Appearance
HIPAA Security Rule Policy Set
Purpose: Enumerate the 12 written security policies required to operate under the HIPAA Security Rule (§164.308 Administrative, §164.310 Physical, §164.312 Technical, §164.316 Policies and Procedures). Each policy below is a standalone document managed in SharePoint; this file is the authoritative index and includes the approved policy statement that anchors each.
Owner: Rory (Security Officer) Audience: Workforce, Business Associates, auditors Review frequency: Annual. Each policy document dated and signed annually. Last reviewed: April 2026
How to read this index: Each of the 12 sections names the policy, references the regulation, and states the governing policy statement. The full operational procedures sit in compliance/hipaa-administrative-procedures.md and the control implementations in compliance/hipaa-controls.md.
1. Access Control Policy
Regulation: HIPAA §164.312(a) (Access Control) — Technical Safeguard Location: SharePoint → Compliance → Policies → 01-access-control.pdf Policy statement: Cirius Group grants access to ePHI only to workforce members whose job function requires it, on a least-privilege basis. Every user has a unique identity, every privileged action requires explicit authorization, and emergency access is provided exclusively through documented break-glass accounts whose every use is monitored as a CRITICAL incident. Implementation references: compliance/three-layer-access-architecture.md, security/lpriv-baseline.md, Entra PIM configuration.
2. Audit Control Policy
Regulation: HIPAA §164.312(b) (Audit Controls) — Technical Safeguard Location: SharePoint → Compliance → Policies → 02-audit-controls.pdf Policy statement: All systems that store, process, or transmit ePHI are logged to an immutable, long-term archive. Logs are reviewed on a documented schedule, retained for six years minimum in Write-Once-Read-Many storage, and indexed in the central Log Analytics Workspace (cirius-logging-law-central, ID 5d76d1f2) for investigation and audit. Implementation references: compliance/logging-architecture.md, runbooks/monthly-security-review.md Section 1 and 8.
3. Integrity Policy
Regulation: HIPAA §164.312(c) (Integrity) — Technical Safeguard Location: SharePoint → Compliance → Policies → 03-integrity.pdf Policy statement: Cirius Group protects ePHI from improper alteration or destruction. Backup and restore integrity is validated on a scheduled basis (monthly spot-check, quarterly DR test), Recovery Services Vaults are configured with soft delete and immutability, and file integrity monitoring alerts on unexpected changes in sensitive paths. Implementation references: runbooks/backup-architecture.md, RSV immutability (Unlocked), FIM coverage verification in-progress.
4. Transmission Security Policy
Regulation: HIPAA §164.312(e) (Transmission Security) — Technical Safeguard Location: SharePoint → Compliance → Policies → 04-transmission-security.pdf Policy statement: All ePHI in transit is protected by TLS 1.2 or higher with valid certificates. All east-west traffic crossing environment boundaries passes through Palo Alto VM-Series inspection. Certificate expiration is monitored at 30/60/90 days to prevent silent failures. Implementation references: Palo Alto decryption policy, certificate monitoring, security/palo-alto-overview.md.
5. Workforce Clearance Policy
Regulation: HIPAA §164.308(a)(3)(ii)(B) (Workforce Clearance) — Administrative Safeguard Location: SharePoint → Compliance → Policies → 05-workforce-clearance.pdf Policy statement: Before any workforce member is granted access to systems containing ePHI, their identity is verified, a background check is completed, and they acknowledge the HIPAA Awareness and Acceptable Use policies in writing. Clearance is reviewed annually and revoked promptly upon termination or role change. Implementation references: compliance/onboarding-security-checklist.md Pre-start section and Day 1 identity steps.
6. Authorization and Supervision Policy
Regulation: HIPAA §164.308(a)(3)(ii)(A) (Authorization / Supervision) — Administrative Safeguard Location: SharePoint → Compliance → Policies → 06-authorization-supervision.pdf Policy statement: Every access request to systems containing ePHI is captured in the SecOps platform, approved by the Security Officer (or designated backup for sensitive roles), and supervised through privileged session recording where applicable. All privileged sessions against domain controllers, firewalls, and databases are recorded in Keeper Security PAM and reviewed monthly. Implementation references: compliance/hipaa-administrative-procedures.md §3.1, Keeper session recording, runbooks/monthly-security-review.md Section 3.
7. Password Management Policy
Regulation: HIPAA §164.308(a)(5)(ii)(D) (Password Management) — Administrative Safeguard Location: SharePoint → Compliance → Policies → 07-password-management.pdf Policy statement: All workforce passwords meet a minimum 14-character length, are checked against breached-password lists at creation and change, are never reused across accounts, and are stored only in Keeper Security — never in email, documents, or shared files. Privileged accounts move to FIDO2 phishing-resistant authentication on a managed schedule. Implementation references: Entra password protection policy, Keeper, FIDO2 rollout tracked in compliance/risk-acceptance-register.md.
8. Security Incident Response Policy
Regulation: HIPAA §164.308(a)(6) (Security Incident Procedures) — Administrative Safeguard Location: SharePoint → Compliance → Policies → 08-incident-response.pdf Policy statement: Cirius Group detects, contains, eradicates, recovers from, and learns from security incidents on a defined SLA. All suspected incidents are logged in the SecOps platform within one hour, investigated by the Security Officer, and, if ePHI is impacted, notified per the Breach Notification Rule within the regulatory window. Lessons learned are fed back into the runbooks, threat model, and training. Implementation references: runbooks/incident-response.md, compliance/ir-tabletop-scenario-2026.md, security/threat-model/threat-model-2026.md.
9. Contingency Plan Policy
Regulation: HIPAA §164.308(a)(7) (Contingency Plan) — Administrative Safeguard Location: SharePoint → Compliance → Policies → 09-contingency-plan.pdf Policy statement: Cirius Group maintains a data-backup plan, a disaster recovery plan, and an emergency-mode operation plan. These plans are tested twice per year (Q2 full test + Q4 focused test), and findings are remediated on a tracked schedule. Backups are stored in geographically-separated, immutable storage (Azure RSV immutability + AWS S3 Object Lock) with six-year retention. Implementation references: compliance/q2-dr-test-plan-2026.md, compliance/q4-dr-test-plan-2026.md, aws/dr-overview.md, runbooks/backup-architecture.md.
10. Evaluation Policy
Regulation: HIPAA §164.308(a)(8) (Evaluation) — Administrative Safeguard Location: SharePoint → Compliance → Policies → 10-evaluation.pdf Policy statement: Cirius Group evaluates its Security Rule controls on a periodic basis — at least annually, and after any material change to the environment. Evaluation includes technical testing (penetration tests, vulnerability scans, DR tests) and non-technical review (policy refresh, training completion, access recertification). The annual SOC2 audit anchors the external evaluation cycle. Implementation references: compliance/annual-review-checklist.md, compliance/compliance-scorecard.md, SOC2 audit scheduled September 2026.
11. Business Associate Policy
Regulation: HIPAA §164.308(b) / §164.314(a) (Business Associate Contracts) — Administrative Safeguard Location: SharePoint → Compliance → Policies → 11-business-associate.pdf Policy statement: Cirius Group executes a Business Associate Agreement before any vendor creates, receives, maintains, or transmits ePHI on its behalf. The vendor inventory is reviewed annually and whenever a vendor changes scope. Any vendor without an in-force BAA is prohibited from processing ePHI until the agreement is executed. Implementation references: compliance/vendor-risk-inventory.md (13 vendors tracked; 4 BAA confirmations outstanding pending Adriana).
12. Device and Media Controls Policy
Regulation: HIPAA §164.310(d) (Device and Media Controls) — Physical Safeguard Location: SharePoint → Compliance → Policies → 12-device-media-controls.pdf Policy statement: All devices capable of storing ePHI are encrypted at rest, enrolled in Intune (Windows) or an equivalent MDM, tracked in the CMDB, and wiped securely prior to disposal or reassignment. Removable media is prohibited for ePHI storage. Cloud storage is limited to Cirius-managed tenants; personal cloud services are blocked by endpoint policy where feasible. Implementation references: BitLocker / FileVault with Intune escrow, security/cmdb-guide.md, acceptable use policy, Cortex XDR endpoint restrictions.
Cross-references
| Policy | Related procedure | Related runbook |
|---|---|---|
| 1, 6 | §3, §4 in hipaa-administrative-procedures.md | three-layer-access-architecture.md, lpriv-baseline.md |
| 2 | §1 in hipaa-administrative-procedures.md | monthly-security-review.md |
| 3 | §6 in hipaa-administrative-procedures.md | backup-architecture.md |
| 4 | §4 in hipaa-administrative-procedures.md | palo-alto-overview.md |
| 5, 6 | §3 in hipaa-administrative-procedures.md | onboarding-security-checklist.md |
| 7 | §5 in hipaa-administrative-procedures.md | onboarding-security-checklist.md |
| 8 | §6 in hipaa-administrative-procedures.md | incident-response.md, ir-tabletop-scenario-2026.md |
| 9 | §6 in hipaa-administrative-procedures.md | q2-dr-test-plan-2026.md, q4-dr-test-plan-2026.md |
| 10 | §1 in hipaa-administrative-procedures.md | annual-review-checklist.md |
| 11 | §1 in hipaa-administrative-procedures.md | vendor-risk-inventory.md |
| 12 | §3 in hipaa-administrative-procedures.md | cmdb-guide.md |
Review and approval
| Policy | Last approved | Next review |
|---|---|---|
| 1. Access Control | 2026-01 | 2027-01 |
| 2. Audit Controls | 2026-01 | 2027-01 |
| 3. Integrity | 2026-01 | 2027-01 |
| 4. Transmission Security | 2026-01 | 2027-01 |
| 5. Workforce Clearance | 2026-01 | 2027-01 |
| 6. Authorization / Supervision | 2026-01 | 2027-01 |
| 7. Password Management | 2026-01 | 2027-01 |
| 8. Incident Response | 2026-04 | 2027-04 |
| 9. Contingency Plan | 2026-01 | 2027-01 |
| 10. Evaluation | 2026-01 | 2027-01 |
| 11. Business Associate | 2026-04 | 2027-04 |
| 12. Device and Media Controls | 2026-01 | 2027-01 |
Document history
| Date | Change | Author |
|---|---|---|
| April 2026 | Initial index covering all 12 required HIPAA Security Rule policies | Kobe |