- HIPAA Security Rule: A Complete Guide to Compliance in 2026
- What is the HIPAA Security Rule?
- What the HIPAA Security Rule Covers
- Who the HIPAA Security Rule Applies to
- HIPAA Security Rule Safeguards
- Administrative Safeguards
- Physical Safeguards
- Technical Safeguards
- How OCR Approaches the HIPAA Security Rule
- What the HIPAA Security Rule Does
- HIPAA, HITECH, and the Privacy Rule
- Common HIPAA Security Rule Compliance Gaps and How to Fix Them
- How to Simplify HIPAA Security Rule Compliance
- Key Takeaways
-
HIPAA Security Rule FAQs
- Which best describes the HIPAA Security Rule?
- Who is responsible for enforcing the HIPAA Security Rule?
- Who is exempt from the HIPAA Security Rule?
- What does the HIPAA Security Rule apply to?
- Does the HIPAA Security Rule focus on protections specifically for ePHI?
- What are the three categories of HIPAA safeguards?
- What is the difference between required and addressable specifications?
- Does the HIPAA Security Rule require encryption?
- What does the HIPAA Security Rule describe how to do?
- What was the HIPAA Security Rule specifically designed to do?
HIPAA Security Rule: A Complete Guide to Compliance in 2026
The HIPAA Security Rule is a federal standard that applies to any organization that creates, receives, maintains, or transmits electronic protected health information (ePHI). To stay compliant, covered entities must put administrative, physical, and technical safeguards in place. The HHS Office for Civil Rights (OCR) enforces those requirements.
In 1996, Congress passed the Health Insurance Portability and Accountability Act (HIPAA) and directed the Department of Health and Human Services (HHS) to develop security standards as healthcare moved to electronic systems. HHS finalized the Security Rule in February 2003, and it remains the primary governing federal standard for electronic health information today.
Most recently, HHS published a Notice of Proposed Rulemaking (NPRM) in January 2025 — the first major proposed overhaul of the Security Rule in over two decades.
This guide explains the HIPAA Security Rule, what it protects, who it applies to, how the safeguard categories work, how HHS OCR frames the Rule’s objectives, how the Security Rule relates to HITECH and the Privacy Rule, and the compliance gaps that drive enforcement.
What is the HIPAA Security Rule?
The HIPAA Security Rule is the national data-protection standard for electronic protected health information (ePHI). Codified at 45 CFR Part 164, Subpart C, it requires covered entities and business associates to secure ePHI across every system that touches it.
What the HIPAA Security Rule Covers
The HIPAA Security Rule covers electronic protected health information (ePHI), the electronic subset of protected health information (PHI) that organizations create, receive, store, maintain, or transmit during operations.
What Is ePHI?
ePHI (electronic protected health information) is personally identifiable health information that’s created, received, stored, maintained, or transmitted electronically by organizations. It includes:
- Electronic medical records.
- Patient portal data.
- Electronic billing records.
- Lab results in an electronic system.
- Emails that contain patient information.
- Patient data stored on laptops, servers, mobile devices, removable media, or cloud platforms.
The HIPAA Administrative Simplification definitions at 45 CFR § 160.103 decide what counts as ePHI. Once information meets that definition, the Security Rule’s safeguards apply to it.
What the Security Rule Does NOT Cover
The HIPAA Security Rule does not cover PHI transmitted orally or on paper. Instead, these types of data fall under the Privacy Rule. The Security Rule also excludes:
- Properly de-identified data under 45 CFR § 164.514 (because it is no longer individually identifiable).
- Education records covered by FERPA.
- Employment records held by an organization in its employer role.
- Health information about a person who has been deceased for more than 50 years (which falls outside the definition of PHI under 45 CFR § 160.103).
What the HIPAA Security Rule Covers vs. Does Not Cover
Because the HIPAA Security Rules only applies to ePHI, it does not cover other types of PHI, including paper, oral, or de-identified health information, employment records, FERPA-covered education records, or health information about an individual who has been deceased for over 50 years.
The following table covers which categories of health information the HIPAA Security Rule protects and why with examples.
| Category | Covered by the HIPAA Security Rule? | Why | Examples |
|---|---|---|---|
| Electronic protected health information (ePHI) | Yes | The Security Rule applies to PHI that is maintained or transmitted electronically. | Electronic health records, patient portal lab results, electronic billing files, emails with patient data, patient data stored on laptops, phones, or cloud systems. |
| Paper PHI | No | Paper PHI is protected under the HIPAA Privacy Rule, but it is outside the Security Rule’s electronic scope. | Printed medical charts, paper intake forms, handwritten treatment notes, mailed test results. |
| Oral PHI | No | Spoken PHI is protected under the Privacy Rule, but the Security Rule applies only when PHI is maintained or transmitted electronically. | Provider-patient conversations, verbal clinical handoffs, unrecorded phone conversations. |
| De-identified health information | No | Properly de-identified information is no longer PHI because it cannot reasonably identify an individual. | De-identified datasets used for research, analytics, benchmarking, or reporting. |
| Employment records | No | These records are created and maintained for employment purposes rather than healthcare delivery or payment, so they are not considered PHI under HIPAA. | Employee sick leave records, workplace medical accommodation files, HR health documentation. |
| FERPA-covered education records | No | Education records covered by FERPA are excluded from HIPAA’s PHI definition. | Student health records maintained by a school or university when FERPA applies. |
| Health information about a person deceased for more than 50 years | No | Health information about a person who has been deceased for more than 50 years falls outside the definition of PHI under 45 CFR § 160.103. | Historical medical records, physician casebooks, archived correspondence, or health-related records about individuals deceased for more than 50 years. |
Who the HIPAA Security Rule Applies to
The HIPAA Security Rule applies to covered entities and their business associates. Both must comply with the Security Rule’s administrative, physical, and technical safeguard requirements when they create, receive, store, maintain, or transmit electronic protected health information.
Covered Entities
Covered entities are the organizations bound directly by the HIPAA Security Rule. Under 45 CFR § 160.103, the HHS defines three types of covered entities:
- Health plans: Insurers, HMOs, employer-sponsored group health plans, and government programs that pay for healthcare.
- Health care clearinghouses: Entities that process nonstandard health information into a standard format for covered transactions.
- Health care providers: Any providers that transmit health information electronically in connection with a HIPAA-covered transaction, including hospitals, physician practices, clinics, pharmacies, and nursing homes.
In addition to HIPAA covered entities, business associates and their subcontractors must also follow the Security Rule’s requirements.
Business Associates
A business associate is any person or entity that performs functions or activities on behalf of a covered entity that involve the use or disclosure of PHI. Common examples include:
- Third-party billing companies.
- Cloud service providers that store ePHI.
- IT contractors with access to ePHI.
- Data hosting providers.
- Medical transcription services.
But business associates weren’t always responsible for protecting ePHI. Originally, the 2003 HIPAA Security Rule applied to covered entities only, mainly addressing business associates via contracts. Then, in 2009, the HITECH Act introduced Security Rule requirements for business associates specifically. Finally, the HHS implemented that change with the Omnibus Final Rule in 2013.
Subcontractors
Subcontractors of business associates are also bound by the HIPAA Security Rule. Today, that chain of liability links to every service-provider relationship touching ePHI.
| Dimension | Covered Entity | Business Associate |
|---|---|---|
| Definition | Health plan, healthcare clearinghouse, or provider that transmits health information electronically | Person or entity that performs functions for a covered entity involving PHI |
| Direct Security Rule compliance | Yes | Yes, since HITECH and the 2013 Omnibus Rule |
| BAA required | Not applicable | Must sign a Business Associate Agreement with each covered entity |
| Examples | Hospitals, insurers, billing clearinghouses, providers | Cloud storage vendors, billing services, IT contractors, transcription services |
HIPAA Security Rule Safeguards
The HIPAA Security Rule organizes its requirements into administrative, physical, and technical safeguards. Each category contains a set of standards, and each standard provides implementation specifications that are either required or addressable.
All three categories of HIPAA Security Rule Safeguards fall under the general requirements at 45 CFR § 164.306(a). More specifically, it requires regulated entities to:
- Protect the confidentiality, integrity, and availability of ePHI.
- Defend against reasonably anticipated threats.
- Prevent impermissible uses or disclosures.
- Confirm workforce compliance
In return, each Security Rule safeguard divides that work by what it protects.
- Administrative safeguards cover the policies, procedures, and workforce actions that govern how an organization selects, develops, implements, and maintains security measures.
- Physical safeguards cover the measures that protect electronic systems, equipment, and facilities from unauthorized access, service disruption, and environmental hazards.
- Technical safeguards cover the technology and policies that protect ePHI and control access to it.
Implementing HIPAA Safeguards
Every implementation specification under the Rule is designated as either required or addressable, defined under 45 CFR § 164.306(d).
- Required specifications must be implemented as written.
- Addressable specifications give an organization room to assess whether a measure is reasonable and appropriate, then implement it, adopt a documented equivalent, or document why it does not apply. Addressable does not mean optional.
Risk analysis drives every other safeguard decision under 164.308. Published in February 2024, NIST SP 800-66 Rev. 2 gives regulated entities practical guidance for meeting each standard and reinforces the Security Rule’s flexible, risk-based approach.
Administrative Safeguards
Administrative safeguards are the policies, procedures, and workforce-management actions that govern how a covered entity or business associate selects, develops, implements, and maintains security measures to protect ePHI.
The standards under 45 CFR §164.308 form the foundation of a defensible HIPAA compliance program. But they also represent the largest category by control count.
| Standard | Role | Implementation specifications | Required or addressable |
|---|---|---|---|
| Security Management Process 164.308(a)(1) | Establishes the foundation for preventing, detecting, containing, and correcting security violations. Risk analysis is the linchpin of HIPAA Security Rule compliance. | (A) Risk analysis (B) Risk management (C) Sanction policy (D) Information system activity review |
All four required |
| Assigned Security Responsibility 164.308(a)(2) | Requires the organization to designate a HIPAA Security Officer responsible for developing and implementing Security Rule policies and procedures. | None | Standard must be met |
| Workforce Security 164.308(a)(3) | Confirms workforce members have appropriate access to ePHI and prevents unauthorized access. | (A) Authorization and/or supervision (B) Workforce clearance procedure (C) Termination procedures |
All three addressable |
| Information Access Management 164.308(a)(4) | Governs how access to ePHI is authorized, established, modified, and limited based on role and need. | (A) Isolating health care clearinghouse functions (B) Access authorization (C) Access establishment and modification |
Isolating clearinghouse required, the other two addressable |
| Security Awareness and Training 164.308(a)(5) | Requires a security awareness and training program for all workforce members, including management. | (A) Security reminders (B) Protection from malicious software (C) Log-in monitoring (D) Password management |
All four addressable |
| Security Incident Procedures 164.308(a)(6) | Establishes procedures to identify, respond to, document, and report suspected or known security incidents. | (A) Response and reporting | Required |
| Contingency Plan 164.308(a)(7) | Requires procedures for responding to emergencies or other events that damage systems containing ePHI. | (A) Data backup plan (B) Disaster recovery plan (C) Emergency mode operation plan (D) Testing and revision procedures (E) Applications and data criticality |
First three required, last two addressable |
| Evaluation 164.308(a)(8) | Requires periodic technical and non-technical evaluations of how well the organization’s security policies and procedures meet Security Rule requirements. | None | Standard must be met |
| Business Associate Contracts 164.308(b)(1) | Requires covered entities to obtain satisfactory assurances that business associates will appropriately safeguard ePHI before allowing them to create, receive, maintain, or transmit it. | Written contract or other arrangement | Required |
The Security Management Process risk analysis specification (164.308(a)(1)(ii)(A)) drives every downstream safeguard decision. But it also ranks among the most cited controls in enforcement actions.
In 2024, the HHS OCR launched a dedicated Risk Analysis Initiative, which found that a missing or inadequate risk analysis has driven more than a dozen enforcement settlements since. Today, HHS considers it the linchpin of HIPAA compliance.
To show organizations what a compliant analysis looks like, OCR published its Final Guidance on Risk Analysis Requirements. It lays out the elements every analysis must include and applies them to all ePHI, in every form of electronic media.
Or, for the step-by-step process, see our HIPAA risk assessment guide.
Physical Safeguards
Physical safeguards are the physical measures, policies, and procedures that protect ePHI from unauthorized physical access, theft, and environmental hazards, and support the availability of the systems that store and transmit ePHI. From data-center access to laptop and media handling, 45 CFR § 164.310 ties ePHI protection to the real-world places and devices where data lives.
| Standard | Role | Implementation specifications | Required or addressable |
|---|---|---|---|
| Facility Access Controls 164.310(a)(1) | Limits physical access to electronic information systems and the facilities that house them, while allowing authorized access. | (A) Contingency operations (B) Facility security plan (C) Access control and validation procedures (D) Maintenance records |
Addressable |
| Workstation Use 164.310(b) | Specifies the proper functions, manner of use, and physical surroundings for workstations that access ePHI. | None | Required |
| Workstation Security 164.310(c) | Restricts physical access to workstations that access ePHI to authorized users. | None | Required |
| Device and Media Controls 164.310(d)(1) | Governs the receipt, removal, movement, reuse, disposal, and backup of hardware and electronic media that contain ePHI. | (A) Disposal (B) Media re-use (C) Accountability (D) Data backup and storage |
Disposal and media re-use are required; accountability and backup/storage are addressable |
Physical safeguards close a gap that technical controls alone leave open. Even strong system controls can’t protect ePHI when a facility sits unlocked, a workstation stays open to anyone walking by, a laptop leaves the building unsecured, or old storage drives get reused without being wiped first.
Technical Safeguards
Technical safeguards are the technology-based controls that protect ePHI and govern who can access it. Under 45 CFR § 164.312, this category of safeguard covers access control, audit controls, integrity, person or entity authentication, and transmission security.
| Standard | Role | Implementation specifications | Required or addressable |
|---|---|---|---|
| Access Control 164.312(a)(1) | Limits access to electronic information systems that maintain ePHI to authorized persons or software programs. | (i) Unique user identification (ii) Emergency access procedure (iii) Automatic logoff (iv) Encryption and decryption |
First two required, last two addressable |
| Audit Controls 164.312(b) | Requires mechanisms that record and examine activity in information systems that contain or use ePHI. | None | Standard must be met |
| Integrity 164.312(c)(1) | Protects ePHI from improper alteration or destruction. | (i) Mechanism to authenticate ePHI | Addressable |
| Person or Entity Authentication 164.312(d) | Verifies that a person or entity seeking access to ePHI is the one claimed. | None | Standard must be met |
| Transmission Security 164.312(e)(1) | Guards against unauthorized access to ePHI while it is transmitted over an electronic communications network. | (i) Integrity controls (ii) Encryption |
Both addressable |
For organizations implementing these safeguards, a few points matter. More specifically:
- Audit controls log everything. Audit controls (164.312(b)) require covered organizations to put hardware, software, and procedures in place that record and examine activity in systems containing ePHI.
- Encryption is addressable. Encryption is an addressable specification under 164.312(a)(2)(iv) and 164.312(e)(2)(ii), with added weight under the Breach Notification Rule. Because encrypted ePHI counts as not unsecured, encryption is a practical safe harbor for breach notification. HHS points to NIST SP 800-111 for storage encryption and NIST SP 800-52 Rev. 2 for data in transit. Importantly, most enforcement actions treat unencrypted ePHI on a lost or stolen device as a factor that increases the penalty.
- No specific password policy. There is no specific password requirement under the HIPAA Security Rule. Instead, NIST SP 800-66 Rev. 2 points to NIST SP 800-63B for current authentication guidance, which is where most organizations start.
- Hardened-server baseline. HIPAA requires a hardened-server setup built on least privilege, audit logging, integrity controls, and authenticated access — a baseline described by OCR in its January 2026 cybersecurity newsletter on system hardening.
How OCR Approaches the HIPAA Security Rule
OCR frames the Security Rule as flexible, scalable, and technology neutral. Rather than prescribing specific controls or technologies, the Rule sets standards for regulated entities that range widely in size, organizational structure, and risk profile.
For example, although HIPAA might apply to both a large hospital system and a small medical transcription service, the specific measures each implements will differ based on their individual risk analysis.
Put simply, 45 CFR § 164.306(a) sets the general requirements that all regulated entities must meet, and OCR uses those requirements as the baseline for evaluating compliance.
OCR’s Official Compliance Resources
The OCR publishes its own summary of the Security Rule on hhs.gov, framing the Rule around four general requirements. Alongside this summary of the Security Rule, the agency maintains the seven-part HIPAA Security Series, a set of educational papers covering administrative, physical, and technical safeguards, risk analysis, and the security standards matrix. OCR also points regulated entities to NIST resources, the HHS Security Risk Assessment Tool, and quarterly cybersecurity newsletters for ongoing implementation support.
How OCR Enforces the Rule
OCR also administers and enforces the rule, a responsibility that moved from the Centers for Medicare & Medicaid Services to OCR in July 2009. It investigates complaints, conducts compliance reviews, and may impose civil monetary penalties for violations. The Department of Justice handles criminal violations of HIPAA.
What the HIPAA Security Rule Does
The HIPAA Security Rule was designed to set a national, technology-neutral standard for protecting PHI as healthcare moved to electronic systems. In 2003, HHS finalized the rule to establish a consistent level of protection for electronic health information across federal and private health programs. Today, that design shows up in a risk-based framework that protects ePHI while leaving room for new technology.
Protect Electronic Health Information
The rule’s objectives come straight from 45 CFR § 164.306(a). Regulated entities must keep all ePHI confidential, intact, and available. They must guard against threats they can reasonably see coming. They must prevent uses or disclosures the rule does not allow. They must confirm their workforce follows the rule.
Enable Secure ePHI Exchange
The broader purpose of the HIPAA Security Rule is to let organizations exchange ePHI securely without forcing them to use specific technologies. Because healthcare spans organizations of different sizes, resources, and technical maturity, the Rule stays flexible and scalable.
However, security is an ongoing obligation, not a one-time task. As technology and threats change, regulated entities must identify risks, apply safeguards, document decisions, and update those measures accordingly.
HIPAA, HITECH, and the Privacy Rule
The Security Rule is one of three operational rules under HIPAA, alongside the Privacy Rule and the Breach Notification Rule. However, each rule answers a different compliance question.
- The Privacy Rule governs when PHI may be used or disclosed.
- The Security Rule governs how ePHI must be protected.
- The Breach Notification Rule governs what happens after unsecured PHI is compromised.
| Rule | CFR citation | Scope | Key requirement |
|---|---|---|---|
| Privacy Rule | 45 CFR Part 164 Subpart E | All PHI, electronic, oral, and paper | Use and disclosure standards plus patient rights |
| Security Rule | 45 CFR Part 164 Subpart C | ePHI only | Administrative, physical, and technical safeguards |
| Breach Notification Rule | 45 CFR Part 164 Subpart D | Unsecured PHI | Notification to individuals, HHS, and media |
The HITECH Act, enacted in 2009 as part of the American Recovery and Reinvestment Act, strengthened HIPAA’s security framework. It extended key Security Rule requirements directly to business associates, created the breach-notification framework for unsecured PHI, raised civil monetary penalty tiers, and gave OCR stronger enforcement tools.
HHS implemented many HITECH changes through the 2013 Omnibus Final Rule, which modified the Privacy, Security, Enforcement, and Breach Notification Rules and made business associates directly liable.
The 2025 Federal Register NPRM (90 FR 898) proposes a modernization of this framework rather than a replacement, with proposed changes to encryption, multi-factor authentication, asset inventories, and vulnerability scanning. The HHS fact sheet lays out each proposed change in plain language.
Cross-Framework Connections
The HIPAA Security Rule maps to other data-protection frameworks that organizations follow alongside it. Its safeguards parallel the GLBA Safeguards Rule for organizations regulated under both healthcare and financial services laws.
Common HIPAA Security Rule Compliance Gaps and How to Fix Them
Most HIPAA Security Rule enforcement actions trace back to a small set of recurring gaps, and each has a defined fix path under the rule itself. OCR’s resolution agreements and the HHS Breach Portal point to weaknesses in risk analysis, access governance, documentation, vendor oversight, and monitoring as the most common causes.
Gap 1: Missing or stale risk analysis.
Risk analysis is the most cited control in OCR enforcement, and the 2025 Risk Analysis Initiative produced multiple settlements in the first half of the year.
Fix: Conduct and document a current risk analysis covering all systems that touch ePHI, following OCR’s Final Guidance on Risk Analysis Requirements. See our HIPAA risk assessment guide for the step-by-step process.
Gap 2: Unencrypted ePHI on portable devices.
Lost and stolen laptops, USB drives, and mobile devices remain a top breach cause in the HHS OCR breach portal. Unencrypted ePHI on a lost device triggers full breach notification obligations.
Fix: Implement at-rest encryption per NIST SP 800-111 under 164.312(a)(2)(iv). Encrypted devices qualify for the Breach Notification Rule’s safe harbor.
Gap 3: Insufficient business associate oversight.
A signed BAA with no monitoring, no security questionnaire, and no audit cadence leaves ePHI exposed.
Fix: Maintain a current BA inventory, run annual security assessments, and document a remediation cadence for findings.
Gap 4: Inadequate audit controls.
Section 164.312(b) requires logging activity in systems containing ePHI, but many programs lack log review procedures or retention policies.
Fix: Document log content, retention, and review cadence. Align to NIST SP 800-92 guidance on log management.
Gap 5: Workforce training gaps.
Generic annual training that skips ePHI-specific scenarios and security reminders under 164.308(a)(5)(ii)(A) leaves staff unprepared.
Fix: Implement role-based training with documented completion records and distribute security reminders at defined intervals.
Organizations that run multiple compliance programs often reduce audit burden by mapping HIPAA controls to the NIST Cybersecurity Framework. The HIPAA Security Rule Crosswalk Toolkit provides that mapping in a usable PDF.
How to Simplify HIPAA Security Rule Compliance
The gaps above share a root cause: risk analyses, business associate reviews, and audit-control evidence scattered across spreadsheets and email threads that are hard to keep current and defensible. Isora GRC is the collaborative GRC Assessment Platform™ that gives security teams one connected workspace to close those gaps and run the assessments, risk tracking, and reporting the Security Rule calls for.
- Assessment Management. Track the status of every HIPAA and business associate assessment across the organization in one view — the standing vendor-oversight cadence that closes the business associate gap, without chasing updates by email.
- Questionnaires & Surveys. Prebuilt, framework-aligned questionnaires cover the administrative, physical, and technical safeguards, so non-technical respondents can complete the risk analysis and workforce-training reviews without dedicated training.
- Risk Management. Assessment findings flow into a connected risk register with full lineage, producing the documented, current risk analysis OCR expects and the audit trail that closes the logging gap.
Download the HIPAA Security Rule Crosswalk Toolkit for a free control mapping, or see how the platform fits a healthcare program on the HIPAA Security Rule compliance software page.
Key Takeaways
The HIPAA Security Rule requires covered entities and business associates to protect ePHI through administrative, physical, and technical safeguards, anchored in a documented risk analysis and reinforced by audit controls, encryption, and ongoing workforce training.
Understanding the categorical structure of the rule gives any healthcare security team, billing vendor, or higher-education health center the foundation for a defensible 2026 compliance program. The right next step depends on the program, whether that means a risk assessment, an audit, a safeguards review, business associate oversight, or a NIST CSF crosswalk.
Download the HIPAA Security Rule Crosswalk Toolkit for a free PDF that maps every Security Rule control to NIST CSF and 800-53.
See how Isora GRC can support your HIPAA program →
HIPAA Security Rule FAQs
Which best describes the HIPAA Security Rule?
The HIPAA Security Rule is the federal regulation at 45 CFR Part 164 Subpart C that requires covered entities and business associates to protect electronic protected health information through administrative, physical, and technical safeguards. It sets a national, technology-neutral standard rather than prescribing specific technologies.
Who is responsible for enforcing the HIPAA Security Rule?
The HHS Office for Civil Rights enforces the HIPAA Security Rule. OCR investigates complaints, conducts compliance reviews, and may impose civil monetary penalties. The Department of Justice handles criminal violations of HIPAA.
Who is exempt from the HIPAA Security Rule?
Organizations that are not covered entities, business associates, or subcontractors handling ePHI in a HIPAA-covered relationship sit outside the rule. That group includes many direct-to-consumer health apps, life and disability insurers, employers acting only as employers, and FERPA-covered schools. Exemption depends entirely on whether ePHI moves through a covered relationship.
What does the HIPAA Security Rule apply to?
The HIPAA Security Rule applies to electronic protected health information that covered entities and business associates create, receive, maintain, or transmit. It does not apply to PHI in oral or paper form, which the Privacy Rule governs.
Does the HIPAA Security Rule focus on protections specifically for ePHI?
Yes. The HIPAA Security Rule focuses on ePHI, the electronic subset of protected health information. The Privacy Rule covers all forms of PHI, and the Security Rule covers the electronic subset.
What are the three categories of HIPAA safeguards?
The three categories of HIPAA safeguards are administrative (164.308), physical (164.310), and technical (164.312). Administrative safeguards cover policies and workforce, physical safeguards cover facility and device security, and technical safeguards cover the technology that protects ePHI.
What is the difference between required and addressable specifications?
Required specifications must be implemented as written. Addressable specifications must be assessed, and the organization must implement them, adopt a documented equivalent, or document why implementation is not reasonable and appropriate. Addressable does not mean optional.
Does the HIPAA Security Rule require encryption?
The HIPAA Security Rule treats encryption as an addressable specification under 164.312(a)(2)(iv) and 164.312(e)(2)(ii). HHS Breach Notification guidance treats encrypted ePHI as not unsecured, which makes encryption a practical safe harbor for breach notification.
What does the HIPAA Security Rule describe how to do?
The HIPAA Security Rule describes how to apply administrative, physical, and technical safeguards to protect ePHI. That work includes conducting a risk analysis, designating a Security Officer, controlling access to systems, logging and reviewing activity, and responding to security incidents.
What was the HIPAA Security Rule specifically designed to do?
The HIPAA Security Rule was designed to protect the confidentiality, integrity, and availability of all ePHI, protect against reasonably anticipated threats, protect against impermissible uses or disclosures, and confirm workforce compliance. It does this work while staying flexible, scalable, and technology-neutral.
This content is for informational purposes only and does not constitute legal or compliance advice. See our full disclaimer.