Framework overlap

Does HITECH Act cover NIST SP 800-190?

You hold HITECH Act and have been told to do NIST SP 800-190. Here is how much overlaps, control by control.

40% of NIST SP 800-190 you already have

HITECH Act already covers about 40% of NIST SP 800-190, leaving 27 of 45 controls as genuinely new work.

Already covered 0 Likely covered 18 New work 27

No control in HITECH Act maps directly to one in NIST SP 800-190. Everything counted as covered is covered because both map to the same third standard, which is what a crosswalk is, but it is an inference rather than a lookup.

What is genuinely new work

Nothing in HITECH Act reaches these. This is the list to scope.

NIST190-04
Regulatory compliance for cloud services
NIST190-09
Federation and single sign-on
NIST190-10
API security and access tokens
NIST190-13
Data residency and sovereignty
NIST190-17
Container and serverless security
NIST190-18
Cloud workload protection
NIST190-25
Service level agreement management
SP800-190-3.1
Container Image Vulnerability Management
SP800-190-3.10
Network Segmentation Between Pods
SP800-190-3.11
Mixed Sensitivity Workload Isolation
SP800-190-3.12
Container Runtime Hardening
SP800-190-3.13
Host Operating System Minimization
SP800-190-3.14
Host Patch Management
SP800-190-3.15
Container File System Integrity
SP800-190-3.16
Container Logging and Visibility
SP800-190-3.17
Runtime Threat Detection
SP800-190-3.18
Incident Response for Containers
SP800-190-3.19
Supply Chain Risk for Third Party Images
SP800-190-3.2
Image Configuration Hardening
SP800-190-3.20
Secrets Management at Runtime
SP800-190-3.3
Embedded Secrets in Images
SP800-190-3.4
Image Trust and Provenance
SP800-190-3.5
Registry Authentication and Authorization
SP800-190-3.6
Registry Image Freshness
SP800-190-3.7
Orchestrator Authentication
SP800-190-3.8
Orchestrator Authorization with RBAC
SP800-190-3.9
Pod Security Standards
Show the 18 you already have
NIST190-01
Shared responsibility model definition
NIST190-02
Cloud security policy and strategy
NIST190-03
Cloud risk assessment
NIST190-05
Cloud security roles and responsibilities
NIST190-06
Cloud identity management
NIST190-07
Multi-factor authentication for cloud
NIST190-08
Privileged access in cloud environments
NIST190-11
Data classification for cloud
NIST190-12
Encryption of cloud-stored data
NIST190-14
Data backup and recovery in cloud
NIST190-15
Secure data deletion in cloud
NIST190-16
Virtual network segmentation
NIST190-19
Image and template hardening
NIST190-20
Cloud configuration management
NIST190-21
Cloud security monitoring and logging
NIST190-22
Incident response in cloud
NIST190-23
Cloud vulnerability management
NIST190-24
Cloud change management

How this is calculated

Already covered means a mapping runs from a control in HITECH Act to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition