HIPAA Automatic Logoff: What the Rule Requires and What Timeout to Set
HIPAA automatic logoff is an addressable rule under 45 CFR § 164.312(a)(2)(iii). HIPAA names no exact timeout; risk analysis sets it, usually 2 to 15 minutes. Here is what the rule says, what times to pick by workspace, and why your website sessions count too.