| Framework | HIPAA Security Rule |
|---|---|
| Control ID | §164.308(a)(3) |
| Control Family | Administrative Safeguards > Workforce Security |
| Control Name | Workforce Security |
| Status | IMPLEMENTED |
| Assessment Date | 2026-04-19T02:25:35.202960+00:00 |
| Assessor | TITAN AI Scanner v2.0 (CONDUCTOR + BASTION + SCOUT + COMPLY + SAGE) |
| Environment Scope | Azure: Pay-As-You-Go (prod) (4f29d094-1079-44c9-acb0-4d73a7a2dd34) |
| Report ID | 175d89a9a168b9ae707989a094178a6edd14d4d5a390d3a2426146f2728d90c1 |
Standard: Workforce security. Implement policies and procedures to ensure that all members of its workforce have appropriate access to electronic protected health information, as provided under paragraph (a)(4) of this section, and to prevent those workforce members who do not have access under paragraph (a)(4) of this section from obtaining access to electronic protected health information.
Source: https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C/section-164.308
Each implementation specification addressed separately per HIPAA §164.306(d) / NIST 800-53A assessment methodology.
Implement procedures for the authorization and/or supervision of workforce members who work with electronic protected health information or in locations where it might be accessed.
Implement procedures to determine that the access of a workforce member to electronic protected health information is appropriate.
Summarized with counts + exceptions + drill-down. Raw data available on request per retention policy.
Test of Design (does the control exist?) + Test of Operating Effectiveness (does it work consistently?). Sampling per AICPA AU-C 530.
8 terminations
All 8 had AAD disable within 24h.
Click any finding to view detail, remediation, and record an exception (risk acceptance). Exceptions are retained in the report as part of the audit trail.
No findings for this control.
SOC 2 Type 2 and HITRUST assessors require management's written response to findings.
| Scanner | TITAN AI Scanner v2.0 (CONDUCTOR + BASTION + SCOUT + COMPLY + SAGE) |
|---|---|
| Scanner version | v2.0.1 |
| Collection timestamp | 2026-04-19T02:25:35.202960+00:00 |
| Retention | 2555 days (HIPAA 164.316(b)(2)) |
| Report hash (SHA-256) | 175d89a9a168b9ae707989a094178a6edd14d4d5a390d3a2426146f2728d90c1 |
This same evidence is admissible for the following related controls. Scan once, satisfy multiple frameworks.
PS-3, PS-4, PS-5, AC-2(3) — same evidence satisfiesCC1.4, CC6.2, CC6.3 — same evidence satisfiesA.7.1, A.7.2, A.7.3 — same evidence satisfies12.7, 8.1.3 — same evidence satisfies02.a, 02.b, 02.c — same evidence satisfies