Compliance
HIPAA Security Rule mapping
Which HIPAA standards ITDR maps automatically from posture findings, which need manual attestation, and how to prepare for an audit.
Updated May 26, 2026 | 8 min
Standards mapped automatically
These standards have at least one ITDR posture check that contributes evidence. Status flips to Gap when any linked finding is open, Met when none are.
- §164.308(a)(3)(i) — Workforce Security: Global Administrator inventory and dedicated-admin separation checks (CIS M365 1.1.3, 1.1.4).
- §164.308(a)(4)(ii)(B) — Access Authorization: OAuth admin consent workflow + user consent restrictions (CIS M365 5.1.8.1).
- §164.308(a)(5)(ii)(D) — Password Management: MFA enforcement on privileged users + SSPR enabled (CIS M365 1.2.1, 5.1.3.1).
- §164.308(a)(5)(ii)(C) — Log-in Monitoring: Risky sign-in detection reviews (CIS M365 5.1.5.2).
- §164.308(a)(6)(i) — Security Incident Procedures: Same as above — risky sign-in detection mapping.
- §164.308(a)(1)(ii)(D) — Information System Activity Review: Sign-in log review cadence + mailbox auditing enabled (CIS M365 5.1.5.1, 6.1.2).
- §164.312(a)(1) — Access Control: CA policies that block legacy authentication + Conditional Access analyzer findings.
- §164.312(b) — Audit Controls: Mailbox auditing + sign-in log review checks.
- §164.312(d) — Person or Entity Authentication: MFA coverage, phishing-resistant MFA, SMS/voice MFA disabled (CIS M365 1.2.1, 5.2.3.1, 5.2.3.4).
- §164.312(e)(1) — Transmission Security: Exchange external forwarding blocked + SharePoint external sharing restricted.
Standards that require manual attestation
These standards live outside the M365 posture surface or cover policy/process controls. Use the Manual attestation form on the control detail page to upload supporting evidence.
- §164.308(a)(1)(i) — Security Management Process: Policy and documentation control — upload your Information Security Policy.
- §164.308(a)(3)(ii)(C) — Termination Procedures: Process control — upload your offboarding runbook or HR-IT handoff procedure.
- §164.308(a)(4)(i) — Information Access Management: Combination — partly mapped (access authorization), partly attested (documented role-based access policy).
- §164.308(a)(4)(ii)(C) — Access Establishment and Modification: Process control — upload your access review cadence document.
- §164.312(a)(2)(i) — Unique User Identification: M365 enforces unique UPNs; attest that the policy is documented.
- §164.312(a)(2)(iii) — Automatic Logoff: Configured at the device level (Intune or workstation policy) — not visible to M365 posture scans.
- §164.312(c)(1) — Integrity: Largely outside identity scope — backup tool attestation, file-integrity monitoring, etc.
Audit-prep workflow
- Subscribe the tenant to the HIPAA Security Rule framework on /compliance.
- Run "Re-reconcile now" on the HIPAA framework page so coverage reflects current open findings.
- Walk every Gap control: either remediate the linked posture finding, or attach a manual attestation explaining the compensating control.
- For controls in the "manual attestation" list, upload the relevant policy or vendor letter via the Manual attestation form on the control detail page.
- Generate an audit package PDF from /compliance/packages. Cover page shows coverage % and grade; body has control-by-control evidence.
- Hand the PDF to your auditor. The audit trail (when each evidence was attested, by which operator) is in the appendix.
Scope and limits
- ITDR maps the technical safeguards (§164.312) most completely. Administrative safeguards (§164.308) need a mix of automated and manual evidence; physical safeguards (§164.310) are entirely out of scope for an identity product.
- A "Met" status from automated mapping means we don't see open posture findings — it is not a positive attestation that the policy is documented. For an actual audit, expect to attach policy documentation as manual evidence for §164.308 standards.
- The HIPAA mapping is opinionated. If your auditor expects a different mapping for a specific check, override on the control detail page with a manual attestation.