- The HIPAA Security Series: OCR’s 7 Guidance Papers, Explained
- What Is the HIPAA Security Series?
- Why the HIPAA Security Series Was Published
- Paper 1 — Security 101 for Covered Entities
- Paper 2 — Security Standards: Administrative Safeguards
- Paper 3 — Security Standards: Physical Safeguards
- Paper 4 — Security Standards: Technical Safeguards
- Paper 5 — Organizational, Policies and Procedures, and Documentation Requirements
- Paper 6 — Basics of Risk Analysis and Risk Management
- Paper 7 — Implementation for the Small Provider
- What Is HIPAA Security Software?
- How to Simplify HIPAA Compliance
- Key Takeaways
- HIPAA Security Series FAQs
The HIPAA Security Series: OCR’s 7 Guidance Papers, Explained
The HIPAA Security Series is the closest thing to an official user’s manual for the HIPAA Security Rule. OCR published its seven papers between 2004 and 2007 to explain each part of the Rule in plain language. In 2026, they remain a useful entry point for anyone learning the Rule or scoping a compliance program.
This guide summarizes each of the seven papers and links directly to the OCR PDF. It also flags where the Series is becoming outdated, offering current implementation guidance to supplement such areas.
What Is the HIPAA Security Series?
The HIPAA Security Series is the U.S. Department of Health and Human Services Office for Civil Rights’ (HHS OCR) seven-paper educational guidance set on the HIPAA Security Rule, published 2004–2007. The papers cover Security 101, the three safeguard categories, organizational requirements, risk analysis, and implementation for small providers.
The HIPAA Security Series is a set of seven papers that OCR wrote to explain how to meet each part of the HIPAA Security Rule. Each paper takes one topic, states what the Rule requires, and offers practical ways to put it into effect.
Following the structure of the Security Rule itself, the Series moves from a broad introduction to the specific requirements in each part of the Rule.
- Paper 1: Security 101 for Covered Entities, an introduction to the Rule and the core concepts used across the Series.
- Papers 2 — 4: The three safeguard categories (administrative, physical, and technical).
- Paper 5: Organizational, policies and procedures, and documentation requirements.
- Paper 6: The basics of risk analysis and risk management.
- Paper 7: Implementation for solo and small-group providers.
OCR builds two concepts into every paper. The first sorts each implementation specification into Required or Addressable:
- Required specifications must be applied as written.
- Addressable specifications let an organization apply the specification, adopt an equivalent measure, or document why neither fits its environment.
The second is flexibility and scalability, which lets a solo practice and a national health system meet the same standards at a scale that matches their size, resources, and risk.
Why the HIPAA Security Series Was Published
The HIPAA Security Series gives covered entities and business associates a plain-English implementation guide for each part of the Security Rule. OCR published the papers between 2004 and 2007, as the April 2005 compliance deadline for HIPAA approached.
Created as educational guidance, the papers explain what HIPAA requires and suggest practical ways to implement it. But they do not add obligations beyond the Security Rule itself.
Notably, OCR has not refreshed the Series since 2007. Now, it predates:
- The HITECH Act (2009)
- The 2013 Omnibus Final Rule
- The 2025 Notice of Proposed Rulemaking (NPRM)
However, because the papers stay accurate on the parts of the Rule they cover, they’re still useful as a plain-language reference.
The current implementation companion is NIST SP 800-66 Revision 2, published February 2024. It maps HIPAA implementation to the NIST Cybersecurity Framework (CSF) 2.0 and NIST SP 800-53 Rev. 5, NIST’s CSF 2.0 white paper and security-and-privacy control catalog. Its Appendix D crosswalk ties each Security Rule standard and implementation specification to specific CSF 2.0 subcategories and SP 800-53 controls.
HHS’s voluntary 405(d) Health Industry Cybersecurity Practices (HICP) further complements the Series with sector-specific practices scaled to small versus medium and large organizations. And AHIMA’s analysis of updating HIPAA security for AI explores how the Series’ safeguard categories carry forward into that newer guidance.
Paper 1 — Security 101 for Covered Entities
Paper 1, Security 101 for Covered Entities is OCR’s introduction to the HIPAA Security Rule and the rest of the Security Series.
Paper 1 covers:
- Purpose and statutory background.
- Definitions used throughout the Series, including covered entity, business associate, and electronic protected health information (ePHI).
- Three safeguard categories at a high level.
- Required versus Addressable implementation specifications.
It also introduces language like “flexibility, scalability, and technology-neutral” that still runs through OCR enforcement guidance, explaining why the HIPAA Security Rule sets standards rather than prescriptive controls.
Paper 2 — Security Standards: Administrative Safeguards
Paper 2, Security Standards: Administrative Safeguards walks through every administrative-safeguard standard at 45 CFR § 164.308, the largest of the three safeguard categories.
Paper 2 covers:
- All nine administrative standards.
- Each specification’s Required or Addressable status.
- Sample questions a covered entity should ask when implementing each one.
Because the Security Management Process (164.308(a)(1)) houses the risk analysis requirement, every other safeguard decision flows from it.
Paper 3 — Security Standards: Physical Safeguards
Paper 3, Security Standards: Physical Safeguards covers the controls at 45 CFR § 164.310, the smallest of the three safeguard categories by control count.
Paper 3 covers:
- All four physical-safeguard standards.
- Facility entry controls and workstation positioning.
- Electronic-media disposal and re-use.
Device-and-media controls apply to any hardware that stores ePHI, including laptops, portable drives, and equipment being disposed of or reused.
Paper 4 — Security Standards: Technical Safeguards
Paper 4, Security Standards: Technical Safeguards details the technology-based controls at 45 CFR § 164.312.
Paper 4 covers:
- All five technical-safeguard standards and their Required or Addressable status.
- Access control, integrity, person-or-entity authentication, and transmission security.
- Encryption (Addressable but heavily favored) and audit-log mechanisms.
Audit Controls (164.312(b)) is Required and has no implementation specifications beneath it, a structural detail many readers miss.
Paper 5 — Organizational, Policies and Procedures, and Documentation Requirements
Paper 5, Security Standards: Organizational, Policies and Procedures, and Documentation Requirements sets out the cross-cutting program requirements at 45 CFR §§ 164.314 and 164.316 — the parts of the Rule that don’t fit neatly into any one safeguard category.
Paper 5 covers:
- Organizational requirements under 164.314 (business associate contracts and group-health-plan provisions).
- Policies and procedures under 164.316(a).
- Documentation under 164.316(b), including the six-year retention rule, availability to those who implement the policies, and periodic review.
These requirements tie the three safeguard categories together at the program level. The designated HIPAA Security Officer usually owns them, from business associate agreements to the policy lifecycle and required documentation.
Paper 6 — Basics of Risk Analysis and Risk Management
Paper 6, Basics of Risk Analysis and Risk Management is the canonical OCR reference for what 45 CFR § 164.308(a)(1)(ii)(A) actually requires, and one of the most-cited documents in HIPAA enforcement.
Paper 6 covers:
- The regulatory grounding for risk analysis and risk management.
- A nine-step process, running from scope and data collection through threat and vulnerability identification, current-measures assessment, likelihood, impact, risk levels, documentation, and periodic review.
- How the two functions pair, with the analysis driving the management decisions.
OCR treats risk analysis as the foundation for every other safeguard decision, which is why it surfaces so often in Resolution Agreements. Its ongoing Risk Analysis Initiative reinforces the point: as of an April 23, 2026 announcement, OCR had completed 19 ransomware-breach investigations and 13 Risk Analysis Initiative resolutions, most citing a missing or inadequate risk analysis.
A November 2024 HHS OIG report faulted OCR’s earlier audits — the 2016–2017 round covered only 8 of 180 HIPAA requirements and skipped the Security Rule’s physical and technical safeguards — prompting the broader 2024–2025 audit round now underway. Read Paper 6 alongside OCR’s separate Guidance on Risk Analysis, and for a step-by-step procedure version, see the HIPAA risk assessment guide.
Paper 7 — Implementation for the Small Provider
Paper 7, Implementation for the Small Provider is OCR’s guidance on scaling Security Rule compliance for solo and small-group practices.
Paper 7 covers:
- How the Rule’s flexibility and scalability principles play out at small-practice scale.
- Practical, sized-down implementation examples.
- The HHS Security Risk Assessment (SRA) Tool, built for small-practice use.
Small practices meet the same standards as larger organizations, scaled to their size, resources, and risk.
What Is HIPAA Security Software?
HIPAA security software operationalizes the Security Series by translating its categorical structure into assessment workflows, questionnaires, and audit-evidence repositories that span all 18 Security Rule standards.
In practice, “HIPAA security software” covers a few tool classes.
- GRC assessment-management platforms distribute HIPAA questionnaires, track responses, and consolidate findings.
- Security information and event management (SIEM) and log-management tools satisfy the audit-control requirement at the system level.
- Encryption and key-management products support the addressable encryption specifications.
The 2025 NPRM proposes moving several of those specifications from addressable to required, as Johnson Lambert HIPAA Security Shake-Up details. However, these changes are proposals, not current requirements. In the Fall 2026 Unified Agenda, HHS moved that proposed rule (RIN 0945-AA22) to its long-term agenda, with final action now projected for July 2027.
Still, no software “implements the Security Series.” Because the Series is guidance, HIPAA software supports the human-led implementation of the underlying Security Rule.
How to Simplify HIPAA Compliance
Isora GRC, the GRC Assessment Platform™, ships a prebuilt HIPAA questionnaire library structured around the same Security Rule standards the OCR Series describes.
- A prebuilt HIPAA questionnaire library maps to the administrative, physical, and technical safeguards at 45 CFR §§ 164.308, 164.310, and 164.312. Teams distribute the question set to department heads, system owners, and business associates instead of building it from scratch, and the same library serves NIST CSF and NIST 800-53 programs.
- The connected risk register populates findings directly from each assessment, tied to the safeguard that produced them. An append-only audit log records the state of every finding over time, which supports the documented, current evidence OCR expects for risk analysis.
- Distributed assessment management routes each assessment to the right owner, tracks completion, and consolidates results into one view. The same workflow scales from a solo practice to a multi-site program with dozens of business associates.
See how Isora GRC supports HIPAA Security Rule compliance →
Key Takeaways
OCR’s HIPAA Security Series is a seven-paper educational guide to the HIPAA Security Rule, useful for both new readers and experienced practitioners as a structured walkthrough of the Rule’s components.
Read each paper directly on the HHS OCR site, and pair it with NIST SP 800-66 Rev. 2 (February 2024) for current implementation guidance.
See the GRC Assessment Platform™ in action →
HIPAA Security Series FAQs
What is the HIPAA Security Series?
The HIPAA Security Series is HHS OCR’s seven-paper educational guidance set on the HIPAA Security Rule, published 2004–2007. The papers cover Security 101, the three safeguard categories, organizational and documentation requirements, risk analysis, and implementation for small providers.
How many papers are in the HIPAA Security Series?
Seven: (1) Security 101 for Covered Entities, (2) Administrative Safeguards, (3) Physical Safeguards, (4) Technical Safeguards, (5) Organizational, Policies and Procedures, and Documentation Requirements, (6) Basics of Risk Analysis and Risk Management, and (7) Implementation for the Small Provider.
Is the HIPAA Security Series still current?
The Series has not been refreshed since 2007 and predates the HITECH Act (2009), the 2013 Omnibus Final Rule, and the 2025 NPRM. The papers remain authoritative for what they describe, but readers should pair them with NIST SP 800-66 Rev. 2 (February 2024) for current implementation guidance.
Where can I download the HIPAA Security Series papers?
The seven papers are available as free PDFs on the HHS OCR website at hhs.gov, under the Security Rule guidance materials. Each paper runs approximately 9 to 16 pages.
Which paper of the HIPAA Security Series should I read first?
Read Paper 1, Security 101 for Covered Entities, first when new to the Rule. For those who own the risk-analysis program, Paper 6, Basics of Risk Analysis and Risk Management, is among the most frequently referenced papers in OCR enforcement.
This content is for informational purposes only and does not constitute legal or compliance advice. See our full disclaimer.