Dion Healthcare is considering migrating its electronic health records (EHR) system to a cloud provider. To ensure compliance, the organization must validate that the provider enforces strict security controls to protect patient data. Which compliance requirement is the MOST relevant for this scenario?