HIPAA Security Rule
The HIPAA Security Rule is a set of United States federal standards that require certain healthcare organizations and their business partners to protect health information kept or shared in electronic form. It calls for safeguards to keep this electronic health data confidential, available, and secure. It applies specifically to electronic protected health information, not to health information held only on paper or spoken.
The HIPAA Security Rule is a binding U.S. federal regulation that establishes a national set of security standards for protecting electronic protected health information (ePHI) that is maintained or transmitted in electronic form. It requires covered entities and business associates to implement administrative, physical, and technical safeguards addressing the confidentiality, integrity, and availability of ePHI, including conducting a security risk assessment. It is distinct from the HIPAA Privacy Rule, which governs a broader set of protected health information across all media rather than the electronic-only scope of the Security Rule. Because the Rule's requirements are addressable and risk-based, their practical application depends on an organization's specific circumstances; readers should verify obligations against the current official text at HHS and apply professional judgment to particular situations.
Why it matters
The HIPAA Security Rule is one of the foundational U.S. federal regulations governing how electronic health information is protected, and it carries legal force rather than being a voluntary framework. For healthcare organizations and their business partners, it establishes the baseline expectation that electronic protected health information (ePHI) will be safeguarded against unauthorized access, alteration, and loss. Because it addresses the confidentiality, integrity, and availability of ePHI specifically, it shapes how covered entities and business associates design their information security programs around electronic data rather than health information in all forms.
The Rule matters because it translates broad privacy expectations into concrete security obligations. It requires organizations to implement administrative, physical, and technical safeguards and to conduct a security risk assessment, meaning compliance is not a one-time exercise but an ongoing, risk-based process tied to each organization's circumstances. Failure to maintain appropriate safeguards can expose organizations to regulatory scrutiny and enforcement, and it can undermine the trust patients place in the systems that hold their health data.
It is important to recognize the boundaries of the Rule's relevance. It governs electronic protected health information and does not extend to health information held only on paper or communicated orally; those are addressed under the broader HIPAA Privacy Rule. Because many of the Rule's requirements are addressable and risk-based, their practical effect varies by organization, and enforcement interpretation continues to develop. Readers should verify current obligations against the official text published by HHS.
Who it's relevant to
Inside HIPAA Security Rule
Common questions
Answers to the questions practitioners most commonly ask about HIPAA Security Rule.

