HIPAA Security Rule and the AIC Kits
The HIPAA Security Rule sets administrative, physical, and technical safeguards for electronic protected health information. Analog Informatics Corporation (AIC) kits cover the access, audit, integrity, authentication, and transmission safeguards on paths the kit manages. The covered entity or business associate decides its compliance program. This page is not legal advice.

Security Rule Safeguards
| Safeguard | What the Kit Does |
|---|---|
| 164.308(a)(1) Security management process | Current State Compliance records findings. Information system activity review uses Audit. Risk analysis stays with the organization. |
| 164.308(a)(2) Assigned security responsibility | The organization assigns the official. |
| 164.308(a)(3) Workforce security | Account removal and change in the kit when the organization directs it. |
| 164.308(a)(4) Information access management | Privileged Access Management, Privileged User Management, and access review on kit accounts. |
| 164.308(a)(5) Security awareness and training | Training and attestation assigns material and records a signature. |
| 164.308(a)(6) Security incident procedures | Incident Response records the event and can alert. |
| 164.308(a)(7) Contingency plan | Backup and recovery stay with the organization. |
| 164.308(a)(8) Evaluation | The Assessment Binder supports periodic evaluation. |
| 164.308(b)(1) Business associate contracts | Contracts stay with the organization. |
| 164.310(a)(1) Facility access controls | Facilities stay with the organization. |
| 164.310(b) Workstation use | Configuration compliance on enrolled workstations. Use policy stays with the organization. |
| 164.310(c) Workstation security | Physical workstation security stays with the organization. |
| 164.310(d)(1) Device and media controls | Media disposal stays with the organization. The document sharing vault holds files on kit paths. |
| 164.312(a)(1) Access control | Unique accounts, emergency access through break-glass credentials, automatic session end, and encryption on kit paths. |
| 164.312(b) Audit controls | Audit, Windows Event Log, and syslog. |
| 164.312(c)(1) Integrity | Configuration compliance and protected audit records on kit paths. |
| 164.312(d) Person or entity authentication | Kit sign-in with another step beyond a password. |
| 164.312(e)(1) Transmission security | Validated cryptography on kit paths. |
| 164.316 Policies, procedures, and documentation | The organization writes the policies. The Assessment Binder stores them. |
Screenshots
More on Product Screenshots.
An assessment organization, certification body, or regulator decides whether a requirement is satisfied.