Skip to content

    HIPAA (Security, Privacy and Breach Notification Rules) to HITRUST CSF v11 control mapping

    HIPAA (Security, Privacy and Breach Notification Rules) and HITRUST CSF v11 both map to 53 NIST SP 800-53 controls. Every one is listed below, with the controls on each side that map to it.

    Shared NIST 800-53 controls
    53
    HIPAA (Security, Privacy and Breach Notification Rules) controls involved
    159
    HITRUST CSF v11 controls involved
    63
    NIST 800-53 families touched
    19

    How this pairing is derived

    Both frameworks are mapped to NIST SP 800-53 Rev 5 in the source dataset, so the ground they share is the set of NIST controls they both reference. That set is what the table shows. It is not an authored HIPAA (Security, Privacy and Breach Notification Rules) to HITRUST CSF v11 crosswalk: two controls on the same row are related through the NIST control between them, not asserted to be equivalent to each other.

    Shared controls in full

    NIST SP 800-53 Rev 5 controls mapped by both HIPAA (Security, Privacy and Breach Notification Rules) and HITRUST CSF v11, with the controls on each side that map to them.
    NIST 800-53 controlFamilyHIPAA (Security, Privacy and Breach Notification Rules) controlsHITRUST CSF v11 controls
    AC-1Policy and ProceduresACAccess Control164.308(a)(1)(i), 164.308(a)(3)(i), 164.308(a)(4)(i), 164.308(a)(4)(ii)(A), 164.308(a)(4)(ii)(B), 164.308(a)(6)(i), 164.308(a)(7)(i), 164.310(a)(1), 164.310(a)(2)(ii), 164.310(a)(2)(iii), 164.310(a)(2)(iv), 164.310(b), 164.310(d)(1), 164.310(d)(2)(i), 164.312(a)(1), 164.312(c)(1), 164.316(a), 164.316(b)(1), 164.316(b)(2)(iii), 164.530(c)(2)(ii), 164.530(i)(2)(i), 164.530(i)(2)(ii), 164.530(i)(2)(iii), 164.530(i)(3), 164.530(j)(1)(i)HITRUST-01.c
    AC-2Account ManagementACAccess Control164.308(a)(3)(ii)(C), 164.312(a)(2)(ii)HITRUST-01.d, HITRUST-01.h, HITRUST-01.p
    AC-6Least PrivilegeACAccess Control164.308(a)(3)(i), 164.312(a)(1)HITRUST-01.i, HITRUST-01.j
    AC-12Session TerminationACAccess Control164.312(a)(2)(iii)HITRUST-01.s
    AT-3Role-based TrainingATAwareness and Training164.308(a)(5)(ii)(C), 164.308(a)(5)(ii)(D), 164.530(b)(1)HITRUST-02.b, HITRUST-02.d
    AU-1Policy and ProceduresAUAudit and Accountability164.308(a)(1)(i), 164.308(a)(1)(ii)(D), 164.308(a)(3)(i), 164.308(a)(4)(i), 164.308(a)(4)(ii)(A), 164.308(a)(6)(i), 164.308(a)(7)(i), 164.310(a)(1), 164.310(a)(2)(ii), 164.310(a)(2)(iv), 164.310(b), 164.310(d)(1), 164.310(d)(2)(i), 164.312(a)(1), 164.312(b), 164.312(c)(1), 164.316(a), 164.316(b)(1), 164.316(b)(2)(iii), 164.530(i)(2)(i), 164.530(i)(2)(ii), 164.530(i)(2)(iii), 164.530(i)(3), 164.530(j)(1)(i)HITRUST-09.aa
    AU-2Event LoggingAUAudit and Accountability164.308(a)(1)(ii)(D), 164.312(b)HITRUST-09.aa
    AU-3Content of Audit RecordsAUAudit and Accountability164.312(b)HITRUST-09.aa
    CM-1Policy and ProceduresCMConfiguration Management164.308(a)(1)(i), 164.308(a)(3)(i), 164.308(a)(4)(i), 164.308(a)(4)(ii)(A), 164.308(a)(6)(i), 164.308(a)(7)(i), 164.310(a)(1), 164.310(a)(2)(ii), 164.310(a)(2)(iv), 164.310(b), 164.310(d)(1), 164.310(d)(2)(i), 164.312(a)(1), 164.312(c)(1), 164.316(a), 164.316(b)(1), 164.316(b)(2)(iii), 164.530(i)(2)(i), 164.530(i)(2)(ii), 164.530(i)(2)(iii), 164.530(i)(3), 164.530(j)(1)(i)HITRUST-09.a
    CM-2Baseline ConfigurationCMConfiguration Management164.312(a)(2)(iii), 164.312(e)(1), 164.312(e)(2)(i), 164.312(e)(2)(ii)HITRUST-06.d, HITRUST-10.h
    CM-3Configuration Change ControlCMConfiguration Management164.308(a)(1)(i)HITRUST-06.d, HITRUST-09.b, HITRUST-10.i
    CM-6Configuration SettingsCMConfiguration Management164.312(a)(2)(iii), 164.312(e)(1), 164.312(e)(2)(i), 164.312(e)(2)(ii)HITRUST-06.d, HITRUST-10.h
    CM-8System Component InventoryCMConfiguration Management164.310(d)(2)(iii)HITRUST-06.g
    CP-1Policy and ProceduresCPContingency Planning164.308(a)(1)(i), 164.308(a)(3)(i), 164.308(a)(4)(i), 164.308(a)(4)(ii)(A), 164.308(a)(6)(i), 164.308(a)(7)(i), 164.308(a)(7)(ii)(C), 164.310(a)(1), 164.310(a)(2)(ii), 164.310(a)(2)(iv), 164.310(b), 164.310(d)(1), 164.310(d)(2)(i), 164.312(a)(1), 164.312(c)(1), 164.316(a), 164.316(b)(1), 164.316(b)(2)(iii), 164.530(i)(2)(i), 164.530(i)(2)(ii), 164.530(i)(2)(iii), 164.530(i)(3), 164.530(j)(1)(i)HITRUST-12.a
    CP-2Contingency PlanCPContingency Planning164.308(a)(7)(i), 164.308(a)(7)(ii)(C)HITRUST-12.a, HITRUST-12.b
    CP-4Contingency Plan TestingCPContingency Planning164.308(a)(7)(ii)(D)HITRUST-12.a
    CP-9System BackupCPContingency Planning164.308(a)(7)(ii)(A), 164.310(d)(2)(iv)HITRUST-12.a
    CP-10System Recovery and ReconstitutionCPContingency Planning164.308(a)(7)(i), 164.308(a)(7)(ii)(B), 164.308(a)(7)(ii)(C)HITRUST-12.a
    IA-1Policy and ProceduresIAIdentification and Authentication164.308(a)(1)(i), 164.308(a)(3)(i), 164.308(a)(4)(i), 164.308(a)(4)(ii)(A), 164.308(a)(4)(ii)(B), 164.308(a)(6)(i), 164.308(a)(7)(i), 164.310(a)(1), 164.310(a)(2)(ii), 164.310(a)(2)(iii), 164.310(a)(2)(iv), 164.310(b), 164.310(d)(1), 164.310(d)(2)(i), 164.312(a)(1), 164.312(c)(1), 164.316(a), 164.316(b)(1), 164.316(b)(2)(iii), 164.530(c)(2)(ii), 164.530(i)(2)(i), 164.530(i)(2)(ii), 164.530(i)(2)(iii), 164.530(i)(3), 164.530(j)(1)(i)HITRUST-01.d
    IA-2Identification and Authentication (Organizational Users)IAIdentification and Authentication164.312(a)(2)(i)HITRUST-01.l, HITRUST-01.m
    IA-4Identifier ManagementIAIdentification and Authentication164.312(a)(2)(i)HITRUST-01.d
    IR-1Policy and ProceduresIRIncident Response164.308(a)(1)(i), 164.308(a)(3)(i), 164.308(a)(4)(i), 164.308(a)(4)(ii)(A), 164.308(a)(6)(i), 164.308(a)(7)(i), 164.310(a)(1), 164.310(a)(2)(ii), 164.310(a)(2)(iv), 164.310(b), 164.310(d)(1), 164.310(d)(2)(i), 164.312(a)(1), 164.312(c)(1), 164.316(a), 164.316(b)(1), 164.316(b)(2)(iii), 164.530(i)(2)(i), 164.530(i)(2)(ii), 164.530(i)(2)(iii), 164.530(i)(3), 164.530(j)(1)(i)HITRUST-11.a, HITRUST-11.c
    IR-4Incident HandlingIRIncident Response164.308(a)(6)(ii), 164.412, 164.412(a), 164.412(b), 164.530(f)HITRUST-11.a, HITRUST-11.c
    IR-6Incident ReportingIRIncident Response164.404(b), 164.408(a), 164.408(b), 164.408(c)HITRUST-11.b, HITRUST-13.c
    MA-2Controlled MaintenanceMAMaintenance164.310(a)(2)(iv)HITRUST-08.j
    PE-1Policy and ProceduresPEPhysical and Environmental Protection164.308(a)(1)(i), 164.308(a)(3)(i), 164.308(a)(4)(i), 164.308(a)(4)(ii)(A), 164.308(a)(6)(i), 164.308(a)(7)(i), 164.310(a)(1), 164.310(a)(2)(ii), 164.310(a)(2)(iv), 164.310(b), 164.310(d)(1), 164.310(d)(2)(i), 164.312(a)(1), 164.312(c)(1), 164.316(a), 164.316(b)(1), 164.316(b)(2)(iii), 164.530(i)(2)(i), 164.530(i)(2)(ii), 164.530(i)(2)(iii), 164.530(i)(3), 164.530(j)(1)(i)HITRUST-08.e
    PE-3Physical Access ControlPEPhysical and Environmental Protection164.310(a)(2)(ii), 164.310(a)(2)(iii), 164.310(c)HITRUST-08.a, HITRUST-08.e
    PL-1Policy and ProceduresPLPlanning164.306(c), 164.306(d)(1), 164.306(d)(2), 164.308(a)(1)(i), 164.308(a)(3)(i), 164.308(a)(4)(i), 164.308(a)(4)(ii)(A), 164.308(a)(6)(i), 164.308(a)(7)(i), 164.310(a)(1), 164.310(a)(2)(ii), 164.310(a)(2)(iv), 164.310(b), 164.310(d)(1), 164.310(d)(2)(i), 164.312(a)(1), 164.312(c)(1), 164.314(a)(1), 164.314(a)(2)(ii), 164.316(a), 164.316(b)(1), 164.316(b)(2)(iii), 164.504(g)(1), 164.530(i)(1), 164.530(i)(2)(i), 164.530(i)(2)(ii), 164.530(i)(2)(iii), 164.530(i)(3), 164.530(j)(1)(i)HITRUST-01.a, HITRUST-01.b, HITRUST-01.e, HITRUST-01.g, HITRUST-04.b, HITRUST-09.a, HITRUST-10.a
    PL-4Rules of BehaviorPLPlanning164.310(b)HITRUST-04.b
    RA-1Policy and ProceduresRARisk Assessment164.306(a)(3), 164.306(b)(2)(iv), 164.308(a)(1)(i), 164.308(a)(3)(i), 164.308(a)(4)(i), 164.308(a)(4)(ii)(A), 164.308(a)(6)(i), 164.308(a)(7)(i), 164.310(a)(1), 164.310(a)(2)(ii), 164.310(a)(2)(iv), 164.310(b), 164.310(d)(1), 164.310(d)(2)(i), 164.312(a)(1), 164.312(c)(1), 164.316(a), 164.316(b)(1), 164.316(b)(2)(iii), 164.530(i)(2)(i), 164.530(i)(2)(ii), 164.530(i)(2)(iii), 164.530(i)(3), 164.530(j)(1)(i)HITRUST-03.a
    RA-2Security CategorizationRARisk Assessment164.306(b)(2)(iv)HITRUST-03.a
    RA-3Risk AssessmentRARisk Assessment164.306(b)(2)(iv), 164.306(d)(3)(i), 164.306(e), 164.308(a)(1)(ii)(A), 164.308(a)(8)HITRUST-03.a, HITRUST-03.b, HITRUST-03.c, HITRUST-05.j
    SA-4Acquisition ProcessSASystem and Services Acquisition164.308(b)(1), 164.312(d)HITRUST-05.a, HITRUST-05.b, HITRUST-05.c, HITRUST-05.i, HITRUST-05.k, HITRUST-09.e
    SA-9External System ServicesSASystem and Services Acquisition164.308(b)(1)HITRUST-05.a, HITRUST-05.i, HITRUST-05.j, HITRUST-09.e
    SC-8Transmission Confidentiality and IntegritySCSystem and Communications Protection164.312(e)(1), 164.312(e)(2)(i)HITRUST-09.m, HITRUST-09.n, HITRUST-09.o
    SC-13Cryptographic ProtectionSCSystem and Communications Protection164.312(a)(2)(iv), 164.312(e)(2)(ii)HITRUST-09.r, HITRUST-09.s, HITRUST-13.d
    SC-28Protection of Information at RestSCSystem and Communications Protection164.310(c)HITRUST-09.v, HITRUST-13.d
    SI-4System MonitoringSISystem and Information Integrity164.308(a)(1)(i), 164.308(a)(1)(ii)(D), 164.312(b)HITRUST-06.f, HITRUST-09.p, HITRUST-10.l
    SI-12Information Management and RetentionSISystem and Information Integrity164.316(b)(2)(i), 164.530(j)(2)HITRUST-13.b
    MP-1Policy and ProceduresMPMedia Protection164.306(a)(3), 164.308(a)(1)(i), 164.308(a)(3)(i), 164.308(a)(4)(i), 164.308(a)(4)(ii)(A), 164.308(a)(6)(i), 164.308(a)(7)(i), 164.310(a)(1), 164.310(a)(2)(ii), 164.310(a)(2)(iv), 164.310(b), 164.310(d)(1), 164.310(d)(2)(i), 164.312(a)(1), 164.312(c)(1), 164.316(a), 164.316(b)(1), 164.316(b)(2)(iii), 164.514(d)(3)(i), 164.530(c)(2)(i), 164.530(i)(2)(i), 164.530(i)(2)(ii), 164.530(i)(2)(iii), 164.530(i)(3), 164.530(j)(1)(i)HITRUST-07.a
    MP-2Media AccessMPMedia Protection164.310(b), 164.310(d)(1)HITRUST-07.a
    MP-6Media SanitizationMPMedia Protection164.310(d)(2)(ii)HITRUST-07.b, HITRUST-07.c
    PS-1Policy and ProceduresPSPersonnel Security164.308(a)(1)(i), 164.308(a)(3)(i), 164.308(a)(3)(ii)(A), 164.308(a)(4)(i), 164.308(a)(4)(ii)(A), 164.308(a)(6)(i), 164.308(a)(7)(i), 164.310(a)(1), 164.310(a)(2)(ii), 164.310(a)(2)(iv), 164.310(b), 164.310(d)(1), 164.310(d)(2)(i), 164.312(a)(1), 164.312(c)(1), 164.312(d), 164.316(a), 164.316(b)(1), 164.316(b)(2)(iii), 164.530(e)(2), 164.530(i)(2)(i), 164.530(i)(2)(ii), 164.530(i)(2)(iii), 164.530(i)(3), 164.530(j)(1)(i)HITRUST-02.a
    PS-3Personnel ScreeningPSPersonnel Security164.312(d)HITRUST-02.a
    PS-4Personnel TerminationPSPersonnel Security164.308(a)(3)(ii)(C)HITRUST-02.e, HITRUST-02.f, HITRUST-02.g
    PS-5Personnel TransferPSPersonnel Security164.308(a)(3)(ii)(C)HITRUST-02.e, HITRUST-02.f
    PM-1Information Security Program PlanPMProgram Management164.306(a)(1), 164.306(a)(2), 164.306(a)(3), 164.308(a)(1)(i), 164.308(a)(3)(i), 164.308(a)(4)(i), 164.308(a)(4)(ii)(A), 164.308(a)(6)(i), 164.308(a)(7)(i), 164.310(a)(1), 164.310(a)(2)(ii), 164.310(a)(2)(iv), 164.310(b), 164.310(d)(1), 164.310(d)(2)(i), 164.312(a)(1), 164.312(c)(1), 164.316(a), 164.316(b)(1), 164.316(b)(2)(iii), 164.530(c)(1), 164.530(i)(1), 164.530(i)(2)(i), 164.530(i)(2)(ii), 164.530(i)(2)(iii), 164.530(i)(3), 164.530(j)(1)(i)HITRUST-04.a
    PM-2Information Security Program Leadership RolePMProgram Management164.308(a)(2)HITRUST-01.e
    PM-9Risk Management StrategyPMProgram Management164.306(a)(3), 164.306(b)(2)(iv)HITRUST-04.a, HITRUST-05.b
    PT-1Policy and ProceduresPTPII Processing and Transparency164.306(b)(1), 164.308(a)(1)(i), 164.308(a)(3)(i), 164.308(a)(4)(i), 164.308(a)(4)(ii)(A), 164.308(a)(6)(i), 164.308(a)(7)(i), 164.310(a)(1), 164.310(a)(2)(ii), 164.310(a)(2)(iv), 164.310(b), 164.310(d)(1), 164.310(d)(2)(i), 164.312(a)(1), 164.312(c)(1), 164.316(a), 164.316(b)(1), 164.316(b)(2)(iii), 164.502(a), 164.530(a)(1)(i), 164.530(i)(1), 164.530(i)(2)(i), 164.530(i)(2)(ii), 164.530(i)(2)(iii), 164.530(i)(3), 164.530(i)(4)(i)(A), 164.530(i)(4)(i)(B), 164.530(i)(5), 164.530(i)(5)(i), 164.530(i)(5)(ii), 164.530(j)(1)(i)HITRUST-13.a
    PT-2Authority to Process Personally Identifiable InformationPTPII Processing and Transparency164.502(a)(1)(i), 164.502(a)(1)(ii), 164.502(a)(1)(iii), 164.502(a)(5)(i), 164.502(c), 164.502(d)(1), 164.502(i), 164.504(g)(2), 164.506(a), 164.506(c)(1), 164.506(c)(5), 164.508(a)(1), 164.508(a)(2)(i)(B), 164.508(a)(2)(i)(C), 164.510(a)(1)(i)(A), 164.510(a)(1)(i)(B), 164.510(a)(1)(i)(C), 164.510(a)(1)(i)(D), 164.510(a)(1)(ii)(A), 164.510(a)(1)(ii)(B), 164.510(b)(4), 164.512, 164.512(i)(1), 164.512(j)(1), 164.512(j)(1)(i)(A), 164.512(j)(1)(i)(B), 164.512(j)(1)(ii), 164.512(j)(1)(ii)(A), 164.512(j)(1)(ii)(B), 164.512(j)(2)(i), 164.512(j)(2)(ii), 164.512(j)(3), 164.512(j)(4), 164.512(k)(1)(i), 164.512(k)(1)(i)(A), 164.512(k)(1)(i)(B), 164.512(k)(1)(ii), 164.512(k)(1)(iii), 164.512(k)(1)(iv), 164.512(k)(2), 164.512(k)(3), 164.512(k)(4), 164.512(k)(4)(i), 164.512(k)(4)(ii), 164.512(k)(4)(iii), 164.512(k)(5)(i), 164.512(k)(5)(i)(A), 164.512(k)(5)(i)(B), 164.512(k)(5)(i)(C), 164.512(k)(5)(i)(D), 164.512(k)(5)(i)(E), 164.512(k)(5)(i)(F), 164.512(k)(5)(ii), 164.512(k)(5)(iii), 164.512(k)(6)(i), 164.512(k)(6)(ii), 164.512(k)(6)(ii)(1), 164.514(f)(2)(i), 164.514(g), 164.530(i)(4)(ii), 164.530(i)(4)(ii)(B), 164.532(a), 164.532(b), 164.532(c)HITRUST-13.a
    PT-3Personally Identifiable Information Processing PurposesPTPII Processing and Transparency164.502(a)(3), 164.508(a)(2)(i)(B), 164.508(c)(1)(i), 164.508(c)(1)(ii), 164.508(c)(1)(iii), 164.508(c)(1)(iv), 164.508(c)(2)(i)(A), 164.508(c)(2)(i)(B)HITRUST-13.a, HITRUST-13.b
    SR-1Policy and ProceduresSRSupply Chain Risk Management164.308(a)(1)(i), 164.308(a)(3)(i), 164.308(a)(4)(i), 164.308(a)(4)(ii)(A), 164.308(a)(6)(i), 164.308(a)(7)(i), 164.308(b)(1), 164.310(a)(1), 164.310(a)(2)(ii), 164.310(a)(2)(iv), 164.310(b), 164.310(d)(1), 164.310(d)(2)(i), 164.312(a)(1), 164.312(c)(1), 164.312(d), 164.316(a), 164.316(b)(1), 164.316(b)(2)(iii), 164.530(i)(2)(i), 164.530(i)(2)(ii), 164.530(i)(2)(iii), 164.530(i)(3), 164.530(j)(1)(i)HITRUST-05.k

    Source and method

    Derived from the Top Floor framework mapping dataset: 4,123 cross-framework control mappings across 19 frameworks, every one pivoted through NIST SP 800-53 Rev 5.

    Cross-framework mappings on this page are derived from the 2026.2 release of the Secure Controls Framework, used under CC BY-ND 4.0.

    Mappings are illustrative aids for planning and are not a substitute for the official text of any framework or for an assessor’s judgment. Always verify control requirements against the authoritative publication. Where no official crosswalk exists, the mapping judgment is our own analysis.