April 13, 2026 · Ken Armstrong
45 CFR 164.502(a) covers permitted and required uses and disclosures. In most assessments the control itself is present and the record proving it is not, which is why this requirement produces findings at organizations that are, in practice, doing the work.
Standard. A covered entity or business associate may not use or disclose protected health information, except as permitted or required by this subpart or by subpart C of part 160 of this subchapter.
That is the operative language of 45 CFR 164.502(a). Read it closely: it describes an outcome to achieve, not a product to buy, which is why two practices of the same size can satisfy it in different ways and both be right.
In an assessment, 45 CFR 164.502(a) is not one question. It resolves into several, and each one is really asking for a different artifact:
Ownership usually sits with the compliance owner, though the evidence is often produced by someone else, which is where the trail breaks. A control that works but has no owner tends to stop working the month the person who quietly maintained it changes roles.
Every covered entity. Business associates are directly liable for only a defined subset of these obligations, so read your business associate agreement alongside the rule rather than assuming the duty transfers. There is no scalability defense here of the kind the Security Rule offers at 45 CFR 164.306(b): a deadline is a deadline at any size. What does scale is how you meet it, and 45 CFR 164.530(i) expects your policies to be designed for the size and activities of your organization.
The sequence below is the order that produces evidence as a by-product rather than as a separate documentation exercise:
The same evidence answers more than one framework. The questions behind 45 CFR 164.502(a) also map to SOC 2 C1.1; NIST 800-53 PT-2, PT-3, SA-9; HITRUST 13.e, 13.f; NIST Privacy CT.PO-P1, GV.MT-P4, GV.PO-P4; GDPR Art 28, Art 5, Art 6. That matters for scoping: if you are working toward SOC 2 or an ISO certification alongside HIPAA, this control is one piece of work and several answers, provided the artifact is written once and referenced rather than rewritten per framework.
For this requirement the artifact types that satisfy it are policy, procedure, and report. The distinction matters more than it looks: a policy states what you intend to do, a procedure states how, and a record proves it happened on a date. Auditors ask for all three, and a practice that has written the first two often has nothing for the third.
Date every artifact and keep the superseded versions. The Privacy Rule carries its own retention rule at 45 CFR 164.530(j)(2): six years from the date of creation or the date when it last was in effect, whichever is later. It is the same period the Security Rule sets at 164.316(b)(2)(i), under a different provision, so cite the one that governs the document you are holding.
The usual gap is a control that exists in practice and nowhere in writing. Someone does the work, reliably, and it has never been written down, so the organization cannot demonstrate it and cannot notice when it stops. The fix is not more control, it is a dated record and a named owner.
The practical test for 45 CFR 164.502(a) is whether someone unfamiliar with your organization could read your documentation and tell what you do, who does it, and when it last happened. If they can, the requirement is met. If they need you in the room to explain it, it is not.