45 CFR Part 164
45 CFR Part 164 is the section of federal regulations that contains the main operational requirements of HIPAA, including rules for protecting health information. It is organized into subparts that cover general provisions, security standards for electronic health data, privacy, and related requirements. Together with 45 CFR Part 160, it forms the core of what are commonly called the HIPAA rules, and readers should consult the current regulatory text for exact provisions.
45 CFR Part 164, titled 'Security and Privacy,' is the part of Title 45 of the Code of Federal Regulations that sets out the substantive standards implementing HIPAA. It is subdivided into subparts, including Subpart A (General Provisions), Subpart C (Security Standards for the Protection of Electronic Protected Health Information, commonly the Security Rule), along with the privacy and breach notification provisions housed within the part. Part 164 works in conjunction with 45 CFR Part 160 (General Administrative Requirements); together these parts are commonly referred to as the HIPAA Privacy, Security, and Breach Notification Rules. Practitioners should note that the Security Rule provisions in Subpart C apply specifically to electronic protected health information (ePHI) and prescribe administrative, physical, and technical safeguards, whereas the Privacy Rule provisions apply to protected health information in all forms. Enforcement of Part 164 rests with HHS OCR. Because the eCFR is continuously updated and is not the official legal edition, and because subpart lettering, section numbers, and specific requirements are subject to amendment, readers should verify against the current CFR text. This entry does not enumerate every subpart, individual section, or implementation specification, and state law or the HITECH Act may impose additional obligations beyond those in Part 164.
Why it matters
45 CFR Part 164 is where the operational heart of HIPAA lives. When compliance professionals reference the Privacy Rule, the Security Rule, or the Breach Notification Rule, they are pointing to provisions housed within this part of the Code of Federal Regulations (working in conjunction with Part 160). Understanding Part 164 matters because it is the text that translates HIPAA's statutory goals into the specific standards, safeguards, and requirements that covered entities and business associates are expected to meet.
Because Part 164 contains distinct subparts with different scopes, precision is essential. The Security Rule provisions in Subpart C apply specifically to electronic protected health information (ePHI) and prescribe administrative, physical, and technical safeguards, while the Privacy Rule provisions apply to protected health information in all forms, including oral and paper. Treating these as interchangeable can lead organizations to misjudge which obligations apply to a given process or data type. Enforcement of Part 164 rests with HHS OCR.
Citing Part 164 accurately also protects credibility in audits, risk assessments, and policy documentation. Because the eCFR is continuously updated and is not the official legal edition, and because subpart lettering, section numbers, and specific requirements are subject to amendment, professionals should verify any specific provision against the current CFR text rather than relying on memory or secondary summaries. Additionally, state law or the HITECH Act may impose obligations beyond those found in Part 164.
Who it's relevant to
Inside 45 CFR Part 164
Common questions
Answers to the questions practitioners most commonly ask about 45 CFR Part 164.