Compliance

HIPAA Security Rule mapping

Which HIPAA standards ITDR maps automatically from posture findings, which need manual attestation, and how to prepare for an audit.

Updated May 26, 2026 | 8 min

Standards mapped automatically

These standards have at least one ITDR posture check that contributes evidence. Status flips to Gap when any linked finding is open, Met when none are.

  • §164.308(a)(3)(i)Workforce Security: Global Administrator inventory and dedicated-admin separation checks (CIS M365 1.1.3, 1.1.4).
  • §164.308(a)(4)(ii)(B)Access Authorization: OAuth admin consent workflow + user consent restrictions (CIS M365 5.1.8.1).
  • §164.308(a)(5)(ii)(D)Password Management: MFA enforcement on privileged users + SSPR enabled (CIS M365 1.2.1, 5.1.3.1).
  • §164.308(a)(5)(ii)(C)Log-in Monitoring: Risky sign-in detection reviews (CIS M365 5.1.5.2).
  • §164.308(a)(6)(i)Security Incident Procedures: Same as above — risky sign-in detection mapping.
  • §164.308(a)(1)(ii)(D)Information System Activity Review: Sign-in log review cadence + mailbox auditing enabled (CIS M365 5.1.5.1, 6.1.2).
  • §164.312(a)(1)Access Control: CA policies that block legacy authentication + Conditional Access analyzer findings.
  • §164.312(b)Audit Controls: Mailbox auditing + sign-in log review checks.
  • §164.312(d)Person or Entity Authentication: MFA coverage, phishing-resistant MFA, SMS/voice MFA disabled (CIS M365 1.2.1, 5.2.3.1, 5.2.3.4).
  • §164.312(e)(1)Transmission Security: Exchange external forwarding blocked + SharePoint external sharing restricted.

Standards that require manual attestation

These standards live outside the M365 posture surface or cover policy/process controls. Use the Manual attestation form on the control detail page to upload supporting evidence.

  • §164.308(a)(1)(i)Security Management Process: Policy and documentation control — upload your Information Security Policy.
  • §164.308(a)(3)(ii)(C)Termination Procedures: Process control — upload your offboarding runbook or HR-IT handoff procedure.
  • §164.308(a)(4)(i)Information Access Management: Combination — partly mapped (access authorization), partly attested (documented role-based access policy).
  • §164.308(a)(4)(ii)(C)Access Establishment and Modification: Process control — upload your access review cadence document.
  • §164.312(a)(2)(i)Unique User Identification: M365 enforces unique UPNs; attest that the policy is documented.
  • §164.312(a)(2)(iii)Automatic Logoff: Configured at the device level (Intune or workstation policy) — not visible to M365 posture scans.
  • §164.312(c)(1)Integrity: Largely outside identity scope — backup tool attestation, file-integrity monitoring, etc.

Audit-prep workflow

  1. Subscribe the tenant to the HIPAA Security Rule framework on /compliance.
  2. Run "Re-reconcile now" on the HIPAA framework page so coverage reflects current open findings.
  3. Walk every Gap control: either remediate the linked posture finding, or attach a manual attestation explaining the compensating control.
  4. For controls in the "manual attestation" list, upload the relevant policy or vendor letter via the Manual attestation form on the control detail page.
  5. Generate an audit package PDF from /compliance/packages. Cover page shows coverage % and grade; body has control-by-control evidence.
  6. Hand the PDF to your auditor. The audit trail (when each evidence was attested, by which operator) is in the appendix.

Scope and limits

  • ITDR maps the technical safeguards (§164.312) most completely. Administrative safeguards (§164.308) need a mix of automated and manual evidence; physical safeguards (§164.310) are entirely out of scope for an identity product.
  • A "Met" status from automated mapping means we don't see open posture findings — it is not a positive attestation that the policy is documented. For an actual audit, expect to attach policy documentation as manual evidence for §164.308 standards.
  • The HIPAA mapping is opinionated. If your auditor expects a different mapping for a specific check, override on the control detail page with a manual attestation.