# CRO-035 — GAISSF–HIPAA Mapping **Version:** 1.0 **Status:** Publication Candidate **Publisher:** ODA3 Institute **Baseline date:** 29 June 2026 ## Scope This crosswalk maps 59 GAISSF v1.0 controls to 39 operationally material provisions of the HIPAA Privacy, Security, Breach Notification, and Enforcement Rules. It contains 163 forward mapping records. ## Important limitation Mapping does not establish HIPAA compliance, covered-entity or business-associate status, PHI/ePHI scope, permitted uses or disclosures, breach-reportability, or HHS endorsement. The proposed HIPAA Security Rule modernization is excluded because it is not final. ## Rule-level coverage | Provision | Title | Group | Mapped controls | Coverage | |---|---|---|---:|---| | 160.103 | Definitions | General Provisions | 0 | Not Addressed | | 160.203 | General rule and exceptions | Preemption | 0 | Not Addressed | | 164.105 | Organizational requirements | General Requirements | 0 | Not Addressed | | 164.306 | Security standards: general rules | Security Rule | 0 | Not Addressed | | 164.308(a)(1) | Security management process | Administrative Safeguards | 24 | Partially Addressed | | 164.308(a)(2) | Assigned security responsibility | Administrative Safeguards | 7 | Partially Addressed | | 164.308(a)(3) | Workforce security | Administrative Safeguards | 6 | Partially Addressed | | 164.308(a)(4) | Information access management | Administrative Safeguards | 0 | Not Addressed | | 164.308(a)(5) | Security awareness and training | Administrative Safeguards | 3 | Partially Addressed | | 164.308(a)(6) | Security incident procedures | Administrative Safeguards | 10 | Partially Addressed | | 164.308(a)(7) | Contingency plan | Administrative Safeguards | 1 | Partially Addressed | | 164.308(a)(8) | Evaluation | Administrative Safeguards | 3 | Partially Addressed | | 164.308(b) | Business associate contracts and arrangements | Administrative Safeguards | 8 | Partially Addressed | | 164.310(a) | Facility access controls | Physical Safeguards | 7 | Partially Addressed | | 164.310(b) | Workstation use | Physical Safeguards | 6 | Partially Addressed | | 164.310(c) | Workstation security | Physical Safeguards | 0 | Not Addressed | | 164.310(d) | Device and media controls | Physical Safeguards | 1 | Partially Addressed | | 164.312(a) | Access control | Technical Safeguards | 1 | Partially Addressed | | 164.312(b) | Audit controls | Technical Safeguards | 2 | Partially Addressed | | 164.312(c) | Integrity | Technical Safeguards | 16 | Partially Addressed | | 164.312(d) | Person or entity authentication | Technical Safeguards | 1 | Partially Addressed | | 164.312(e) | Transmission security | Technical Safeguards | 1 | Partially Addressed | | 164.314 | Organizational requirements | Security Rule | 0 | Not Addressed | | 164.316 | Policies, procedures and documentation | Security Rule | 10 | Partially Addressed | | 164.502 | Uses and disclosures of PHI: general rules | Privacy Rule | 6 | Partially Addressed | | 164.504 | Organizational requirements | Privacy Rule | 11 | Partially Addressed | | 164.506 | Uses and disclosures for treatment, payment, operations | Privacy Rule | 0 | Not Addressed | | 164.508 | Uses and disclosures requiring authorization | Privacy Rule | 0 | Not Addressed | | 164.514 | Other requirements relating to uses and disclosures | Privacy Rule | 1 | Partially Addressed | | 164.520 | Notice of privacy practices | Privacy Rule | 0 | Not Addressed | | 164.522 | Rights to request privacy protection | Privacy Rule | 0 | Not Addressed | | 164.524 | Access of individuals to PHI | Privacy Rule | 0 | Not Addressed | | 164.526 | Amendment of PHI | Privacy Rule | 16 | Partially Addressed | | 164.528 | Accounting of disclosures | Privacy Rule | 0 | Not Addressed | | 164.530 | Administrative requirements | Privacy Rule | 13 | Partially Addressed | | 164.532 | Transition provisions | Privacy Rule | 0 | Not Addressed | | 164.534 | Compliance dates | Privacy Rule | 0 | Not Addressed | | 164.400-414 | Breach notification requirements | Breach Notification Rule | 4 | Partially Addressed | | 160.300-552 | Compliance, investigations and penalties | Enforcement Rule | 5 | Partially Addressed | ## Notably Absent No certification, safe harbor, legal advice, permitted-use determination, state-law analysis, or substitute for a HIPAA Security Risk Analysis. © 2026 ODA3 Pvt Ltd. Published by ODA3 Institute.