Skip to content

HIPAA Security Rule

The HIPAA Security Rule (45 CFR Part 164 Subpart C) is StackTakt’s anchor framework: the first one the blueprints map to and the one the evidence PDF cites. Adopting it on the Compliance page activates its requirements for a tenant and runs a compliance scan right away.

StackTakt demonstrates and evidences specific technical capabilities mapped to Security Rule citations. It does not by itself satisfy the Security Rule for any organization; your compliance program, policies, and audit outcomes remain your responsibility.

The catalog release carries 52 Security Rule requirements across the administrative, physical, technical, organizational, and documentation safeguards. Each requirement records:

  • Its citation, written as the CFR section, for example 164.312(a)(1). Displays add the section mark: §164.312(a)(1).
  • Its obligation: a standard, a required implementation specification, or an addressable implementation specification.
  • Its coverage class: how StackTakt can help with it.
ClassMeaning
AutomatedA deployable or evaluable technical control covers it.
Partially automatedTechnical controls cover part; an attestation document covers the rest.
Manual attestationNo technical control reaches it; a completed, approved document demonstrates it.
Inherited from AWSCarried by AWS’s own responsibilities.

This split is why the matrix is honest: requirements like the sanction policy or workforce training can never be “demonstrated” by infrastructure, and StackTakt routes them through attestation documents instead of pretending a bucket setting covers them.

Some Security Rule expectations become numeric floors the templates consume. A HIPAA profile sets, for example, a 2,190-day (six-year) log-retention floor, against SOC 2’s 365; when a tenant adopts both, the strictest value wins. The same mechanism covers backup retention and access-key age.

  • Blueprint pages and the deploy wizard show each template’s HIPAA mappings with statuses and verbatim caveats.
  • The Compliance matrix rolls every requirement up per tenant or per AWS account.
  • The evidence PDF cites the Security Rule per captured configuration.

SOC 2 criteria live in the same catalog and appear through the same framework lens; the Security Rule remains the most fully mapped framework today.