HIPAA Security Rule Mapping Overview
Status: Configuration and review reference
Scope
This public summary describes how LNC Nexus security capabilities can support a customer’s HIPAA Security Rule program. It is not a certification, attestation, legal opinion, or substitute for the customer’s risk analysis and implementation decisions.
Administrative Safeguards
LNC Nexus supports customer programs for:
- Security management and periodic risk review
- Assigned security responsibility and workforce oversight
- Access authorization, supervision, and timely access removal
- Security awareness, training, and acceptable-use practices
- Incident reporting, response, and contingency planning
- Periodic evaluation of safeguards and deployment configuration
Physical Safeguards
Physical safeguards are determined by the environment in which LNC Nexus is operated. Customers and hosting providers must address facility access, workstation security, devices, media, physical monitoring, and secure disposal appropriate to the deployment.
Technical Safeguards
LNC Nexus provides capabilities that support:
- Unique user access, role separation, session protection, and MFA
- Auditability of supported security and case operations
- Integrity and provenance checks for supported evidence workflows
- Protected transmission and configurable storage encryption
- Review of access activity and anomalous behavior
Exact thresholds, system identifiers, deployment topology, storage locations, and operational procedures are not published in this public document. They are verified as part of a private security review.
Customer Responsibilities
Customers must establish and document:
- A lawful basis for handling PHI and a minimum-necessary data policy
- Workforce authorization, training, and access lifecycle procedures
- Environment, endpoint, network, storage, key, backup, and retention safeguards
- Incident, breach-notification, legal-hold, and disaster-recovery procedures
- Required business associate and subcontractor agreements
- A current HIPAA risk analysis and periodic evaluation process
Assurance Boundary
LNC Nexus does not claim that a customer is HIPAA compliant merely because the application provides security features. Deployment-specific evidence, contractual terms, and control testing are handled through authenticated review channels.