HIPAA Safeguards: Complete Guide [2026]

SaltyCloud Research Team

Updated Aug 12, 2026 Read Time 14 min

HIPAA Safeguards: Administrative, Physical, and Technical Controls Explained

HIPAA safeguards are the control set the HIPAA Security Rule uses to protect electronic protected health information (ePHI). They divide into three categories, administrative, physical, and technical, and together comprise 18 standards and more than 30 implementation specifications. Every covered entity (CE) and business associate (BA) that handles ePHI must implement them. In 2026, the Security Rule remains the baseline that regulators, cyber insurers, and partners measure against.

This guide explains each category in depth, marks every specification as Required or Addressable, and provides the full 18-standard reference table. It also clarifies the Required-versus-Addressable distinction that trips up most teams. It shows what safeguard violations look like in Office for Civil Rights (OCR) enforcement, and it identifies what sits outside the Security Rule entirely. The HIPAA Security Rule pillar covers the Rule’s history and scope. This page owns the safeguards themselves.

What Are HIPAA Safeguards?

HIPAA safeguards are the administrative, physical, and technical controls that the HIPAA Security Rule requires covered entities and business associates to use to protect electronic protected health information (ePHI). The Security Rule sets them out at 45 CFR Part 164 Subpart C.

HIPAA safeguards include three categories of controls: administrative, physical, and technical. They are established at 45 CFR Part 164 Subpart C of the HIPAA Security Rule. Together they require covered entities and business associates to protect ePHI with 18 standards and more than 30 implementation specifications.

The Security Rule frames every safeguard around protecting the confidentiality, integrity, and availability of ePHI against reasonably anticipated threats, unauthorized uses, and impermissible disclosures. It takes a risk-based, technology-neutral approach, so a single standard scales from a solo practice to a national health plan. Each covered entity and business associate decides how to meet a standard based on its own size, complexity, and risk profile, and then documents that decision.

The safeguards apply to every covered entity, a health plan, a health care clearinghouse, or a health care provider that transmits health information electronically, and to every business associate that creates, receives, maintains, or transmits ePHI on a covered entity’s behalf. Organization size grants no exemption. The Rule reaches ePHI specifically, the electronic subset of protected health information, and not paper records or spoken communications.

Each control falls into one of three categories: administrative (the largest by control count), physical (the smallest), and technical (the most cross-linked to other requirements).

  • Administrative safeguards: Policies, procedures, and workforce-management actions.
  • Physical safeguards: Physical measures protecting facilities, workstations, and devices.
  • Technical safeguards: Technology-based controls protecting ePHI and access to it.

Together, they include 18 standards and more than 30 implementation specifications.

  • A standard is a top-level requirement.
  • An implementation specification is a specific action that satisfies the standard.

Every specification also carries one of two labels, Required or Addressable, which sets how much discretion an organization has in meeting it.

Required vs. Addressable Implementation Specifications

Every HIPAA Security Rule implementation specification is classified as either Required or Addressable. The distinction is regulatory, and it is one of the most-misunderstood concepts in the Rule.

A Required specification (45 CFR § 164.306(d)(2)) must be implemented as written, with no discretion.

An Addressable specification (45 CFR § 164.306(d)(3)) works differently. The organization must first assess it, then do one of three things:

  • Implement the specification as written.
  • Implement an equivalent alternative and document why that alternative is reasonable and appropriate.
  • Document why the specification is not reasonable and appropriate and why no alternative is needed.

Addressable does not mean optional, however. The decision must trace back to the HIPAA risk assessment and be documented. According to the OCR FAQ on addressable and required specifications, organizations that do nothing for Addressable specifications face the same range of penalties as those that fail Required specifications.

Administrative Safeguards

Administrative safeguards are the policies, procedures, and workforce-management actions that govern security measures. They cover how covered entities and business associates select, develop, implement, and maintain those measures. Codified at 45 CFR § 164.308 with nine standards and more than a dozen implementation specifications, it is the largest of the three categories.

Security Management Process: Required

The Security Management Process is the foundational administrative standard for identifying and reducing risks to ePHI. It contains four Required specifications:

  • Risk Analysis
  • Risk Management
  • Sanction Policy
  • Information System Activity Review

For more on risk analysis, see the HIPAA risk assessment guide.

Assigned Security Responsibility: Required

Assigned Security Responsibility requires every covered entity and business associate to designate a HIPAA Security Officer responsible for developing and implementing Security Rule policies and procedures.

Workforce Security: Addressable

Workforce Security governs which workforce members can access ePHI. Its Addressable specifications are authorization and supervision, workforce clearance procedures, and termination procedures.

Information Access Management: Required and Addressable

Information Access Management controls how workforce members are granted access to ePHI. Isolating healthcare clearinghouse functions is Required, while access authorization and access establishment and modification are Addressable.

Security Awareness and Training: Addressable

Security Awareness and Training builds a security-aware workforce across the organization. Its Addressable specifications are security reminders, protection from malicious software, log-in monitoring, and password management.

Security Incident Procedures: Required

Security Incident Procedures define how the organization identifies and responds to security incidents. They require covered entities and business associates to mitigate the effects of suspected or known incidents and to document each incident and its outcome.

Contingency Plan: Required and Addressable

The Contingency Plan keeps ePHI available during an emergency or system failure. Data backup, disaster recovery, and emergency mode operation plans are Required, while testing-and-revision procedures and applications-and-data criticality analysis are Addressable. This standard is where ePHI disaster recovery, high availability, and uptime expectations live operationally.

Evaluation: Required

Evaluation measures how well an organization’s safeguards continue to meet the Security Rule. It calls for periodic technical and non-technical assessment as systems and threats change.

Business Associate Contracts: Required

Business Associate Contracts extend safeguard obligations to third parties that handle ePHI. The standard requires written contracts with HIPAA business associates that create, receive, maintain, or transmit ePHI on the organization’s behalf.

Section 5 of NIST SP 800-66 Rev. 2 provides implementation guidance for each of these standards, scaled to organization size.

Physical Safeguards

Physical safeguards protect ePHI from unauthorized physical access, theft, and environmental hazards. They cover facility access, workstation security, and the lifecycle of any electronic media that contains ePHI. Codified at 45 CFR § 164.310, this is the smallest category by control count, with just four standards.

Physical safeguards still matter in 2026, even though hacking and information-technology (IT) incidents now dominate the Department of Health and Human Services (HHS) Breach Portal. Lost and stolen unencrypted devices continue to produce reportable breaches, and physical safeguards combined with encryption form the most effective defense against them.

Facility Access Controls: Addressable

Facility Access Controls limit physical access to the facilities and rooms that house ePHI systems. The Addressable specifications are:

  • Contingency operations
  • A facility security plan
  • Access control and validation procedures
  • Maintenance records

A hospital, for example, can satisfy these requirements with badge-access controls on the data center, a documented visitor-escort procedure, and a maintenance log.

Workstation Use: Required

Workstation Use sets the rules for how and where workstations that access ePHI may be used. It requires policies specifying the proper functions, manner, and physical surroundings of those workstations.

For instance, a clinic can satisfy this requirement with a policy requiring auto-lock and privacy screens on workstations in shared exam rooms, plus a remote-work configuration policy.

Workstation Security: Required

Workstation Security restricts physical access to workstations to authorized users. Examples include:

  • Cable locks on portable workstations
  • Locked rooms or cabinets for fixed workstations
  • Badge-controlled access to areas with ePHI workstations

Device and Media Controls: Required and Addressable

Device and Media Controls govern the full lifecycle of any electronic media containing ePHI, including hard drives, USB drives, tape backups, mobile devices, and decommissioned servers.

  • Required: Disposal and media re-use.
  • Addressable: Accountability (tracking media), and data backup and storage.

Organizations can satisfy this requirement with a documented hard-drive sanitization process per NIST SP 800-88 Rev. 2, a USB-drive chain-of-custody log, and a mobile device management (MDM)-enforced remote-wipe policy on company-issued mobile devices.

Technical Safeguards

Technical safeguards are the technology-based controls that protect ePHI and govern who can access it. They comprise access control, audit controls, integrity, person-or-entity authentication, and transmission security. Codified at 45 CFR § 164.312 with five standards, this is the most cross-linked category in the cluster.

Access Control: Required and Addressable

Access Control limits ePHI to authorized users and software programs.

  • Required: Unique user identification and an emergency access procedure.
  • Addressable: Automatic logoff, and encryption and decryption.

However, the Rule prescribes no specific password policy. NIST SP 800-66 Rev. 2 references NIST SP 800-63B (SP 800-63-4 is the successor) for current authentication guidance, including modern passphrase length and lifetime recommendations.

Although encryption is Addressable, HHS treats encrypted ePHI as not “unsecured,” which makes encryption a de facto safe harbor.

Audit Controls: Required

Audit Controls record and examine activity in the information systems that contain ePHI. The standard relies on hardware, software, and procedural mechanisms and has no implementation specifications below it.

For more about log content, retention, and review cadence, see the HIPAA security audit guide.

Integrity: Addressable

Integrity protects ePHI from improper alteration or destruction. The standard calls for a mechanism to authenticate ePHI and confirm it has not been altered or destroyed in an unauthorized manner. ePHI patch management also sits here, since unpatched systems are a leading cause of integrity-affecting incidents such as ransomware.

Person or Entity Authentication: Required

Person or Entity Authentication verifies that anyone seeking access to ePHI is who they claim to be. The standard requires procedures to confirm that identity. Multi-factor authentication is not named explicitly, but it aligns with current NIST SP 800-63B guidance for accounts that reach sensitive data.

Transmission Security: Addressable

Transmission Security protects ePHI as it moves across an electronic network. Its Addressable specifications are integrity controls and encryption.

NIST SP 800-66 Rev. 2 points to NIST SP 800-52 Rev. 2 (Transport Layer Security, TLS) as implementation guidance for transmission security, and NIST SP 800-52 Rev. 2 sets TLS 1.2 as the minimum version.

Full HIPAA Safeguards List

The full HIPAA safeguards list spans 18 standards and more than 30 implementation specifications across the three categories. The NIST HIPAA Security Rule Crosswalk maps each standard to the NIST Cybersecurity Framework (CSF) and NIST 800-53. The following table summarizes each standard, its implementation specifications, and its Required or Addressable status.

Category Standard CFR § Implementation Specifications Status
Administrative Security Management Process 164.308(a)(1) Risk Analysis · Risk Management · Sanction Policy · Info System Activity Review All Required
Administrative Assigned Security Responsibility 164.308(a)(2) (Standard itself) Required
Administrative Workforce Security 164.308(a)(3) Authorization/Supervision · Workforce Clearance · Termination All Addressable
Administrative Information Access Management 164.308(a)(4) Isolating Clearinghouse Functions · Access Authorization · Access Establishment/Modification Required (1st), Addressable (rest)
Administrative Security Awareness and Training 164.308(a)(5) Security Reminders · Malware Protection · Log-in Monitoring · Password Management All Addressable
Administrative Security Incident Procedures 164.308(a)(6) Response and Reporting Required
Administrative Contingency Plan 164.308(a)(7) Data Backup · Disaster Recovery · Emergency Mode · Testing/Revision · Applications/Data Criticality Required (first 3), Addressable (last 2)
Administrative Evaluation 164.308(a)(8) (Standard itself) Required
Administrative Business Associate Contracts 164.308(b)(1) Written Contract or Other Arrangement Required
Physical Facility Access Controls 164.310(a)(1) Contingency Operations · Facility Security Plan · Access Control/Validation · Maintenance Records All Addressable
Physical Workstation Use 164.310(b) (Standard itself) Required
Physical Workstation Security 164.310(c) (Standard itself) Required
Physical Device and Media Controls 164.310(d)(1) Disposal · Media Re-use · Accountability · Data Backup/Storage Required (first 2), Addressable (last 2)
Technical Access Control 164.312(a)(1) Unique User ID · Emergency Access · Automatic Logoff · Encryption/Decryption Required (first 2), Addressable (last 2)
Technical Audit Controls 164.312(b) (Standard itself) Required
Technical Integrity 164.312(c)(1) Mechanism to Authenticate ePHI Addressable
Technical Person or Entity Authentication 164.312(d) (Standard itself) Required
Technical Transmission Security 164.312(e)(1) Integrity Controls · Encryption All Addressable

For the full crosswalk mapping each of these 18 standards to NIST CSF subcategories and NIST 800-53 controls, access the HIPAA Security Rule Crosswalk Toolkit.

Examples of Safeguard Violations

OCR enforcement actions are the clearest examples of safeguard violations and a useful pattern catalog for what auditors look for. Violations rarely stay in one category, so an enforcement action that names one almost always documents related failures in at least one other category.

Examples of Administrative Safeguard Violations

The most common administrative violation is a missing or stale Risk Analysis. In these cases, an organization either never conducted an enterprise-wide risk analysis or did not update it after a major change such as a cloud electronic health record (EHR) migration.

Risk analysis is the linchpin of every other safeguard decision, and OCR frequently cites it in enforcement actions. Corrective-action plans routinely require a fresh enterprise-wide risk analysis under multi-year HHS oversight.

Examples of Physical Safeguard Violations

Most physical violations pair insufficient Device and Media Controls with the absence of Access Control encryption. When an unencrypted laptop, USB drive, or backup tape is lost or stolen, the ePHI counts as “unsecured,” which triggers notification to affected individuals, HHS, and, for breaches affecting 500 or more people, the media.

Examples of Technical Safeguard Violations

Technical violations tend to center on inadequate Audit Controls. In these cases, organizations cannot produce logs showing who accessed which records, and when. Without audit controls, OCR cannot complete its breach-impact analysis, and the organization cannot demonstrate compliance with the adjacent Information System Activity Review standard.

What’s NOT Part of the HIPAA Security Rule

Several categories commonly associated with HIPAA are not part of the HIPAA Security Rule. Understanding what sits outside the Rule is essential for accurate scope-setting.

The Privacy Rule

The HIPAA Privacy Rule governs uses and disclosures of all protected health information and patient rights. Codified at 45 CFR Part 164 Subpart E, it operates alongside the Security Rule and not within it, as explained in HHS OCR Privacy Rule guidance.

The Breach Notification Rule

The Breach Notification Rule governs post-breach notification and is likewise separate. It is codified at 45 CFR Part 164 Subpart D and explained in the HHS OCR Breach Notification Rule overview.

Paper Records and Oral PHI

Paper records and oral PHI fall outside the Security Rule, which covers ePHI only. Two other categories are also excluded:

  • Family Educational Rights and Privacy Act (FERPA)-covered education records, even when they contain health information, an overlap that higher-education health centers watch closely.
  • Employment records held by a covered entity in its capacity as an employer.

How to Simplify HIPAA Compliance

Isora GRC is the collaborative GRC Assessment Platform™ that runs assessments across all 18 HIPAA Security Rule safeguard standards in one shared workspace, mapping the administrative, physical, and technical categories to a single workflow.

The Questionnaires and Surveys capability ships with prebuilt, customizable HIPAA questionnaires aligned to all three safeguard categories, and the same library scales into multi-framework programs across HIPAA, NIST CSF, and NIST 800-53 as a program grows.

Download the HIPAA Security Rule Crosswalk Toolkit to map all 18 safeguards to NIST CSF and 800-53.

See how Isora GRC simplifies HIPAA Security Rule compliance →

HIPAA Safeguards FAQs

What are HIPAA safeguards?

HIPAA safeguards are the administrative, physical, and technical controls required by the HIPAA Security Rule (45 CFR Part 164 Subpart C) to protect electronic protected health information (ePHI). Together they form 18 standards and more than 30 implementation specifications that every covered entity and business associate must implement.

What are the 3 types of HIPAA safeguards?

The three types are administrative (45 CFR § 164.308), physical (45 CFR § 164.310), and technical (45 CFR § 164.312). Administrative is the largest category, physical the smallest, and technical the most cross-linked to other Security Rule requirements.

What’s the difference between Required and Addressable specifications?

Required specifications must be implemented as written. Addressable specifications must be assessed, and the organization must either implement them, document an equivalent alternative, or document why implementation is not reasonable and appropriate. Addressable does not mean optional.

Which category is NOT part of the HIPAA Security Rule?

The Privacy Rule, the Breach Notification Rule, paper records, oral communications, FERPA-covered education records, and employer-held employment records are not part of the Security Rule. The Security Rule covers ePHI only and is composed of administrative, physical, and technical safeguards.

Was this a violation of HIPAA security safeguards?

A violation occurs when a covered entity or business associate fails to implement a Required specification, or fails to defensibly document an Addressable specification’s equivalent alternative or non-implementation rationale. The most-cited safeguard violation in OCR enforcement is a missing or stale Risk Analysis (164.308(a)(1)(ii)(A)).

How many HIPAA safeguards are there?

The Security Rule contains 18 standards across the three categories: 9 administrative, 4 physical, and 5 technical. These contain more than 30 implementation specifications, each classified as either Required or Addressable.

Does HIPAA require encryption?

HIPAA’s encryption specifications at 164.312(a)(2)(iv) and 164.312(e)(2)(ii) are Addressable, not Required. However, HHS Breach Notification guidance treats encrypted ePHI as not “unsecured,” which makes encryption a de facto safe harbor. Enforcement actions involving unencrypted devices treat the absence of encryption as an aggravating factor.

This content is for informational purposes only and does not constitute legal or compliance advice. See our full disclaimer.

The InfoSec GRC Brief
Join 1,500+ security and compliance professionals who get monthly regulatory updates, GRC strategies, and threat intel with actionable next steps.
Let’s Chat
See the GRC Assessment Platform in action
Book a Demo