Get HIPAA Audit →

HIPAA Security Rule Explained: Administrative, Physical & Technical Safeguards

Quick Answer

The HIPAA Security Rule requires covered entities to implement three categories of safeguards to protect electronic protected health information (ePHI): Administrative Safeguards (policies, training, security management), Physical Safeguards (facility access, workstation control), and Technical Safeguards (encryption, access controls, audit logs). Safeguards are classified as either "Required" (mandatory) or "Addressable" (you must assess and document your approach). Non-compliance can result in penalties of $100-$1,500,000 per violation.

Overview of the HIPAA Security Rule

The HIPAA Security Rule (45 CFR Parts 160 and 164, Subpart C) is a federal regulation that sets national standards for protecting electronic protected health information (ePHI). Unlike the Privacy Rule which addresses all PHI in any form, the Security Rule specifically applies to ePHI—protected health information that's created, stored, transmitted, or received in electronic format.

The Security Rule applies to all covered entities (healthcare providers, health plans, healthcare clearinghouses) and their business associates. It mandates that organizations implement reasonable and appropriate safeguards to protect ePHI from unauthorized access, alteration, deletion, and transmission.

The regulation is structured around three main categories of safeguards, each containing specific standards and implementation specifications that may be required or addressable.

Administrative Safeguards

Administrative safeguards are policies, procedures, and processes that establish your organization's framework for protecting ePHI. These form the foundation of your HIPAA compliance program.

Security Management Process
REQUIRED

Implement a comprehensive security management process that includes conducting a risk analysis, implementing risk mitigation strategies, monitoring security effectiveness, and periodically evaluating the process. This is the cornerstone of the Security Rule—you must analyze threats and vulnerabilities to your ePHI and implement appropriate controls.

Assigned Security Responsibility
REQUIRED

Designate a Security Officer responsible for developing and implementing your security policies and procedures. This person (or role) coordinates your organization's HIPAA compliance efforts and serves as the primary contact for security matters.

Workforce Security
REQUIRED

Implement procedures to ensure that authorized workforce members have access to ePHI appropriate to their role, and that access is terminated when employment ends. This includes authorization procedures (granting access), supervision (monitoring appropriate use), and termination procedures (revoking access).

Workforce Training and Education
REQUIRED

Conduct initial HIPAA training for all workforce members with access to ePHI, and provide annual refresher training. Training must cover your security policies and procedures, how to handle ePHI securely, breach notification procedures, and the consequences of HIPAA violations. Document training completion.

Access Management
REQUIRED

Establish procedures to ensure workforce members have appropriate access to ePHI based on their role. This includes role-based access controls, least privilege principles, and emergency access procedures. Addressable implementation specifications include isolating health care clearinghouse functions and system audit logs.

Security Awareness and Training
REQUIRED

Implement programs to address security awareness and training beyond initial HIPAA education. This includes protection from malware, log-in monitoring, password management, and reporting of security incidents.

Security Incident Procedures
REQUIRED

Establish procedures for identifying, logging, and responding to suspected or confirmed security incidents. Every incident must be documented, investigated, and corrective actions must be implemented to prevent recurrence.

Contingency Planning
REQUIRED

Develop plans for responding to emergencies and disasters that affect your systems. This includes data backup procedures, disaster recovery plans, and emergency mode operations. Test your contingency plan regularly.

Business Associate Contracts and Other Arrangements
REQUIRED

Establish and maintain Business Associate Agreements with all entities that access, use, or handle ePHI on your behalf. These agreements must contractually require compliance with applicable HIPAA security standards.

Physical Safeguards

Physical safeguards protect the physical infrastructure containing your ePHI—the buildings, equipment, and media where data is stored or processed.

Facility Access Controls
REQUIRED

Implement procedures and controls that limit physical access to facilities and equipment where ePHI is processed or stored. Required implementation specifications include visitor log procedures, facility security plans, and procedures for securing entry to facilities. Addressable specifications include video surveillance and motion sensors.

Workstation Use
REQUIRED

Establish policies and procedures governing the use of workstations (computers, monitors, keyboards, other equipment) that can access ePHI. Specify which employees can use which workstations, how they should be configured, and what activities are permitted.

Workstation Security
REQUIRED

Implement physical safeguards for workstations to prevent unauthorized access. This includes locking computer screens when unattended, positioning monitors so they can't be viewed from unauthorized locations, and preventing removal of storage devices containing ePHI.

Device and Media Controls
REQUIRED

Establish procedures for properly managing devices and media that contain ePHI. Required specifications include inventory management (knowing what devices contain ePHI), access controls (limiting access to devices), security testing (verifying devices are secure), and disposition procedures (securely destroying devices when they reach end of life).

Technical Safeguards

Technical safeguards are technology-based measures that protect ePHI in electronic systems and networks.

Access Controls
REQUIRED

Implement technical safeguards to control access to ePHI. Required implementation specifications include unique user identification (every person has a unique login), emergency access procedures (processes for accessing ePHI during emergencies when normal access isn't available), and encryption and decryption mechanisms for ePHI at rest and in transit.

Audit Controls
REQUIRED

Implement hardware, software, and procedural mechanisms to audit and examine access and activity related to ePHI. You must maintain audit logs that record who accessed which ePHI, when they accessed it, and what actions they performed. These logs are essential for detecting unauthorized access and investigating suspected breaches.

Integrity Controls
REQUIRED

Protect ePHI from improper alteration or destruction. This includes mechanisms to verify that ePHI has not been altered in unauthorized ways. Digital signatures, checksums, and write-once storage are examples of integrity controls.

Transmission Security
REQUIRED

Implement safeguards to protect ePHI during transmission over electronic networks. This includes encryption of ePHI before transmission, secure communication protocols (HTTPS, TLS, VPN), and procedures for securely transmitting ePHI between systems.

Required vs. Addressable Implementation Specifications

A critical distinction in the Security Rule is between "Required" and "Addressable" implementation specifications:

Required Implementation Specifications

These specifications must be implemented by all covered entities. There's no flexibility—you must adopt these specific safeguards or demonstrate why they're technically infeasible in your environment. Examples include unique user identification, emergency access procedures, audit logs, and workforce security procedures.

Addressable Implementation Specifications

These specifications provide flexibility. You must assess whether they're reasonable and appropriate for your organization, implement them if appropriate, or if you determine they're not necessary, document your decision and the risk mitigation you've implemented instead. For example, encryption might be addressable for certain data, but you might implement physical controls instead if encryption isn't technically feasible.

When OCR reviews your implementation of addressable specifications, they look for documented decision-making. If you elected not to implement a safeguard, you must document: (1) why you considered it, (2) why you determined it wasn't appropriate, and (3) what alternative safeguards you implemented to address the security risk it would have mitigated.

Common Security Rule Violations

The Office for Civil Rights frequently cites these violations:

Getting Started with Security Rule Compliance

If you haven't fully implemented the Security Rule, the recommended approach is:

  1. Conduct a comprehensive risk analysis evaluating your systems and processes
  2. Develop written policies and procedures covering all required safeguards
  3. Implement technical controls (encryption, access controls, audit logs)
  4. Establish administrative procedures (training, incident response, access management)
  5. Document your decisions, especially regarding addressable specifications
  6. Implement ongoing monitoring and periodic assessments
  7. Train your workforce on security policies and procedures

Frequently Asked Questions

Is encryption always required for ePHI?
Encryption for ePHI at rest and in transit is a required implementation specification under access controls. However, the regulation recognizes that some situations may make encryption infeasible, in which case you must document this and implement alternative safeguards to achieve the same level of protection.
What's the difference between the Security Rule and the Privacy Rule?
The Privacy Rule addresses all PHI in any form and focuses on when information can be used and disclosed. The Security Rule specifically addresses ePHI and focuses on technical, physical, and administrative safeguards to protect it.
How often should I conduct a risk analysis?
HIPAA requires conducting a risk analysis initially and then periodically thereafter to identify new threats and vulnerabilities. Best practice is annually, but you should also conduct one whenever you make significant system changes or implement new technologies that access ePHI.
Who needs to receive HIPAA security training?
All workforce members with any access to ePHI must receive training. This includes clinical staff, administrative staff, IT personnel, and anyone else who touches systems containing health information.
What should my contingency plan include?
Your contingency plan should include data backup procedures, disaster recovery procedures (how you'll restore service if systems fail), emergency mode operations (how you'll operate with reduced systems), and testing and revision procedures. You should test the plan at least annually.
Are cloud-based systems covered by the Security Rule?
Yes. Whether ePHI is stored on-premises or in cloud systems, the Security Rule applies. Your cloud provider is typically a business associate and must sign a BAA agreeing to implement the same security controls.
What documentation do I need to maintain?
Document all security policies, procedures, risk assessments, training records, incident investigations, contingency plans, and decisions regarding addressable implementation specifications. Maintain documentation for at least 6 years.
What penalties apply for Security Rule violations?
Penalties are tiered: $100-$50,000 per violation (unknowing), $1,000-$100,000 (reasonable cause), and $10,000-$1,500,000 per violation (willful neglect). These accumulate across affected individuals and incidents.

Assess Your Security Rule Compliance

A comprehensive Security Rule implementation requires understanding complex technical and administrative requirements. Medcurity conducts detailed security assessments evaluating your administrative, physical, and technical safeguards against HIPAA standards, identifying gaps, and providing prioritized remediation guidance.

Schedule Security Assessment →