Confidentiality, Integrity, and Availability (CIA)
The CIA triad describes the three core goals of information security: confidentiality (keeping information from unauthorized access), integrity (keeping data accurate, complete, and unaltered), and availability (ensuring information and systems are accessible when needed). It is a foundational model used to guide security policies and protect data. In a HIPAA context, these three goals are commonly used as a framework for thinking about how to protect health information.
The CIA triad is a foundational information security model composed of three pillars: confidentiality, the protection of information from unauthorized access or disclosure; integrity, the assurance that data are trustworthy, complete, and have not been improperly altered; and availability, the assurance that information and systems are accessible and usable when needed. The model forms a basis for developing and evaluating security policies, controls, and safeguards. Note that the CIA triad is a general information security concept rather than a HIPAA-defined term; the HIPAA Security Rule separately requires covered entities and business associates to ensure the confidentiality, integrity, and availability of electronic protected health information (ePHI), but readers should consult the current regulatory text for HIPAA's specific obligations, and be aware the Security Rule addresses only ePHI while other information may fall outside its scope.
Why it matters
The CIA triad gives security and compliance professionals a shared vocabulary for reasoning about what they are actually protecting. Rather than treating security as a vague goal, the triad breaks it into three distinct objectives, confidentiality (preventing unauthorized access), integrity (keeping data accurate and unaltered), and availability (ensuring systems and information are usable when needed). This framing helps teams recognize that a strong control in one area does not necessarily satisfy the others; a system that keeps data perfectly confidential but becomes unavailable during an outage, or one that stays online but allows records to be silently altered, has failed a core security goal.
In a HIPAA context, these three concepts are especially useful because the HIPAA Security Rule itself requires covered entities and business associates to ensure the confidentiality, integrity, and availability of electronic protected health information (ePHI). The triad therefore serves as a practical mental model for organizing safeguards and risk analysis around health data. It is important to keep the distinction clear, however: the CIA triad is a general information security concept, not a HIPAA-defined term. Applying the triad does not by itself establish HIPAA compliance, and readers should consult the current regulatory text for the Security Rule's specific obligations.
The triad also helps surface scope limitations that matter for compliance. The HIPAA Security Rule addresses only ePHI, so information outside that definition, as well as PHI in oral or paper form governed by the Privacy Rule, may fall outside the Security Rule's reach even though the same CIA principles could still apply as good practice. Using the triad as an analytical lens can help organizations avoid gaps, but it should be paired with a clear understanding of which regulatory rule and which information categories are in play.
Who it's relevant to
Inside CIA
Common questions
Answers to the questions practitioners most commonly ask about CIA.