CROSSWALK MAPPINGVerified Data

Mapping HIPAA Security Rule to NIST Cybersecurity Framework

A practitioner-grade, domain-level crosswalk between HIPAA Security Rule and NIST Cybersecurity Framework. Understand how these compliance standards overlap to streamline your audit programs.

Basis for Alignment

HHS's Office for Civil Rights, developed jointly with NIST and ONC, published an official 'HIPAA Security Rule Crosswalk to NIST Cybersecurity Framework' (February 2016) mapping every HIPAA safeguard to a CSF subcategory. That document predates CSF 2.0's GOVERN function (added 2024 — the 2016 crosswalk covers only Identify/Protect/Detect/Respond/Recover), so rows involving GV extend the same logic rather than citing the original publication, and are marked moderate accordingly.

Overall Confidence:high
Last Verified:2026-08-07

Domain Correspondences

HIPAA Security Rule
§164.308: Administrative Safeguards
NIST Cybersecurity Framework
ID: IDENTIFY

HIPAA's required risk analysis and risk management provisions are, by name, the same activity as CSF's IDENTIFY function.

HIPAA Security Rule
§164.308: Administrative Safeguards
NIST Cybersecurity Framework
PR: PROTECT

Workforce training and access-management provisions in Administrative Safeguards correspond directly to CSF's PROTECT function.

HIPAA Security Rule
§164.308: Administrative Safeguards
NIST Cybersecurity Framework
RC: RECOVER

HIPAA's contingency-planning requirement corresponds directly to CSF's RECOVER function.

HIPAA Security Rule
§164.308: Administrative Safeguards
NIST Cybersecurity Framework
RS: RESPOND

HIPAA's Security Incident Procedures requirement corresponds to CSF's RESPOND function; this specific requirement is not named in this app's abbreviated domain description, so this row relies on the underlying rule text rather than the app copy alone.

HIPAA Security Rule
§164.312: Technical Safeguards
NIST Cybersecurity Framework
PR: PROTECT

Access control, authentication, and transmission security in Technical Safeguards are core CSF PROTECT topics.

HIPAA Security Rule
§164.312: Technical Safeguards
NIST Cybersecurity Framework
DE: DETECT

Audit controls and integrity controls in Technical Safeguards correspond to CSF's DETECT function.

HIPAA Security Rule
§164.314: Organizational Requirements
NIST Cybersecurity Framework
GV: GOVERN

HIPAA's Business Associate Agreement requirements are third-party/vendor risk controls, matching CSF 2.0's GOVERN supply-chain-risk-management category — a function that did not exist when HHS's official crosswalk was published.

Explore Interactively

Use our interactive crosswalk matrix to explore mappings between HIPAA Security Rule, NIST Cybersecurity Framework, and 10 other compliance frameworks simultaneously.

Open Interactive Matrix