{
  "node_id": "us-hipaa-automated-workflow-45-cfr-164-312-access-control",
  "title": "US HIPAA 45 CFR 164.312 - Technical Safeguards for Electronic Protected Health Information in Automated Healthcare Workflows",
  "domain": "Workflow Automation",
  "version": "1.0.0",
  "last_updated": "2026-05-09",
  "bluf": "Covered entities and business associates operating automated healthcare workflows must implement five technical safeguard standards for electronic protected health information (ePHI): access control (unique user ID, emergency access, automatic logoff, encryption), audit controls (activity logging and examination), integrity (ePHI alteration detection), person or entity authentication (identity verification before access), and transmission security (integrity controls and encryption in transit). Required specifications are mandatory; addressable specifications must be implemented or substituted with documented equivalent alternatives.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
  },
  "crosswalks": {
    "_available_keys": [
      "nist_framework",
      "iso_standard",
      "industry_mapping",
      "ai_overlay_2026"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "nist-csf-2-0-govern-function",
    "eu-nis2-directive-2022-2555"
  ],
  "primary_citations_count": 7
}