Skip to main content
Category: Regulatory Framework

45 CFR Part 164

Also known as: Part 164, Title 45 CFR Part 164, Security and Privacy (Part 164)
Simply put

45 CFR Part 164 is the section of federal regulations that contains the main operational requirements of HIPAA, including rules for protecting health information. It is organized into subparts that cover general provisions, security standards for electronic health data, privacy, and related requirements. Together with 45 CFR Part 160, it forms the core of what are commonly called the HIPAA rules, and readers should consult the current regulatory text for exact provisions.

Formal definition

45 CFR Part 164, titled 'Security and Privacy,' is the part of Title 45 of the Code of Federal Regulations that sets out the substantive standards implementing HIPAA. It is subdivided into subparts, including Subpart A (General Provisions), Subpart C (Security Standards for the Protection of Electronic Protected Health Information, commonly the Security Rule), along with the privacy and breach notification provisions housed within the part. Part 164 works in conjunction with 45 CFR Part 160 (General Administrative Requirements); together these parts are commonly referred to as the HIPAA Privacy, Security, and Breach Notification Rules. Practitioners should note that the Security Rule provisions in Subpart C apply specifically to electronic protected health information (ePHI) and prescribe administrative, physical, and technical safeguards, whereas the Privacy Rule provisions apply to protected health information in all forms. Enforcement of Part 164 rests with HHS OCR. Because the eCFR is continuously updated and is not the official legal edition, and because subpart lettering, section numbers, and specific requirements are subject to amendment, readers should verify against the current CFR text. This entry does not enumerate every subpart, individual section, or implementation specification, and state law or the HITECH Act may impose additional obligations beyond those in Part 164.

Why it matters

45 CFR Part 164 is where the operational heart of HIPAA lives. When compliance professionals reference the Privacy Rule, the Security Rule, or the Breach Notification Rule, they are pointing to provisions housed within this part of the Code of Federal Regulations (working in conjunction with Part 160). Understanding Part 164 matters because it is the text that translates HIPAA's statutory goals into the specific standards, safeguards, and requirements that covered entities and business associates are expected to meet.

Because Part 164 contains distinct subparts with different scopes, precision is essential. The Security Rule provisions in Subpart C apply specifically to electronic protected health information (ePHI) and prescribe administrative, physical, and technical safeguards, while the Privacy Rule provisions apply to protected health information in all forms, including oral and paper. Treating these as interchangeable can lead organizations to misjudge which obligations apply to a given process or data type. Enforcement of Part 164 rests with HHS OCR.

Citing Part 164 accurately also protects credibility in audits, risk assessments, and policy documentation. Because the eCFR is continuously updated and is not the official legal edition, and because subpart lettering, section numbers, and specific requirements are subject to amendment, professionals should verify any specific provision against the current CFR text rather than relying on memory or secondary summaries. Additionally, state law or the HITECH Act may impose obligations beyond those found in Part 164.

Who it's relevant to

Privacy and Security Officers
Officers responsible for HIPAA compliance rely on Part 164 as the source text for the standards they must implement and document. Because Subpart C (Security Rule) governs ePHI while the privacy provisions cover PHI in all forms, these professionals must map organizational processes to the correct subpart and verify specific requirements against the current CFR text.
Covered Entities and Business Associates
Both covered entities and business associates are subject to provisions within Part 164, though the specific obligations that attach depend on their defined role and, for business associates, on the terms of applicable business associate agreements. Understanding where an obligation originates in the regulatory text helps these organizations avoid over- or under-scoping their compliance efforts.
Auditors and Legal Professionals
Auditors assessing HIPAA compliance and attorneys advising healthcare clients cite Part 164 when documenting findings or interpreting requirements. Because the eCFR is not the official legal edition and provisions may be amended, these professionals should confirm citations against the current CFR text and consider whether the HITECH Act or state law imposes additional requirements.
Compliance and IT Teams
Teams implementing safeguards translate the administrative, physical, and technical requirements of the Security Rule (Subpart C) into operational controls for ePHI. They benefit from knowing that these requirements sit within Part 164 alongside broader privacy obligations, so that technical controls are aligned with the correct scope of the applicable rule.

Inside 45 CFR Part 164

Subpart C - Security Rule
Contains the security standards for the protection of electronic protected health information (ePHI), organized into administrative, physical, and technical safeguards. This subpart applies only to ePHI, not to PHI in oral or paper form.
Subpart D - Breach Notification Rule
Sets out the requirements for notifying affected individuals, HHS, and in some cases the media following a breach of unsecured protected health information. Notification obligations and timelines are enforced by HHS OCR and should be confirmed against the current regulatory text.
Subpart E - Privacy Rule
Establishes standards governing the use and disclosure of protected health information in all forms, including oral, paper, and electronic. This is broader in scope than the Security Rule, which is limited to ePHI.
Administrative, physical, and technical safeguards
The three safeguard categories under the Security Rule (Subpart C). Each category contains standards with implementation specifications that are designated as either required or addressable. Addressable does not mean optional; where a specification is not reasonable and appropriate, an entity must document its rationale and implement an equivalent alternative if reasonable.
Applicability to covered entities and business associates
Provisions in Part 164 apply to covered entities and, for many requirements, to business associates and their subcontractors. Obligations generally flow to vendors through business associate agreements rather than through direct regulation of every party that touches data.

Common questions

Answers to the questions practitioners most commonly ask about 45 CFR Part 164.

Does 45 CFR Part 164 apply only to electronic protected health information?
No. This is a common misconception that conflates the whole of Part 164 with its Security Rule subpart. Part 164 contains multiple subparts, including the Privacy Rule, which generally applies to protected health information in all forms, oral, paper, and electronic, and the Security Rule, which applies specifically to electronic protected health information (ePHI). The Breach Notification provisions also reside within Part 164. When citing Part 164, it is important to identify which subpart and which safeguard category you mean, since their scopes differ. Readers should verify the specific provisions against the current regulatory text.
If an implementation specification in Part 164 is labeled 'addressable,' does that mean my organization can skip it?
No. Addressable does not mean optional. Within the Security Rule provisions of Part 164, implementation specifications are designated as either 'required' or 'addressable.' For an addressable specification, a covered entity or business associate generally must assess whether the specification is reasonable and appropriate in its environment, and then either implement it, implement an equivalent alternative measure, or document why it is not reasonable and appropriate. That analysis and documentation are themselves expectations, so an addressable specification cannot simply be ignored. Confirm the specific treatment against the current regulation.
Which subpart of Part 164 should I look to for the safeguards my security program must implement?
The Security Rule safeguards are organized within Part 164 into administrative, physical, and technical categories, each containing standards and their associated implementation specifications. In practice, teams building an ePHI security program typically map their controls to these three safeguard categories and note whether each implementation specification is required or addressable. Keep in mind the Security Rule addresses ePHI, while broader handling of PHI in all forms is governed by the Privacy Rule provisions of Part 164. Verify the current organization of these provisions against the applicable regulatory text.
How does Part 164 apply to our vendors and their subcontractors?
Part 164's obligations generally attach through defined relationships rather than to any vendor that merely touches data. Covered entities are directly subject to the applicable provisions, and business associates are subject to certain provisions through the HIPAA framework and through business associate agreements. Subcontractors that create, receive, maintain, or transmit PHI on behalf of a business associate are also generally treated as business associates, with obligations flowing through the chain of agreements. When implementing, organizations typically inventory these relationships and ensure appropriate agreements are in place. Confirm the specific flow-down requirements against the current regulation.
Does achieving HITRUST CSF certification demonstrate compliance with 45 CFR Part 164?
Not by itself. HITRUST is a private organization and the HITRUST CSF is a certifiable control framework; certification is not a legal requirement under HIPAA and does not by itself establish compliance with the provisions of Part 164, which are enforced by HHS OCR. Many organizations use the HITRUST CSF as a structured way to help organize and evidence controls that map to Part 164 requirements, but the underlying regulatory obligations remain independent of any certification. Organizations should assess their compliance against the current regulatory text and confirm control mappings against the current HITRUST CSF version.
When we document our compliance efforts under Part 164, does that documentation guarantee we won't face enforcement or a breach?
No documentation or safeguard guarantees compliance or prevents all breaches. Documentation of policies, procedures, risk analyses, and decisions, including the rationale for how addressable specifications are handled, is generally expected and supports demonstrating reasonable and appropriate measures. However, enforcement of Part 164 is carried out by HHS OCR, and penalty tiers and figures are adjusted over time and should be confirmed against current guidance. Additionally, state law, the HITECH Act, or other frameworks may impose obligations beyond Part 164, so organizations should account for those requirements as well.

Common misconceptions

45 CFR Part 164 governs only electronic data.
Only the Security Rule (Subpart C) is limited to electronic protected health information. The Privacy Rule (Subpart E) within the same Part covers protected health information in all forms, including oral and paper.
Addressable implementation specifications in the Security Rule are optional.
Addressable specifications are not optional. An entity must assess whether the specification is reasonable and appropriate, implement it if so, or document why it is not and adopt an equivalent alternative measure where reasonable.
Achieving HITRUST CSF certification satisfies the requirements of Part 164.
HITRUST is a private organization and the HITRUST CSF is a certifiable control framework, not a legal requirement. Certification may support a compliance program but does not by itself establish compliance with the HIPAA rules codified in Part 164, which are enforced by HHS OCR.

Best practices

Map your organization's obligations to the correct subpart, distinguishing Privacy Rule (all PHI), Security Rule (ePHI only), and Breach Notification requirements, since applying the wrong scope is a common source of gaps.
For every Security Rule addressable implementation specification, document your assessment of whether it is reasonable and appropriate, and record either its implementation or the rationale and equivalent alternative adopted.
Use business associate agreements to flow applicable Part 164 obligations to vendors and subcontractors, and confirm that these relationships are properly defined rather than assuming HIPAA directly regulates every party handling data.
Verify breach notification timelines, penalty tiers, and any specific figures against current HHS OCR guidance and regulatory text, since these are adjusted over time.
Treat any HITRUST CSF certification as a supporting measure and separately confirm alignment with the specific requirements of Part 164, noting the current HITRUST CSF version where relevant.
Check whether state law or the HITECH Act imposes additional requirements beyond Part 164, as these may extend obligations related to privacy, security, or breach notification.