Compliance

MedStack Confidential

Metadata

Comply with the appropriate regional regulations

CodeSectionTitle
HIPAA 45 CFR Part 160, Subpart B (ยงยง 160.201 - 160.205) Preemption of State Law

Comply with contractual requirements

Who is accountable and responsible

CodeSectionTitle
HIPAA 164.308(a)(2) Standard: Assigned security responsibility
SOC2 CC1.1 COSO Principle 1: The entity demonstrates a commitment to integrity and ethical values.
SOC2 CC1.2 COSO Principle 2: The board of directors demonstrates independence from management and exercises oversight of the development and performance of internal control.
SOC2 CC1.3 COSO Principle 3: Management establishes, with board oversight, structures, reporting lines, and appropriate authorities and responsibilities in the pursuit of objectives.
SOC2 CC5.3 COSO Principle 12: The entity deploys control activities through policies that establish what is expected and in procedures that put policies into action.

Handle investigations, complaints and rights

HIPAA and state law preemption in the United States

Enforcement

References

CodeSectionTitle
ISO A.18.1 Compliance with legal and contractual requirements
ISO A.18.1.1 Identification of applicable legislation and contractual requirements
ISO A.18.1.3 Protection of records
SOC2 CC3.1 COSO Principle 6: The entity specifies objectives with sufficient clarity to enable the identification and assessment of risks relating to objectives.
SOC2 CC3.1 COSO Principle 6: The entity specifies objectives with sufficient clarity to enable the identification and assessment of risks relating to objectives.
SOC2 CC3.1 COSO Principle 6: The entity specifies objectives with sufficient clarity to enable the identification and assessment of risks relating to objectives.