Skip to main content
Category: Administrative Safeguards

Evaluation

Also known as: Security evaluation, Periodic evaluation
Simply put

In HIPAA terms, an evaluation is a regular check-up on how well an organization's security measures protect electronic health information. It looks at whether the safeguards in place are still working and still appropriate as technology, systems, and risks change over time. Generally, this is not a one-time event but something organizations are expected to repeat periodically.

Formal definition

Under the HIPAA Security Rule, Evaluation refers to the administrative safeguard standard requiring covered entities and business associates to perform periodic technical and non-technical evaluations of the extent to which their security policies, procedures, and controls continue to meet Security Rule requirements for safeguarding electronic protected health information (ePHI). Such evaluations are typically prompted both by regular review cycles and by environmental or operational changes affecting the security of ePHI. This term applies specifically to the Security Rule and ePHI; it is distinct from the general dictionary or program-evaluation sense of the word, and it does not by itself establish overall HIPAA compliance. Readers should verify the precise standard language and citation against the current text of the Security Rule, and note that state law or the HITECH Act may impose additional assessment obligations.

Why it matters

The Evaluation standard matters because a security program is only as good as its ability to keep pace with change. Systems get replaced, new threats emerge, staff turnover alters who has access, and business relationships shift. Safeguards that were reasonable and appropriate when first implemented can quietly become outdated or ineffective. The Evaluation standard exists to ensure organizations periodically step back and confirm that their policies, procedures, and controls still meet Security Rule requirements for protecting ePHI, rather than assuming a one-time implementation is sufficient indefinitely.

For covered entities and business associates, periodic evaluation also provides a documented basis for demonstrating due diligence. Because evaluations are typically prompted both by scheduled review cycles and by operational or environmental changes, they help organizations catch gaps before those gaps result in unauthorized access to or disclosure of ePHI. It is important to understand, however, that performing an evaluation does not by itself establish overall HIPAA compliance and does not guarantee that breaches will be prevented; it is one administrative safeguard among many.

Readers should also be aware that the Evaluation standard under the Security Rule applies specifically to ePHI and is distinct from the broader dictionary or program-evaluation sense of the word. State law or the HITECH Act may impose additional assessment obligations beyond what the Security Rule requires, so an organization's evaluation practices should be scoped with those potential additional requirements in mind and verified against current regulatory text.

Who it's relevant to

Security Officers
Security officers are typically responsible for scheduling, conducting, and documenting periodic evaluations, and for ensuring that both technical and non-technical aspects of the security program are reviewed against current Security Rule requirements. They also determine when operational or environmental changes should trigger an evaluation outside the regular cycle.
Covered Entities
As organizations directly subject to the Security Rule, covered entities must ensure that evaluations are performed to confirm their ePHI safeguards remain appropriate over time. This obligation cannot be assumed to be satisfied by a one-time assessment at initial implementation.
Business Associates and Subcontractors
Business associates, and subcontractors acting as business associates, are also subject to the Security Rule and are generally expected to perform their own periodic evaluations of the safeguards protecting ePHI they handle. These obligations typically flow through business associate agreements as well as the rule itself.
Auditors and Compliance Professionals
Auditors and compliance staff rely on evaluation records as evidence of ongoing due diligence and use them to identify gaps between documented safeguards and Security Rule requirements. They should note that a completed evaluation demonstrates one administrative safeguard but does not by itself establish overall HIPAA compliance.
IT and Legal Teams
IT teams provide the technical detail needed to assess system-level controls, while legal teams help interpret how state law or the HITECH Act may add assessment obligations beyond the Security Rule. Both should confirm the current standard language and citation before finalizing evaluation scope.

Inside Evaluation

Standard Under the Security Rule
Evaluation is an administrative safeguard standard within the HIPAA Security Rule, applicable to covered entities and business associates that handle electronic protected health information (ePHI). It generally requires periodic technical and nontechnical assessments of how well an entity's security policies and procedures meet the Security Rule's requirements.
Technical Assessment Component
The technical portion typically involves reviewing the effectiveness of technical controls protecting ePHI, such as access controls, audit mechanisms, and transmission security, to confirm they continue to operate as intended.
Nontechnical Assessment Component
The nontechnical portion generally addresses administrative and physical safeguards, including policies, procedures, workforce practices, and physical protections, evaluating whether they remain adequate and are being followed.
Response to Environmental or Operational Change
Evaluation is generally triggered both periodically and in response to environmental or operational changes that may affect the security of ePHI, such as new technology, system changes, reorganizations, or newly identified threats.
Documentation of Findings
The evaluation process typically results in documented findings that establish the extent to which safeguards meet Security Rule requirements, supporting remediation planning and demonstrating ongoing compliance efforts.
Relationship to Risk Analysis
Evaluation is distinct from, but complementary to, the Security Rule's risk analysis requirement. Risk analysis focuses on identifying and assessing risks to ePHI, while evaluation focuses on measuring how effectively existing safeguards satisfy the rule's standards. Readers should verify the specific scope of each against the current regulatory text.

Common questions

Answers to the questions practitioners most commonly ask about Evaluation.

Is the evaluation requirement a one-time task I can complete during initial HIPAA implementation?
No. The evaluation standard under the Security Rule is intended to be periodic and ongoing, not a single event. Evaluations should generally be performed both when initially implementing safeguards and in response to environmental or operational changes that may affect the security of ePHI, such as new technologies, changes in business practices, or updates to organizational structure. Treating evaluation as a one-time checkbox misunderstands its purpose. Readers should confirm the specifics against the current regulatory text.
Does the evaluation standard require me to hire an outside auditor or third-party firm?
Not necessarily. The Security Rule generally permits evaluations to be conducted internally or by an external party. The standard focuses on the substance, a technical and nontechnical evaluation of how well safeguards meet Security Rule requirements, rather than mandating who performs it. Many organizations use internal staff, external consultants, or a combination, based on their resources and expertise. Note that a HITRUST assessment or certification is a separate, private-framework activity and does not by itself satisfy or establish HIPAA compliance.
What should be included in the scope of a Security Rule evaluation?
An evaluation generally encompasses both technical and nontechnical components. Technical aspects may include reviewing access controls, audit mechanisms, transmission security, and other technical safeguards protecting ePHI. Nontechnical aspects typically involve reviewing administrative and physical safeguards, policies, procedures, and workforce practices. The goal is to assess whether implemented safeguards continue to meet the applicable Security Rule requirements. Because the Security Rule applies only to ePHI, evaluations under this standard address ePHI protections rather than PHI in all forms.
How often should evaluations be performed?
The Security Rule does not, as a general matter, prescribe a fixed calendar interval. Instead, evaluations are typically expected to occur periodically and in response to operational or environmental changes affecting ePHI security. Many organizations adopt a regular cadence (for example, annually) as a matter of practice while also triggering evaluations after significant changes such as new systems, mergers, or major process changes. Organizations should document their rationale and verify expectations against current guidance.
How does the evaluation standard relate to the required risk analysis?
They are distinct but complementary. The risk analysis is a separate administrative safeguard focused on identifying risks and vulnerabilities to ePHI, while the evaluation standard focuses on assessing whether implemented safeguards continue to meet Security Rule requirements over time. In practice, findings from ongoing evaluations often inform updates to the risk analysis and vice versa. Readers should treat each as its own obligation rather than assuming one satisfies the other.
How should the results of an evaluation be documented?
As a general practice, organizations should retain documentation demonstrating that evaluations were performed, what was assessed, findings identified, and any resulting remediation or changes to safeguards. Maintaining this documentation helps demonstrate ongoing compliance efforts and supports accountability. Documentation and retention practices should be aligned with the Security Rule's general documentation requirements, which readers should confirm against the current regulatory text, and may be supplemented by applicable state law requirements.

Common misconceptions

Evaluation is a one-time activity completed at initial Security Rule implementation.
Evaluation is generally an ongoing obligation. It is expected to be performed periodically and again in response to environmental or operational changes affecting ePHI security, not treated as a single completed task.
The Evaluation standard applies to protected health information in all forms, including paper and oral.
As a Security Rule standard, Evaluation applies only to electronic protected health information (ePHI). Assessments of PHI in oral or paper form fall under the separate scope of the Privacy Rule.
Passing a HITRUST CSF assessment or obtaining HITRUST certification satisfies the HIPAA Evaluation requirement.
HITRUST is a private organization and the HITRUST CSF is a certifiable control framework; certification is not a legal requirement and does not by itself establish HIPAA compliance. It may support evaluation efforts, but the entity remains responsible for meeting the Security Rule's Evaluation standard as enforced by HHS OCR. Readers should confirm details against the current HITRUST CSF version and current regulatory guidance.

Best practices

Establish a defined schedule for periodic evaluations and document a policy that also triggers an evaluation when significant environmental or operational changes occur, such as new systems, mergers, or emerging threats.
Ensure each evaluation covers both technical safeguards (for example, access controls and audit mechanisms) and nontechnical safeguards (administrative policies, workforce practices, and physical protections) so no safeguard category is overlooked.
Maintain thorough documentation of evaluation scope, methodology, findings, and any resulting remediation, since documentation supports demonstrating ongoing compliance and informs future assessments.
Coordinate evaluation activities with, but do not substitute them for, the required risk analysis, keeping the distinct purpose of each clear in your compliance program.
Where external frameworks such as the HITRUST CSF are used to support evaluation, map their controls back to Security Rule requirements and treat certification as supporting evidence rather than proof of HIPAA compliance.
Confirm current requirements, applicable deadlines, and any additional obligations under state law or the HITECH Act against authoritative sources, as these may impose requirements beyond the HIPAA Security Rule's baseline.