Skip to content
Menu ▾
Patent pending

Regulayer  /  The 146 laws  /  Privacy law

HIPAA · Security Rule

Audit controls over ePHI.

Applies to: Healthcare / health-data AI (US).

What the signed record shows

Audit-control, integrity, and authentication evidence for systems touching health data.

The proof is a signed, tamper-evident record. Anyone can check it, free, without an account, and nothing has to leave the building to make it. Evidence, not a promise.

Citation: 45 CFR §164.312(a)/(b)/(c)/(d), 308(a)(1)(ii)(D)

In the same family

What to do about it

Seven days free, then $349 a month.

A signed record of which AI you used and what you checked, sealed to the exact file you deliver, made on your own machine and checkable free by anyone you send it to.

Start the free weekOr verify a real record, free →

Part of the Regulayer proof catalogue: 146 laws and standards, one sealed engine. This page is a product description, not legal advice.

What the statute requires, section by section

HIPAA Security Rule, 45 CFR Part 164, Subpart C (Security Standards for the Protection of Electronic Protected Health Information). The technical-safeguard standards this mapper evidences from the per-decision signed record:

§164.312(b)
Audit controls (record and examine activity in information systems that contain or use ePHI).
§164.312(c)(1)
Integrity (protect ePHI from improper alteration or destruction).
§164.312(d)
Person or entity authentication (verify the identity seeking access).
§164.308(a)(1)(ii)(D)
Information system activity review (regularly review records of information system activity).
§164.312(a)(1)
Access control (the system/service whose access is governed).

Taken from the Regulayer entry for this instrument, which is built against the primary text.