Loading controls...
Benchmark: 164.308(a)(4)(i) Information access management
Description
Implement policies and procedures for authorizing access to electronic protected health information that are consistent with the applicable requirements of subpart E of this part.
Usage
Browse dashboards and select 164.308(a)(4)(i) Information access management:
steampipe dashboard
Or run the benchmarks in your terminal:
steampipe check aws_compliance.benchmark.hipaa_security_rule_2003_164_308_a_4_i
Snapshot and share results via Steampipe Cloud:
steampipe loginsteampipe check --share aws_compliance.benchmark.hipaa_security_rule_2003_164_308_a_4_i
Controls
- IAM groups should have at least one user
- IAM policy should not have statements with admin access
- IAM users should be in at least one group
- IAM user should not have any inline or attached policies
- RDS DB instances should have iam authentication enabled