.310(a). The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0159",
      "gaissf_id": "D9-CTL-06",
      "gaissf_title": "ACTUATOR COMMAND VERIFICATION",
      "gaissf_domain": "D9: PHYSICAL AI SAFETY",
      "hipaa_section": "164.310(a)",
      "hipaa_title": "Facility access controls",
      "rule_group": "Physical Safeguards",
      "relationship": "P",
      "coverage": "Partially Addressed",
      "confidence": "Medium",
      "rationale": "D9-CTL-06 supports the security, governance, privacy, resilience, or evidence objective represented by 164.310(a). The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0160",
      "gaissf_id": "D9-CTL-07",
      "gaissf_title": "PHYSICAL INCIDENT EVIDENCE PRESERVATION",
      "gaissf_domain": "D9: PHYSICAL AI SAFETY",
      "hipaa_section": "164.530",
      "hipaa_title": "Administrative requirements",
      "rule_group": "Privacy Rule",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "D9-CTL-07 supports the security, governance, privacy, resilience, or evidence objective represented by 164.530. The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0161",
      "gaissf_id": "D9-CTL-07",
      "gaissf_title": "PHYSICAL INCIDENT EVIDENCE PRESERVATION",
      "gaissf_domain": "D9: PHYSICAL AI SAFETY",
      "hipaa_section": "164.400-414",
      "hipaa_title": "Breach notification requirements",
      "rule_group": "Breach Notification Rule",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "D9-CTL-07 supports the security, governance, privacy, resilience, or evidence objective represented by 164.400-414. The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0162",
      "gaissf_id": "D9-CTL-07",
      "gaissf_title": "PHYSICAL INCIDENT EVIDENCE PRESERVATION",
      "gaissf_domain": "D9: PHYSICAL AI SAFETY",
      "hipaa_section": "164.310(a)",
      "hipaa_title": "Facility access controls",
      "rule_group": "Physical Safeguards",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "D9-CTL-07 supports the security, governance, privacy, resilience, or evidence objective represented by 164.310(a). The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    },
    {
      "record_id": "GAISSF-CRO-035-MAP-0163",
      "gaissf_id": "D9-CTL-07",
      "gaissf_title": "PHYSICAL INCIDENT EVIDENCE PRESERVATION",
      "gaissf_domain": "D9: PHYSICAL AI SAFETY",
      "hipaa_section": "164.308(a)(6)",
      "hipaa_title": "Security incident procedures",
      "rule_group": "Administrative Safeguards",
      "relationship": "SP",
      "coverage": "Partially Addressed",
      "confidence": "Medium-High",
      "rationale": "D9-CTL-07 supports the security, governance, privacy, resilience, or evidence objective represented by 164.308(a)(6). The relationship is functional, not legal equivalence.",
      "residual_gap": "HIPAA-specific applicability, covered-entity/business-associate status, PHI/ePHI scope, required-versus-addressable implementation specifications, reasonableness, documentation, breach analysis, legal permissions, and evidence sufficiency remain separate."
    }
  ],
  "reverse_coverage": [
    {
      "section": "160.103",
      "title": "Definitions",
      "group": "General Provisions",
      "mapped_controls": [],
      "mapped_count": 0,
      "coverage_status": "Not Addressed",
      "residual_gap": "HIPAA-specific applicability, legal permissions, individual rights, documentation, breach notification, entity status, and evidence sufficiency require separate implementation and legal review."
    },
    {
      "section": "160.203",
      "title": "General rule and exceptions",
      "group": "Preemption",
      "mapped_controls": [],
      "mapped_count": 0,
      "coverage_status": "Not Addressed",
      "residual_gap": "HIPAA-specific applicability, legal permissions, individual rights, documentation, breach notification, entity status, and evidence sufficiency require separate implementation and legal review."
    },
    {
      "section": "164.105",
      "title": "Organizational requirements",
      "group": "General Requirements",
      "mapped_controls": [],
      "mapped_count": 0,
      "coverage_status": "Not Addressed",
      "residual_gap": "HIPAA-specific applicability, legal permissions, individual rights, documentation, breach notification, entity status, and evidence sufficiency require separate implementation and legal review."
    },
    {
      "section": "164.306",
      "title": "Security standards: general rules",
      "group": "Security Rule",
      "mapped_controls": [],
      "mapped_count": 0,
      "coverage_status": "Not Addressed",
      "residual_gap": "HIPAA-specific applicability, legal permissions, individual rights, documentation, breach notification, entity status, and evidence sufficiency require separate implementation and legal review."
    },
    {
      "section": "164.308(a)(1)",
      "title": "Security management process",
      "group": "Administrative Safeguards",
      "mapped_controls": [
        "D1-CTL-01",
        "D1-CTL-02",
        "D1-CTL-03",
        "D1-CTL-04",
        "D1-CTL-05",
        "D1-CTL-06",
        "D1-CTL-07",
        "D1-CTL-08",
        "D1-CTL-09",
        "D2-CTL-01",
        "D2-CTL-02",
        "D2-CTL-03",
        "D2-CTL-04",
        "D2-CTL-05",
        "D2-CTL-06",
        "D3-CTL-01",
        "D3-CTL-02",
        "D3-CTL-03",
        "D3-CTL-04",
        "D3-CTL-05",
        "D3-CTL-06",
        "D3-CTL-07",
        "D6-CTL-07",
        "D8-CTL-01"
      ],
      "mapped_count": 24,
      "coverage_status": "Partially Addressed",
      "residual_gap": "HIPAA-specific applicability, legal permissions, individual rights, documentation, breach notification, entity status, and evidence sufficiency require separate implementation and legal review."
    },
    {
      "section": "164.308(a)(2)",
      "title": "Assigned security responsibility",
      "group": "Administrative Safeguards",
      "mapped_controls": [
        "D6-CTL-01",
        "D6-CTL-02",
        "D6-CTL-03",
        "D6-CTL-04",
        "D6-CTL-05",
        "D6-CTL-06",
        "D6-CTL-07"
      ],
      "mapped_count": 7,
      "coverage_status": "Partially Addressed",
      "residual_gap": "HIPAA-specific applicability, legal permissions, individual rights, documentation, breach notification, entity status, and evidence sufficiency require separate implementation and legal review."
    },
    {
      "section": "164.308(a)(3)",
      "title": "Workforce security",
      "group": "Administrative Safeguards",
      "mapped_controls": [
        "D7-CTL-H01",
        "D7-CTL-H02",
        "D7-CTL-H03",
        "D7-CTL-H04",
        "D7-CTL-H05",
        "D9-CTL-03"
      ],
      "mapped_count": 6,
      "coverage_status": "Partially Addressed",
      "residual_gap": "HIPAA-specific applicability, legal permissions, individual rights, documentation, breach notification, entity status, and evidence sufficiency require separate implementation and legal review."
    },
    {
      "section": "164.308(a)(4)",
      "title": "Information access management",
      "group": "Administrative Safeguards",
      "mapped_controls": [],
      "mapped_count": 0,
      "coverage_status": "Not Addressed",
      "residual_gap": "HIPAA-specific applicability, legal permissions, individual rights, documentation, breach notification, entity status, and evidence sufficiency require separate implementation and legal review."
    },
    {
      "section": "164.308(a)(5)",
      "title": "Security awareness and training",
      "group": "Administrative Safeguards",
      "mapped_controls": [
        "D7-CTL-H01",
        "D7-CTL-H02",
        "D7-CTL-H04"
      ],
      "mapped_count": 3,
      "coverage_status": "Partially Addressed",
      "residual_gap": "HIPAA-specific applicability, legal permissions, individual rights, documentation, breach notification, entity status, and evidence sufficiency require separate implementation and legal review."
    },
    {
      "section": "164.308(a)(6)",
      "title": "Security incident procedures",
      "group": "Administrative Safeguards",
      "mapped_controls": [
        "D1-CTL-03",
        "D1-CTL-08",
        "D3-CTL-03",
        "D4-CTL-04",
        "D5-CTL-03",
        "D6-CTL-04",
        "D7-CTL-H02",
        "D8-CTL-04",
        "D9-CTL-04",
        "D9-CTL-07"
      ],
      "mapped_count": 10,
      "coverage_status": "Partially Addressed",
      "residual_gap": "HIPAA-specific applicability, legal permissions, individual rights, documentation, breach notification, entity status, and evidence sufficiency require separate implementation and legal review."
    },
    {
      "section": "164.308(a)(7)",
      "title": "Contingency plan",
      "group": "Administrative Safeguards",
      "mapped_controls": [
        "D6-CTL-07"
      ],
      "mapped_count": 1,
      "coverage_status": "Partially Addressed",
      "residual_gap": "HIPAA-specific applicability, legal permissions, individual rights, documentation, breach notification, entity status, and evidence sufficiency require separate implementation and legal review."
    },
    {
      "section": "164.308(a)(8)",
      "title": "Evaluation",
      "group": "Administrative Safeguards",
      "mapped_controls": [
        "D2-CTL-03",
        "D3-CTL-05",
        "D4-CTL-05"
      ],
      "mapped_count": 3,
      "coverage_status": "Partially Addressed",
      "residual_gap": "HIPAA-specific applicability, legal permissions, individual rights, documentation, breach notification, entity status, and evidence sufficiency require separate implementation and legal review."
    },
    {
      "section": "164.308(b)",
      "title": "Business associate contracts and arrangements",
      "group": "Administrative Safeguards",
      "mapped_controls": [
        "D4-CTL-01",
        "D4-CTL-02",
        "D4-CTL-03",
        "D4-CTL-04",
        "D4-CTL-05",
        "D4-CTL-06",
        "D4-CTL-07",
        "D6-CTL-06"
      ],
      "mapped_count": 8,
      "coverage_status": "Partially Addressed",
      "residual_gap": "HIPAA-specific applicability, legal permissions, individual rights, documentation, breach notification, entity status, and evidence sufficiency require separate implementation and legal review."
    },
    {
      "section": "164.310(a)",
      "title": "Facility access controls",
      "group": "Physical Safeguards",
      "mapped_controls": [
        "D9-CTL-01",
        "D9-CTL-02",
        "D9-CTL-03",
        "D9-CTL-04",
        "D9-CTL-05",
        "D9-CTL-06",
        "D9-CTL-07"
      ],
      "mapped_count": 7,
      "coverage_status": "Partially Addressed",
      "residual_gap": "HIPAA-specific applicability, legal permissions, individual rights, documentation, breach notification, entity status, and evidence sufficiency require separate implementation and legal review."
    },
    {
      "section": "164.310(b)",
      "title": "Workstation use",
      "group": "Physical Safeguards",
      "mapped_controls": [
        "D2-CTL-01",
        "D2-CTL-02",
        "D2-CTL-03",
        "D2-CTL-04",
        "D2-CTL-05",
        "D2-CTL-06"
      ],
      "mapped_count": 6,
      "coverage_status": "Partially Addressed",
      "residual_gap": "HIPAA-specific applicability, legal permissions, individual rights, documentation, breach notification, entity status, and evidence sufficiency require separate implementation and legal review."
    },
    {
      "section": "164.310(c)",
      "title": "Workstation security",
      "group": "Physical Safeguards",
      "mapped_controls": [],
      "mapped_count": 0,
      "coverage_status": "Not Addressed",
      "residual_gap": "HIPAA-specific applicability, legal permissions, individual rights, documentation, breach notification, entity status, and evidence sufficiency require separate implementation and legal review."
    },
    {
      "section": "164.310(d)",
      "title": "Device and media controls",
      "group": "Physical Safeguards",
      "mapped_controls": [
        "D1-CTL-01"
      ],
      "mapped_count": 1,
      "coverage_status": "Partially Addressed",
      "residual_gap": "HIPAA-specific applicability, legal permissions, individual rights, documentation, breach notification, entity status, and evidence sufficiency require separate implementation and legal review."
    },
    {
      "section": "164.312(a)",
      "title": "Access control",
      "group": "Technical Safeguards",
      "mapped_controls": [
        "D7-CTL-H03"
      ],
      "mapped_count": 1,
      "coverage_status": "Partially Addressed",
      "residual_gap": "HIPAA-specific applicability, legal permissions, individual rights, documentation, breach notification, entity status, and evidence sufficiency require separate implementation and legal review."
    },
    {
      "section": "164.312(b)",
      "title": "Audit controls",
      "group": "Technical Safeguards",
      "mapped_controls": [
        "D4-CTL-04",
        "D9-CTL-05"
      ],
      "mapped_count": 2,
      "coverage_status": "Partially Addressed",
      "residual_gap": "HIPAA-specific applicability, legal permissions, individual rights, documentation, breach notification, entity status, and evidence sufficiency require separate implementation and legal review."
    },
    {
      "section": "164.312(c)",
      "title": "Integrity",
      "group": "Technical Safeguards",
      "mapped_controls": [
        "D1-CTL-01",
        "D1-CTL-02",
        "D1-CTL-03",
        "D1-CTL-04",
        "D1-CTL-05",
        "D1-CTL-06",
        "D1-CTL-07",
        "D1-CTL-08",
        "D1-CTL-09",
        "D5-CTL-01",
        "D5-CTL-02",
        "D5-CTL-03",
        "D5-CTL-04",
        "D5-CTL-05",
        "D5-CTL-06",
        "D9-CTL-05"
      ],
      "mapped_count": 16,
      "coverage_status": "Partially Addressed",
      "residual_gap": "HIPAA-specific applicability, legal permissions, individual rights, documentation, breach notification, entity status, and evidence sufficiency require separate implementation and legal review."
    },
    {
      "section": "164.312(d)",
      "title": "Person or entity authentication",
      "group": "Technical Safeguards",
      "mapped_controls": [
        "D7-CTL-H03"
      ],
      "mapped_count": 1,
      "coverage_status": "Partially Addressed",
      "residual_gap": "HIPAA-specific applicability, legal permissions, individual rights, documentation, breach notification, entity status, and evidence sufficiency require separate implementation and legal review."
    },
    {
      "section": "164.312(e)",
      "title": "Transmission security",
      "group": "Technical Safeguards",
      "mapped_controls": [
        "D3-CTL-06"
      ],
      "mapped_count": 1,
      "coverage_status": "Partially Addressed",
      "residual_gap": "HIPAA-specific applicability, legal permissions, individual rights, documentation, breach notification, entity status, and evidence sufficiency require separate implementation and legal review."
    },
    {
      "section": "164.314",
      "title": "Organizational requirements",
      "group": "Security Rule",
      "mapped_controls": [],
      "mapped_count": 0,
      "coverage_status": "Not Addressed",
      "residual_gap": "HIPAA-specific applicability, legal permissions, individual rights, documentation, breach notification, entity status, and evidence sufficiency require separate implementation and legal review."
    },
    {
      "section": "164.316",
      "title": "Policies, procedures and documentation",
      "group": "Security Rule",
      "mapped_controls": [
        "D4-CTL-06",
        "D6-CTL-01",
        "D6-CTL-02",
        "D6-CTL-03",
        "D6-CTL-05",
        "D8-CTL-01",
        "D8-CTL-02",
        "D8-CTL-03",
        "D8-CTL-04",
        "D8-CTL-05"
      ],
      "mapped_count": 10,
      "coverage_status": "Partially Addressed",
      "residual_gap": "HIPAA-specific applicability, legal permissions, individual rights, documentation, breach notification, entity status, and evidence sufficiency require separate implementation and legal review."
    },
    {
      "section": "164.502",
      "title": "Uses and disclosures of PHI: general rules",
      "group": "Privacy Rule",
      "mapped_controls": [
        "D5-CTL-01",
        "D5-CTL-02",
        "D5-CTL-03",
        "D5-CTL-04",
        "D5-CTL-05",
        "D5-CTL-06"
      ],
      "mapped_count": 6,
      "coverage_status": "Partially Addressed",
      "residual_gap": "HIPAA-specific applicability, legal permissions, individual rights, documentation, breach notification, entity status, and evidence sufficiency require separate implementation and legal review."
    },
    {
      "section": "164.504",
      "title": "Organizational requirements",
      "group": "Privacy Rule",
      "mapped_controls": [
        "D4-CTL-01",
        "D4-CTL-02",
        "D4-CTL-03",
        "D4-CTL-04",
        "D4-CTL-05",
        "D4-CTL-06",
        "D4-CTL-07",
        "D6-CTL-01",
        "D6-CTL-03",
        "D6-CTL-05",
        "D6-CTL-06"
      ],
      "mapped_count": 11,
      "coverage_status": "Partially Addressed",
      "residual_gap": "HIPAA-specific applicability, legal permissions, individual rights, documentation, breach notification, entity status, and evidence sufficiency require separate implementation and legal review."
    },
    {
      "section": "164.506",
      "title": "Uses and disclosures for treatment, payment, operations",
      "group": "Privacy Rule",
      "mapped_controls": [],
      "mapped_count": 0,
      "coverage_status": "Not Addressed",
      "residual_gap": "HIPAA-specific applicability, legal permissions, individual rights, documentation, breach notification, entity status, and evidence sufficiency require separate implementation and legal review."
    },
    {
      "section": "164.508",
      "title": "Uses and disclosures requiring authorization",
      "group": "Privacy Rule",
      "mapped_controls": [],
      "mapped_count": 0,
      "coverage_status": "Not Addressed",
      "residual_gap": "HIPAA-specific applicability, legal permissions, individual rights, documentation, breach notification, entity status, and evidence sufficiency require separate implementation and legal review."
    },
    {
      "section": "164.514",
      "title": "Other requirements relating to uses and disclosures",
      "group": "Privacy Rule",
      "mapped_controls": [
        "D5-CTL-02"
      ],
      "mapped_count": 1,
      "coverage_status": "Partially Addressed",
      "residual_gap": "HIPAA-specific applicability, legal permissions, individual rights, documentation, breach notification, entity status, and evidence sufficiency require separate implementation and legal review."
    },
    {
      "section": "164.520",
      "title": "Notice of privacy practices",
      "group": "Privacy Rule",
      "mapped_controls": [],
      "mapped_count": 0,
      "coverage_status": "Not Addressed",
      "residual_gap": "HIPAA-specific applicability, legal permissions, individual rights, documentation, breach notification, entity status, and evidence sufficiency require separate implementation and legal review."
    },
    {
      "section": "164.522",
      "title": "Rights to request privacy protection",
      "group": "Privacy Rule",
      "mapped_controls": [],
      "mapped_count": 0,
      "coverage_status": "Not Addressed",
      "residual_gap": "HIPAA-specific applicability, legal permissions, individual rights, documentation, breach notification, entity status, and evidence sufficiency require separate implementation and legal review."
    },
    {
      "section": "164.524",
      "title": "Access of individuals to PHI",
      "group": "Privacy Rule",
      "mapped_controls": [],
      "mapped_count": 0,
      "coverage_status": "Not Addressed",
      "residual_gap": "HIPAA-specific applicability, legal permissions, individual rights, documentation, breach notification, entity status, and evidence sufficiency require separate implementation and legal review."
    },
    {
      "section": "164.526",
      "title": "Amendment of PHI",
      "group": "Privacy Rule",
      "mapped_controls": [
        "D1-CTL-01",
        "D1-CTL-02",
        "D1-CTL-03",
        "D1-CTL-04",
        "D1-CTL-05",
        "D1-CTL-06",
        "D1-CTL-07",
        "D1-CTL-08",
        "D1-CTL-09",
        "D5-CTL-01",
        "D5-CTL-02",
        "D5-CTL-03",
        "D5-CTL-04",
        "D5-CTL-05",
        "D5-CTL-06",
        "D9-CTL-05"
      ],
      "mapped_count": 16,
      "coverage_status": "Partially Addressed",
      "residual_gap": "HIPAA-specific applicability, legal permissions, individual rights, documentation, breach notification, entity status, and evidence sufficiency require separate implementation and legal review."
    },
    {
      "section": "164.528",
      "title": "Accounting of disclosures",
      "group": "Privacy Rule",
      "mapped_controls": [],
      "mapped_count": 0,
      "coverage_status": "Not Addressed",
      "residual_gap": "HIPAA-specific applicability, legal permissions, individual rights, documentation, breach notification, entity status, and evidence sufficiency require separate implementation and legal review."
    },
    {
      "section": "164.530",
      "title": "Administrative requirements",
      "group": "Privacy Rule",
      "mapped_controls": [
        "D4-CTL-06",
        "D5-CTL-05",
        "D5-CTL-06",
        "D6-CTL-01",
        "D6-CTL-02",
        "D6-CTL-03",
        "D6-CTL-04",
        "D6-CTL-05",
        "D6-CTL-06",
        "D6-CTL-07",
        "D7-CTL-H02",
        "D8-CTL-04",
        "D9-CTL-07"
      ],
      "mapped_count": 13,
      "coverage_status": "Partially Addressed",
      "residual_gap": "HIPAA-specific applicability, legal permissions, individual rights, documentation, breach notification, entity status, and evidence sufficiency require separate implementation and legal review."
    },
    {
      "section": "164.532",
      "title": "Transition provisions",
      "group": "Privacy Rule",
      "mapped_controls": [],
      "mapped_count": 0,
      "coverage_status": "Not Addressed",
      "residual_gap": "HIPAA-specific applicability, legal permissions, individual rights, documentation, breach notification, entity status, and evidence sufficiency require separate implementation and legal review."
    },
    {
      "section": "164.534",
      "title": "Compliance dates",
      "group": "Privacy Rule",
      "mapped_controls": [],
      "mapped_count": 0,
      "coverage_status": "Not Addressed",
      "residual_gap": "HIPAA-specific applicability, legal permissions, individual rights, documentation, breach notification, entity status, and evidence sufficiency require separate implementation and legal review."
    },
    {
      "section": "164.400-414",
      "title": "Breach notification requirements",
      "group": "Breach Notification Rule",
      "mapped_controls": [
        "D3-CTL-06",
        "D6-CTL-04",
        "D8-CTL-04",
        "D9-CTL-07"
      ],
      "mapped_count": 4,
      "coverage_status": "Partially Addressed",
      "residual_gap": "HIPAA-specific applicability, legal permissions, individual rights, documentation, breach notification, entity status, and evidence sufficiency require separate implementation and legal review."
    },
    {
      "section": "160.300-552",
      "title": "Compliance, investigations and penalties",
      "group": "Enforcement Rule",
      "mapped_controls": [
        "D6-CTL-02",
        "D8-CTL-01",
        "D8-CTL-02",
        "D8-CTL-03",
        "D8-CTL-05"
      ],
      "mapped_count": 5,
      "coverage_status": "Partially Addressed",
      "residual_gap": "HIPAA-specific applicability, legal permissions, individual rights, documentation, breach notification, entity status, and evidence sufficiency require separate implementation and legal review."
    }
  ],
  "limitations": [
    "Mapping does not establish HIPAA compliance, legal equivalence, evidence sufficiency, operating effectiveness, HHS endorsement, or automatic GAISSF conformance.",
    "Covered entity or business associate status is not determined by this crosswalk.",
    "PHI/ePHI scope, permitted or required uses/disclosures, breach determinations, and individual-rights obligations require separate legal and operational analysis.",
    "State health-privacy laws, FTC health-breach requirements, 42 CFR Part 2, genetic-information rules, contractual duties, and sector-specific requirements may impose additional obligations.",
    "The 2024 HIPAA Security Rule NPRM remains non-binding; the current Security Rule remains in effect.",
    "The 2024 reproductive-health Privacy Rule was largely vacated on 18 June 2025; remaining Notice of Privacy Practices modifications remain in effect.",
    "D9 is additional/conditional. Where Physical AI is in scope, PAI-SF™ v1.0 may be used alongside GAISSF; CSX-PAISF-004 is mapping only.",
    "Independent crosswalk review and explicit publication approval remain open."
  ]
}