HIPAA Security Rule
The HIPAA Security Rule (45 CFR Part 164 Subpart C) is StackTakt’s anchor framework: the first one the blueprints map to and the one the evidence PDF cites. Adopting it on the Compliance page activates its requirements for a tenant and runs a compliance scan right away.
StackTakt demonstrates and evidences specific technical capabilities mapped to Security Rule citations. It does not by itself satisfy the Security Rule for any organization; your compliance program, policies, and audit outcomes remain your responsibility.
What the catalog tracks
Section titled “What the catalog tracks”The catalog release carries 52 Security Rule requirements across the administrative, physical, technical, organizational, and documentation safeguards. Each requirement records:
- Its citation, written as the CFR section, for example
164.312(a)(1). Displays add the section mark: §164.312(a)(1). - Its obligation: a standard, a required implementation specification, or an addressable implementation specification.
- Its coverage class: how StackTakt can help with it.
The four coverage classes
Section titled “The four coverage classes”| Class | Meaning |
|---|---|
| Automated | A deployable or evaluable technical control covers it. |
| Partially automated | Technical controls cover part; an attestation document covers the rest. |
| Manual attestation | No technical control reaches it; a completed, approved document demonstrates it. |
| Inherited from AWS | Carried by AWS’s own responsibilities. |
This split is why the matrix is honest: requirements like the sanction policy or workforce training can never be “demonstrated” by infrastructure, and StackTakt routes them through attestation documents instead of pretending a bucket setting covers them.
Parameters
Section titled “Parameters”Some Security Rule expectations become numeric floors the templates consume. A HIPAA profile sets, for example, a 2,190-day (six-year) log-retention floor, against SOC 2’s 365; when a tenant adopts both, the strictest value wins. The same mechanism covers backup retention and access-key age.
Where you see it
Section titled “Where you see it”- Blueprint pages and the deploy wizard show each template’s HIPAA mappings with statuses and verbatim caveats.
- The Compliance matrix rolls every requirement up per tenant or per AWS account.
- The evidence PDF cites the Security Rule per captured configuration.
SOC 2 criteria live in the same catalog and appear through the same framework lens; the Security Rule remains the most fully mapped framework today.