Bug 1832760 - (RFE) Add HIPAA profile into RHEL8 compliance content
Summary: (RFE) Add HIPAA profile into RHEL8 compliance content
Alias: None
Product: Red Hat Enterprise Linux 8
Classification: Red Hat
Component: scap-security-guide
Version: 8.1
Hardware: Unspecified
OS: Unspecified
Target Milestone: rc
: 8.0
Assignee: Watson Yuuma Sato
QA Contact: Gabriel Gaspar Becker
Mirek Jahoda
: 1832754 (view as bug list)
Depends On:
TreeView+ depends on / blocked
Reported: 2020-05-07 09:05 UTC by Marek Haicman
Modified: 2020-11-04 02:30 UTC (History)
6 users (show)

Fixed In Version: scap-security-guide-0.1.50-4.el8
Doc Type: Enhancement
Doc Text:
.`scap-security-guide` now provides a profile that implements HIPAA This update of the `scap-security-guide` packages adds the Health Insurance Portability and Accountability Act (HIPAA) profile to the RHEL 8 security compliance content. This profile implements recommendations outlined on the link:https://www.hhs.gov/hipaa/for-professionals/privacy/index.html[The HIPAA Privacy Rule] website. The HIPAA Security Rule establishes U.S. national standards to protect individuals’ electronic personal health information that is created, received, used, or maintained by a covered entity. The Security Rule requires appropriate administrative, physical, and technical safeguards to ensure the confidentiality, integrity, and security of electronically protected health information.
Clone Of:
Last Closed: 2020-11-04 02:30:10 UTC
Type: Bug
Target Upstream Version:

Attachments (Terms of Use)

System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHBA-2020:4626 0 None None None 2020-11-04 02:30:34 UTC

Description Marek Haicman 2020-05-07 09:05:17 UTC
Description of problem:
Provide a profile to cover HIPAA (Health Insurance Portability and Accountability Act) policy required by Healthcare organizations in NA.

Version-Release number of selected component (if applicable):

How reproducible:

Steps to Reproduce:
1. profile exists: oscap info --profiles /usr/share/xml/scap/ssg/content/ssg-rhel8-ds.xml
2. installation with HIPAA hardening works

Actual results:
profile does not exist

Expected results:
profile exists, and remediations hardens system to the "all green" state, i.e. state where rules not dependent on environments are passing

Additional info:
RHEL7 HIPAA should have similar content Bug 1513087

Comment 3 Marek Haicman 2020-05-13 15:16:52 UTC
*** Bug 1832754 has been marked as a duplicate of this bug. ***

Comment 23 errata-xmlrpc 2020-11-04 02:30:10 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory (scap-security-guide bug fix and enhancement update), and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.


Note You need to log in before you can comment on or make changes to this bug.