Skip to main content
Promotional banner for the pentest readiness checklist
Category: Regulations & Laws

HIPAA Security Rule

Also known as: Security Rule, HIPAA Security Standards
Simply put

The HIPAA Security Rule is a set of United States federal standards that require certain healthcare organizations and their business partners to protect health information kept or shared in electronic form. It calls for safeguards to keep this electronic health data confidential, available, and secure. It applies specifically to electronic protected health information, not to health information held only on paper or spoken.

Formal definition

The HIPAA Security Rule is a binding U.S. federal regulation that establishes a national set of security standards for protecting electronic protected health information (ePHI) that is maintained or transmitted in electronic form. It requires covered entities and business associates to implement administrative, physical, and technical safeguards addressing the confidentiality, integrity, and availability of ePHI, including conducting a security risk assessment. It is distinct from the HIPAA Privacy Rule, which governs a broader set of protected health information across all media rather than the electronic-only scope of the Security Rule. Because the Rule's requirements are addressable and risk-based, their practical application depends on an organization's specific circumstances; readers should verify obligations against the current official text at HHS and apply professional judgment to particular situations.

Why it matters

The HIPAA Security Rule is one of the foundational U.S. federal regulations governing how electronic health information is protected, and it carries legal force rather than being a voluntary framework. For healthcare organizations and their business partners, it establishes the baseline expectation that electronic protected health information (ePHI) will be safeguarded against unauthorized access, alteration, and loss. Because it addresses the confidentiality, integrity, and availability of ePHI specifically, it shapes how covered entities and business associates design their information security programs around electronic data rather than health information in all forms.

The Rule matters because it translates broad privacy expectations into concrete security obligations. It requires organizations to implement administrative, physical, and technical safeguards and to conduct a security risk assessment, meaning compliance is not a one-time exercise but an ongoing, risk-based process tied to each organization's circumstances. Failure to maintain appropriate safeguards can expose organizations to regulatory scrutiny and enforcement, and it can undermine the trust patients place in the systems that hold their health data.

It is important to recognize the boundaries of the Rule's relevance. It governs electronic protected health information and does not extend to health information held only on paper or communicated orally; those are addressed under the broader HIPAA Privacy Rule. Because many of the Rule's requirements are addressable and risk-based, their practical effect varies by organization, and enforcement interpretation continues to develop. Readers should verify current obligations against the official text published by HHS.

Who it's relevant to

Covered Entities
Healthcare providers, health plans, and healthcare clearinghouses that maintain or transmit ePHI are directly subject to the Security Rule. They must implement administrative, physical, and technical safeguards and conduct a security risk assessment appropriate to their circumstances.
Business Associates
Organizations that handle ePHI on behalf of covered entities are also subject to the Rule. The Security Rule applies to both covered entities and business associates, so vendors and service providers processing electronic health data must maintain their own safeguards.
Information Security Professionals
Security teams within healthcare organizations rely on the Rule to frame their programs around the confidentiality, integrity, and availability of ePHI, translating its safeguard categories into concrete controls suited to organizational risk.
Compliance Officers and Auditors
Those responsible for HIPAA compliance use the Rule's risk-based, addressable requirements as the benchmark for evaluating whether safeguards and risk assessments are in place and documented. Because requirements are fact-specific, they should assess application against the current HHS text.
Healthcare Providers Conducting Risk Assessments
Providers performing the required security risk assessment are a specific audience the Rule addresses. Resources such as the HealthIT.gov security risk assessment tool are aimed at helping them meet this obligation.

Inside HIPAA Security Rule

Scope: Electronic Protected Health Information (ePHI)
The Security Rule applies specifically to protected health information that is created, received, maintained, or transmitted in electronic form. It does not govern PHI held only in paper or oral form, which falls under other provisions of the broader HIPAA regulatory scheme. Readers should note this scope distinction when mapping controls.
Administrative Safeguards
Policies, procedures, and workforce-facing measures intended to manage the selection, development, implementation, and maintenance of security measures. These generally address matters such as assigned security responsibility, workforce training, and risk management processes, though the specific implementation depends on the organization's circumstances.
Physical Safeguards
Measures addressing the physical protection of electronic systems, equipment, and the facilities in which they are housed against unauthorized access and environmental hazards. The Rule generally expects controls over facility access and device and media handling, scaled to the entity.
Technical Safeguards
Technology-based controls governing access to ePHI and protection of that data in systems and during transmission. These commonly involve access control, audit capability, and integrity and transmission protections. The Rule is generally technology-neutral rather than prescribing specific products.
Required versus Addressable Implementation Specifications
The Rule distinguishes 'required' specifications, which must be implemented, from 'addressable' specifications, where a covered entity or business associate assesses whether the specification is reasonable and appropriate and, if not, documents the rationale and any alternative measures. 'Addressable' does not mean optional.
Covered Entities and Business Associates
The Rule applies to covered entities (such as certain health plans, clearinghouses, and providers) and, through statutory and contractual mechanisms, to business associates that handle ePHI on their behalf. The precise classification of a given organization is fact-specific and should be verified.
Risk Analysis and Flexibility of Approach
The Rule contemplates a flexible, scalable approach in which security measures are informed by an assessment of risks to ePHI, taking into account factors such as the entity's size, complexity, and capabilities. It does not mandate a single uniform set of controls for all organizations.

Common questions

Answers to the questions practitioners most commonly ask about HIPAA Security Rule.

Does the HIPAA Security Rule apply to all personal health information a company holds?
No. The Security Rule applies specifically to electronic protected health information (ePHI) created, received, maintained, or transmitted by covered entities and their business associates, as those terms are defined under HIPAA. It does not govern all health-related data in every context. Information held by entities that are not covered entities or business associates, or health data outside the scope of HIPAA (for example, certain data collected by consumer wellness apps or employers acting as employers), generally falls outside the Rule. It also does not cover PHI in non-electronic form, which is addressed by other HIPAA provisions. Application to a particular data set is fact-specific and should be verified against the current regulatory text and professional judgment.
Is the HIPAA Security Rule the same thing as the HIPAA Privacy Rule?
No. They are distinct components of the HIPAA regulatory framework that address different concerns. The Security Rule focuses on safeguarding electronic protected health information through administrative, physical, and technical safeguards—essentially the security dimension. The Privacy Rule governs the permitted uses and disclosures of protected health information more broadly, including in non-electronic forms, and addresses individuals' rights over their information. Security and privacy are related but separate concepts: security concerns how information is protected, while privacy concerns how it may be used and shared. Compliance with one does not by itself establish compliance with the other; both apply where relevant. Readers should consult the current official text for the precise scope of each.
How does the HIPAA Security Rule's distinction between 'required' and 'addressable' safeguards affect implementation?
The Security Rule generally organizes its safeguards into implementation specifications that are designated as either 'required' or 'addressable.' Required specifications must be implemented as stated. Addressable specifications are not optional in the sense of being ignorable; rather, a regulated entity generally must assess whether a given specification is reasonable and appropriate for its environment, and either implement it, implement an equivalent alternative measure, or document why it is not reasonable and appropriate. This structure is intended to allow flexibility based on an organization's size, complexity, and risk profile. Because interpretations and enforcement expectations can evolve, entities should verify current guidance and document their decision-making. This is informational and not a substitute for professional judgment applied to specific facts.
What role does risk analysis play in Security Rule compliance?
Risk analysis is generally treated as a foundational element of the Security Rule's administrative safeguards. In most cases, a regulated entity is expected to conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of the ePHI it holds, and to implement measures to reduce those risks to a reasonable and appropriate level. This process is generally expected to be ongoing rather than a one-time exercise, given changes in systems, threats, and operations. The specific methodology is not rigidly prescribed, allowing scalability. Entities should confirm current expectations against authoritative sources, as enforcement practice can diverge from a literal reading of the text.
Do business associates have their own obligations under the Security Rule, or only the covered entity?
Business associates generally have direct obligations under the Security Rule with respect to ePHI they handle on behalf of covered entities, in addition to obligations arising from their contractual business associate agreements. This means a business associate can, in many cases, be directly subject to the Rule's safeguard requirements rather than being covered only indirectly through the covered entity. The precise scope of these direct obligations and how they interact with contractual terms is fact-specific. Entities in either role should verify their responsibilities against the current regulatory text and, where appropriate, obtain professional advice on their particular arrangements.
How should an organization document its Security Rule compliance efforts?
The Security Rule generally includes documentation requirements, and maintaining records of policies, procedures, risk analyses, and the rationale for decisions—such as how addressable specifications were handled—is typically important for demonstrating compliance. Documentation supports both internal governance and any external review, since it can evidence that reasonable and appropriate measures were considered and implemented. Note that compliance is a state of meeting regulatory obligations and is distinct from any external certification; the Security Rule does not establish a government certification scheme. Retention periods and specific documentation practices should be verified against the current official text, and application to a particular organization requires professional judgment.

Common misconceptions

The HIPAA Security Rule governs all protected health information, regardless of format.
The Security Rule applies to protected health information in electronic form (ePHI). PHI in paper or oral form is addressed by other parts of the HIPAA framework rather than by the Security Rule. Practitioners should keep the Privacy Rule and the Security Rule distinct.
'Addressable' implementation specifications are optional and can simply be skipped.
'Addressable' means an organization must assess whether the specification is reasonable and appropriate for its environment. If it is not, the organization is generally expected to document that determination and implement a reasonable alternative where appropriate. It is not a license to ignore the specification.
HIPAA is a voluntary framework or a certification an organization can obtain.
The HIPAA Security Rule is binding U.S. federal regulation applicable to covered entities and business associates, not a voluntary standard or certification scheme. There is no official government-issued HIPAA 'certification'; demonstrating compliance is an ongoing obligation rather than a one-time credential.

Best practices

Conduct and periodically update a documented risk analysis of ePHI, treating it as the foundation on which administrative, physical, and technical safeguard decisions are justified.
For every addressable implementation specification, record the reasonableness-and-appropriateness assessment and either the implementation or the rationale and alternative measure adopted, so decisions are defensible.
Maintain clear separation between Privacy Rule obligations (which reach PHI broadly) and Security Rule obligations (which target ePHI), and confirm each in-scope system is mapped to the correct requirement set.
Verify the organization's status as a covered entity or business associate, and ensure business associate arrangements are addressed contractually before ePHI is shared.
Scale safeguards to the organization's size, complexity, and capabilities rather than adopting a fixed checklist, while documenting the reasoning behind the chosen controls.
Review the current authoritative text and applicable HHS guidance periodically, since regulatory interpretation and enforcement practice evolve; treat this entry as informational and seek professional judgment for specific situations.
Promotional banner highlighting failures found in PCI audits and how to spot the gaps