HIPAA (Security, Privacy and Breach Notification Rules) to HITRUST CSF v11 control mapping
HIPAA (Security, Privacy and Breach Notification Rules) and HITRUST CSF v11 both map to 53 NIST SP 800-53 controls. Every one is listed below, with the controls on each side that map to it.
- Shared NIST 800-53 controls
- 53
- HIPAA (Security, Privacy and Breach Notification Rules) controls involved
- 159
- HITRUST CSF v11 controls involved
- 63
- NIST 800-53 families touched
- 19
How this pairing is derived
Both frameworks are mapped to NIST SP 800-53 Rev 5 in the source dataset, so the ground they share is the set of NIST controls they both reference. That set is what the table shows. It is not an authored HIPAA (Security, Privacy and Breach Notification Rules) to HITRUST CSF v11 crosswalk: two controls on the same row are related through the NIST control between them, not asserted to be equivalent to each other.
Shared controls in full
| NIST 800-53 control | Family | HIPAA (Security, Privacy and Breach Notification Rules) controls | HITRUST CSF v11 controls |
|---|---|---|---|
| AC-1Policy and Procedures | ACAccess Control | 164.308(a)(1)(i), 164.308(a)(3)(i), 164.308(a)(4)(i), 164.308(a)(4)(ii)(A), 164.308(a)(4)(ii)(B), 164.308(a)(6)(i), 164.308(a)(7)(i), 164.310(a)(1), 164.310(a)(2)(ii), 164.310(a)(2)(iii), 164.310(a)(2)(iv), 164.310(b), 164.310(d)(1), 164.310(d)(2)(i), 164.312(a)(1), 164.312(c)(1), 164.316(a), 164.316(b)(1), 164.316(b)(2)(iii), 164.530(c)(2)(ii), 164.530(i)(2)(i), 164.530(i)(2)(ii), 164.530(i)(2)(iii), 164.530(i)(3), 164.530(j)(1)(i) | HITRUST-01.c |
| AC-2Account Management | ACAccess Control | 164.308(a)(3)(ii)(C), 164.312(a)(2)(ii) | HITRUST-01.d, HITRUST-01.h, HITRUST-01.p |
| AC-6Least Privilege | ACAccess Control | 164.308(a)(3)(i), 164.312(a)(1) | HITRUST-01.i, HITRUST-01.j |
| AC-12Session Termination | ACAccess Control | 164.312(a)(2)(iii) | HITRUST-01.s |
| AT-3Role-based Training | ATAwareness and Training | 164.308(a)(5)(ii)(C), 164.308(a)(5)(ii)(D), 164.530(b)(1) | HITRUST-02.b, HITRUST-02.d |
| AU-1Policy and Procedures | AUAudit and Accountability | 164.308(a)(1)(i), 164.308(a)(1)(ii)(D), 164.308(a)(3)(i), 164.308(a)(4)(i), 164.308(a)(4)(ii)(A), 164.308(a)(6)(i), 164.308(a)(7)(i), 164.310(a)(1), 164.310(a)(2)(ii), 164.310(a)(2)(iv), 164.310(b), 164.310(d)(1), 164.310(d)(2)(i), 164.312(a)(1), 164.312(b), 164.312(c)(1), 164.316(a), 164.316(b)(1), 164.316(b)(2)(iii), 164.530(i)(2)(i), 164.530(i)(2)(ii), 164.530(i)(2)(iii), 164.530(i)(3), 164.530(j)(1)(i) | HITRUST-09.aa |
| AU-2Event Logging | AUAudit and Accountability | 164.308(a)(1)(ii)(D), 164.312(b) | HITRUST-09.aa |
| AU-3Content of Audit Records | AUAudit and Accountability | 164.312(b) | HITRUST-09.aa |
| CM-1Policy and Procedures | CMConfiguration Management | 164.308(a)(1)(i), 164.308(a)(3)(i), 164.308(a)(4)(i), 164.308(a)(4)(ii)(A), 164.308(a)(6)(i), 164.308(a)(7)(i), 164.310(a)(1), 164.310(a)(2)(ii), 164.310(a)(2)(iv), 164.310(b), 164.310(d)(1), 164.310(d)(2)(i), 164.312(a)(1), 164.312(c)(1), 164.316(a), 164.316(b)(1), 164.316(b)(2)(iii), 164.530(i)(2)(i), 164.530(i)(2)(ii), 164.530(i)(2)(iii), 164.530(i)(3), 164.530(j)(1)(i) | HITRUST-09.a |
| CM-2Baseline Configuration | CMConfiguration Management | 164.312(a)(2)(iii), 164.312(e)(1), 164.312(e)(2)(i), 164.312(e)(2)(ii) | HITRUST-06.d, HITRUST-10.h |
| CM-3Configuration Change Control | CMConfiguration Management | 164.308(a)(1)(i) | HITRUST-06.d, HITRUST-09.b, HITRUST-10.i |
| CM-6Configuration Settings | CMConfiguration Management | 164.312(a)(2)(iii), 164.312(e)(1), 164.312(e)(2)(i), 164.312(e)(2)(ii) | HITRUST-06.d, HITRUST-10.h |
| CM-8System Component Inventory | CMConfiguration Management | 164.310(d)(2)(iii) | HITRUST-06.g |
| CP-1Policy and Procedures | CPContingency Planning | 164.308(a)(1)(i), 164.308(a)(3)(i), 164.308(a)(4)(i), 164.308(a)(4)(ii)(A), 164.308(a)(6)(i), 164.308(a)(7)(i), 164.308(a)(7)(ii)(C), 164.310(a)(1), 164.310(a)(2)(ii), 164.310(a)(2)(iv), 164.310(b), 164.310(d)(1), 164.310(d)(2)(i), 164.312(a)(1), 164.312(c)(1), 164.316(a), 164.316(b)(1), 164.316(b)(2)(iii), 164.530(i)(2)(i), 164.530(i)(2)(ii), 164.530(i)(2)(iii), 164.530(i)(3), 164.530(j)(1)(i) | HITRUST-12.a |
| CP-2Contingency Plan | CPContingency Planning | 164.308(a)(7)(i), 164.308(a)(7)(ii)(C) | HITRUST-12.a, HITRUST-12.b |
| CP-4Contingency Plan Testing | CPContingency Planning | 164.308(a)(7)(ii)(D) | HITRUST-12.a |
| CP-9System Backup | CPContingency Planning | 164.308(a)(7)(ii)(A), 164.310(d)(2)(iv) | HITRUST-12.a |
| CP-10System Recovery and Reconstitution | CPContingency Planning | 164.308(a)(7)(i), 164.308(a)(7)(ii)(B), 164.308(a)(7)(ii)(C) | HITRUST-12.a |
| IA-1Policy and Procedures | IAIdentification and Authentication | 164.308(a)(1)(i), 164.308(a)(3)(i), 164.308(a)(4)(i), 164.308(a)(4)(ii)(A), 164.308(a)(4)(ii)(B), 164.308(a)(6)(i), 164.308(a)(7)(i), 164.310(a)(1), 164.310(a)(2)(ii), 164.310(a)(2)(iii), 164.310(a)(2)(iv), 164.310(b), 164.310(d)(1), 164.310(d)(2)(i), 164.312(a)(1), 164.312(c)(1), 164.316(a), 164.316(b)(1), 164.316(b)(2)(iii), 164.530(c)(2)(ii), 164.530(i)(2)(i), 164.530(i)(2)(ii), 164.530(i)(2)(iii), 164.530(i)(3), 164.530(j)(1)(i) | HITRUST-01.d |
| IA-2Identification and Authentication (Organizational Users) | IAIdentification and Authentication | 164.312(a)(2)(i) | HITRUST-01.l, HITRUST-01.m |
| IA-4Identifier Management | IAIdentification and Authentication | 164.312(a)(2)(i) | HITRUST-01.d |
| IR-1Policy and Procedures | IRIncident Response | 164.308(a)(1)(i), 164.308(a)(3)(i), 164.308(a)(4)(i), 164.308(a)(4)(ii)(A), 164.308(a)(6)(i), 164.308(a)(7)(i), 164.310(a)(1), 164.310(a)(2)(ii), 164.310(a)(2)(iv), 164.310(b), 164.310(d)(1), 164.310(d)(2)(i), 164.312(a)(1), 164.312(c)(1), 164.316(a), 164.316(b)(1), 164.316(b)(2)(iii), 164.530(i)(2)(i), 164.530(i)(2)(ii), 164.530(i)(2)(iii), 164.530(i)(3), 164.530(j)(1)(i) | HITRUST-11.a, HITRUST-11.c |
| IR-4Incident Handling | IRIncident Response | 164.308(a)(6)(ii), 164.412, 164.412(a), 164.412(b), 164.530(f) | HITRUST-11.a, HITRUST-11.c |
| IR-6Incident Reporting | IRIncident Response | 164.404(b), 164.408(a), 164.408(b), 164.408(c) | HITRUST-11.b, HITRUST-13.c |
| MA-2Controlled Maintenance | MAMaintenance | 164.310(a)(2)(iv) | HITRUST-08.j |
| PE-1Policy and Procedures | PEPhysical and Environmental Protection | 164.308(a)(1)(i), 164.308(a)(3)(i), 164.308(a)(4)(i), 164.308(a)(4)(ii)(A), 164.308(a)(6)(i), 164.308(a)(7)(i), 164.310(a)(1), 164.310(a)(2)(ii), 164.310(a)(2)(iv), 164.310(b), 164.310(d)(1), 164.310(d)(2)(i), 164.312(a)(1), 164.312(c)(1), 164.316(a), 164.316(b)(1), 164.316(b)(2)(iii), 164.530(i)(2)(i), 164.530(i)(2)(ii), 164.530(i)(2)(iii), 164.530(i)(3), 164.530(j)(1)(i) | HITRUST-08.e |
| PE-3Physical Access Control | PEPhysical and Environmental Protection | 164.310(a)(2)(ii), 164.310(a)(2)(iii), 164.310(c) | HITRUST-08.a, HITRUST-08.e |
| PL-1Policy and Procedures | PLPlanning | 164.306(c), 164.306(d)(1), 164.306(d)(2), 164.308(a)(1)(i), 164.308(a)(3)(i), 164.308(a)(4)(i), 164.308(a)(4)(ii)(A), 164.308(a)(6)(i), 164.308(a)(7)(i), 164.310(a)(1), 164.310(a)(2)(ii), 164.310(a)(2)(iv), 164.310(b), 164.310(d)(1), 164.310(d)(2)(i), 164.312(a)(1), 164.312(c)(1), 164.314(a)(1), 164.314(a)(2)(ii), 164.316(a), 164.316(b)(1), 164.316(b)(2)(iii), 164.504(g)(1), 164.530(i)(1), 164.530(i)(2)(i), 164.530(i)(2)(ii), 164.530(i)(2)(iii), 164.530(i)(3), 164.530(j)(1)(i) | HITRUST-01.a, HITRUST-01.b, HITRUST-01.e, HITRUST-01.g, HITRUST-04.b, HITRUST-09.a, HITRUST-10.a |
| PL-4Rules of Behavior | PLPlanning | 164.310(b) | HITRUST-04.b |
| RA-1Policy and Procedures | RARisk Assessment | 164.306(a)(3), 164.306(b)(2)(iv), 164.308(a)(1)(i), 164.308(a)(3)(i), 164.308(a)(4)(i), 164.308(a)(4)(ii)(A), 164.308(a)(6)(i), 164.308(a)(7)(i), 164.310(a)(1), 164.310(a)(2)(ii), 164.310(a)(2)(iv), 164.310(b), 164.310(d)(1), 164.310(d)(2)(i), 164.312(a)(1), 164.312(c)(1), 164.316(a), 164.316(b)(1), 164.316(b)(2)(iii), 164.530(i)(2)(i), 164.530(i)(2)(ii), 164.530(i)(2)(iii), 164.530(i)(3), 164.530(j)(1)(i) | HITRUST-03.a |
| RA-2Security Categorization | RARisk Assessment | 164.306(b)(2)(iv) | HITRUST-03.a |
| RA-3Risk Assessment | RARisk Assessment | 164.306(b)(2)(iv), 164.306(d)(3)(i), 164.306(e), 164.308(a)(1)(ii)(A), 164.308(a)(8) | HITRUST-03.a, HITRUST-03.b, HITRUST-03.c, HITRUST-05.j |
| SA-4Acquisition Process | SASystem and Services Acquisition | 164.308(b)(1), 164.312(d) | HITRUST-05.a, HITRUST-05.b, HITRUST-05.c, HITRUST-05.i, HITRUST-05.k, HITRUST-09.e |
| SA-9External System Services | SASystem and Services Acquisition | 164.308(b)(1) | HITRUST-05.a, HITRUST-05.i, HITRUST-05.j, HITRUST-09.e |
| SC-8Transmission Confidentiality and Integrity | SCSystem and Communications Protection | 164.312(e)(1), 164.312(e)(2)(i) | HITRUST-09.m, HITRUST-09.n, HITRUST-09.o |
| SC-13Cryptographic Protection | SCSystem and Communications Protection | 164.312(a)(2)(iv), 164.312(e)(2)(ii) | HITRUST-09.r, HITRUST-09.s, HITRUST-13.d |
| SC-28Protection of Information at Rest | SCSystem and Communications Protection | 164.310(c) | HITRUST-09.v, HITRUST-13.d |
| SI-4System Monitoring | SISystem and Information Integrity | 164.308(a)(1)(i), 164.308(a)(1)(ii)(D), 164.312(b) | HITRUST-06.f, HITRUST-09.p, HITRUST-10.l |
| SI-12Information Management and Retention | SISystem and Information Integrity | 164.316(b)(2)(i), 164.530(j)(2) | HITRUST-13.b |
| MP-1Policy and Procedures | MPMedia Protection | 164.306(a)(3), 164.308(a)(1)(i), 164.308(a)(3)(i), 164.308(a)(4)(i), 164.308(a)(4)(ii)(A), 164.308(a)(6)(i), 164.308(a)(7)(i), 164.310(a)(1), 164.310(a)(2)(ii), 164.310(a)(2)(iv), 164.310(b), 164.310(d)(1), 164.310(d)(2)(i), 164.312(a)(1), 164.312(c)(1), 164.316(a), 164.316(b)(1), 164.316(b)(2)(iii), 164.514(d)(3)(i), 164.530(c)(2)(i), 164.530(i)(2)(i), 164.530(i)(2)(ii), 164.530(i)(2)(iii), 164.530(i)(3), 164.530(j)(1)(i) | HITRUST-07.a |
| MP-2Media Access | MPMedia Protection | 164.310(b), 164.310(d)(1) | HITRUST-07.a |
| MP-6Media Sanitization | MPMedia Protection | 164.310(d)(2)(ii) | HITRUST-07.b, HITRUST-07.c |
| PS-1Policy and Procedures | PSPersonnel Security | 164.308(a)(1)(i), 164.308(a)(3)(i), 164.308(a)(3)(ii)(A), 164.308(a)(4)(i), 164.308(a)(4)(ii)(A), 164.308(a)(6)(i), 164.308(a)(7)(i), 164.310(a)(1), 164.310(a)(2)(ii), 164.310(a)(2)(iv), 164.310(b), 164.310(d)(1), 164.310(d)(2)(i), 164.312(a)(1), 164.312(c)(1), 164.312(d), 164.316(a), 164.316(b)(1), 164.316(b)(2)(iii), 164.530(e)(2), 164.530(i)(2)(i), 164.530(i)(2)(ii), 164.530(i)(2)(iii), 164.530(i)(3), 164.530(j)(1)(i) | HITRUST-02.a |
| PS-3Personnel Screening | PSPersonnel Security | 164.312(d) | HITRUST-02.a |
| PS-4Personnel Termination | PSPersonnel Security | 164.308(a)(3)(ii)(C) | HITRUST-02.e, HITRUST-02.f, HITRUST-02.g |
| PS-5Personnel Transfer | PSPersonnel Security | 164.308(a)(3)(ii)(C) | HITRUST-02.e, HITRUST-02.f |
| PM-1Information Security Program Plan | PMProgram Management | 164.306(a)(1), 164.306(a)(2), 164.306(a)(3), 164.308(a)(1)(i), 164.308(a)(3)(i), 164.308(a)(4)(i), 164.308(a)(4)(ii)(A), 164.308(a)(6)(i), 164.308(a)(7)(i), 164.310(a)(1), 164.310(a)(2)(ii), 164.310(a)(2)(iv), 164.310(b), 164.310(d)(1), 164.310(d)(2)(i), 164.312(a)(1), 164.312(c)(1), 164.316(a), 164.316(b)(1), 164.316(b)(2)(iii), 164.530(c)(1), 164.530(i)(1), 164.530(i)(2)(i), 164.530(i)(2)(ii), 164.530(i)(2)(iii), 164.530(i)(3), 164.530(j)(1)(i) | HITRUST-04.a |
| PM-2Information Security Program Leadership Role | PMProgram Management | 164.308(a)(2) | HITRUST-01.e |
| PM-9Risk Management Strategy | PMProgram Management | 164.306(a)(3), 164.306(b)(2)(iv) | HITRUST-04.a, HITRUST-05.b |
| PT-1Policy and Procedures | PTPII Processing and Transparency | 164.306(b)(1), 164.308(a)(1)(i), 164.308(a)(3)(i), 164.308(a)(4)(i), 164.308(a)(4)(ii)(A), 164.308(a)(6)(i), 164.308(a)(7)(i), 164.310(a)(1), 164.310(a)(2)(ii), 164.310(a)(2)(iv), 164.310(b), 164.310(d)(1), 164.310(d)(2)(i), 164.312(a)(1), 164.312(c)(1), 164.316(a), 164.316(b)(1), 164.316(b)(2)(iii), 164.502(a), 164.530(a)(1)(i), 164.530(i)(1), 164.530(i)(2)(i), 164.530(i)(2)(ii), 164.530(i)(2)(iii), 164.530(i)(3), 164.530(i)(4)(i)(A), 164.530(i)(4)(i)(B), 164.530(i)(5), 164.530(i)(5)(i), 164.530(i)(5)(ii), 164.530(j)(1)(i) | HITRUST-13.a |
| PT-2Authority to Process Personally Identifiable Information | PTPII Processing and Transparency | 164.502(a)(1)(i), 164.502(a)(1)(ii), 164.502(a)(1)(iii), 164.502(a)(5)(i), 164.502(c), 164.502(d)(1), 164.502(i), 164.504(g)(2), 164.506(a), 164.506(c)(1), 164.506(c)(5), 164.508(a)(1), 164.508(a)(2)(i)(B), 164.508(a)(2)(i)(C), 164.510(a)(1)(i)(A), 164.510(a)(1)(i)(B), 164.510(a)(1)(i)(C), 164.510(a)(1)(i)(D), 164.510(a)(1)(ii)(A), 164.510(a)(1)(ii)(B), 164.510(b)(4), 164.512, 164.512(i)(1), 164.512(j)(1), 164.512(j)(1)(i)(A), 164.512(j)(1)(i)(B), 164.512(j)(1)(ii), 164.512(j)(1)(ii)(A), 164.512(j)(1)(ii)(B), 164.512(j)(2)(i), 164.512(j)(2)(ii), 164.512(j)(3), 164.512(j)(4), 164.512(k)(1)(i), 164.512(k)(1)(i)(A), 164.512(k)(1)(i)(B), 164.512(k)(1)(ii), 164.512(k)(1)(iii), 164.512(k)(1)(iv), 164.512(k)(2), 164.512(k)(3), 164.512(k)(4), 164.512(k)(4)(i), 164.512(k)(4)(ii), 164.512(k)(4)(iii), 164.512(k)(5)(i), 164.512(k)(5)(i)(A), 164.512(k)(5)(i)(B), 164.512(k)(5)(i)(C), 164.512(k)(5)(i)(D), 164.512(k)(5)(i)(E), 164.512(k)(5)(i)(F), 164.512(k)(5)(ii), 164.512(k)(5)(iii), 164.512(k)(6)(i), 164.512(k)(6)(ii), 164.512(k)(6)(ii)(1), 164.514(f)(2)(i), 164.514(g), 164.530(i)(4)(ii), 164.530(i)(4)(ii)(B), 164.532(a), 164.532(b), 164.532(c) | HITRUST-13.a |
| PT-3Personally Identifiable Information Processing Purposes | PTPII Processing and Transparency | 164.502(a)(3), 164.508(a)(2)(i)(B), 164.508(c)(1)(i), 164.508(c)(1)(ii), 164.508(c)(1)(iii), 164.508(c)(1)(iv), 164.508(c)(2)(i)(A), 164.508(c)(2)(i)(B) | HITRUST-13.a, HITRUST-13.b |
| SR-1Policy and Procedures | SRSupply Chain Risk Management | 164.308(a)(1)(i), 164.308(a)(3)(i), 164.308(a)(4)(i), 164.308(a)(4)(ii)(A), 164.308(a)(6)(i), 164.308(a)(7)(i), 164.308(b)(1), 164.310(a)(1), 164.310(a)(2)(ii), 164.310(a)(2)(iv), 164.310(b), 164.310(d)(1), 164.310(d)(2)(i), 164.312(a)(1), 164.312(c)(1), 164.312(d), 164.316(a), 164.316(b)(1), 164.316(b)(2)(iii), 164.530(i)(2)(i), 164.530(i)(2)(ii), 164.530(i)(2)(iii), 164.530(i)(3), 164.530(j)(1)(i) | HITRUST-05.k |
Source and method
Derived from the Top Floor framework mapping dataset: 4,123 cross-framework control mappings across 19 frameworks, every one pivoted through NIST SP 800-53 Rev 5.
Cross-framework mappings on this page are derived from the 2026.2 release of the Secure Controls Framework, used under CC BY-ND 4.0.
Mappings are illustrative aids for planning and are not a substitute for the official text of any framework or for an assessor’s judgment. Always verify control requirements against the authoritative publication. Where no official crosswalk exists, the mapping judgment is our own analysis.
Related pairings
- HIPAA (Security, Privacy and Breach Notification Rules) to NIST SP 800-53 Rev 5 control mapping165 shared controls
- SOC 2 Type II to HIPAA (Security, Privacy and Breach Notification Rules) control mapping132 shared controls
- SOC 2 Type II to HITRUST CSF v11 control mapping81 shared controls
- ISO/IEC 27001:2022 (ISMS clauses) to HIPAA (Security, Privacy and Breach Notification Rules) control mapping42 shared controls