36% of HITECH Act you already have
ISO 13485 already covers about 36% of HITECH Act, leaving
7 of 11 controls as genuinely new work.
Already covered 0
Likely covered 4
New work 7
No control in ISO 13485
maps directly to one in HITECH Act. Everything counted as covered is covered because both
map to the same third standard, which is what a crosswalk is, but it is an inference rather
than a lookup.
What is genuinely new work
Nothing in ISO 13485 reaches these. This is the list to scope.
HITECH-2024-2025-NPRM-ReproductiveHealth-SectoralHITECH 2024-2025 Pipeline - HIPAA Security Rule NPRM (Dec 2024), Reproductive Health, OCR Audits, Sectoral Application
HITECH-Crosswalk-HIPAA-NIST-CSF-405d-SectoralHITECH Crosswalk to HIPAA Privacy + Security + Breach Notification Rules + NIST CSF + HHS 405d + State Laws
HITECH-Implementation-Roles-Compliance-AuditHITECH Implementation Roadmap, Organizational Roles, Compliance + Audit-Readiness
HITECH-Scope-ARRA-XIII-42USC-Ch156-SubtitlesHITECH Act Statutory Scope, ARRA Title XIII Origin and 42 USC Chapter 156 Structure (Subtitles A through D)
HITECH-Sectoral-Hospitals-Health-Plans-Pharma-TechHITECH Sectoral Application: Hospitals, Health Plans, Pharma, Tech BAs, State Coordination, OCR Wall of Shame
HITECH-Status-Adoption-Vision-Cures-FutureRegulationHITECH Status, Adoption Statistics, ARRA + Cures Act + 2024 NPRM Vision and Future Healthcare Cybersecurity
HITECH-SubtitleA-ONC-HIT-Standards-EHR-MU-PIHITECH Subtitle A - ONC, HIT Standards Committee, EHR Certification, Meaningful Use / Promoting Interoperability
Show the 4 you already have
HITECH-Coord-HIPAA-Privacy-Security-Cures-ONCHITECH Coordination with HIPAA Privacy Rule + HIPAA Security Rule (Verified Separately) + 21st Century Cures Act + ONC
HITECH-Enforcement-CMP-Tiers-StateAGs-OCRHITECH 4-Tier Civil Monetary Penalty Structure, State AGs Enforcement and HHS OCR Settlements
HITECH-SubtitleD-Breach-Notification-BA-Direct-LiabilityHITECH Subtitle D - Breach Notification Rule (45 CFR Part 164 Subpart D), Business Associate Direct Liability, Subcontractors
HITECH-SubtitleD-StrengthIndividualRightsHITECH Subtitle D - Strengthened Individual Rights (Electronic Access, Accounting of Disclosures, Restrictions, Sale Prohibition)
How this is calculated
Already covered means a mapping runs from a control in ISO 13485 to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition