Evaluation
In HIPAA terms, an evaluation is a regular check-up on how well an organization's security measures protect electronic health information. It looks at whether the safeguards in place are still working and still appropriate as technology, systems, and risks change over time. Generally, this is not a one-time event but something organizations are expected to repeat periodically.
Under the HIPAA Security Rule, Evaluation refers to the administrative safeguard standard requiring covered entities and business associates to perform periodic technical and non-technical evaluations of the extent to which their security policies, procedures, and controls continue to meet Security Rule requirements for safeguarding electronic protected health information (ePHI). Such evaluations are typically prompted both by regular review cycles and by environmental or operational changes affecting the security of ePHI. This term applies specifically to the Security Rule and ePHI; it is distinct from the general dictionary or program-evaluation sense of the word, and it does not by itself establish overall HIPAA compliance. Readers should verify the precise standard language and citation against the current text of the Security Rule, and note that state law or the HITECH Act may impose additional assessment obligations.
Why it matters
The Evaluation standard matters because a security program is only as good as its ability to keep pace with change. Systems get replaced, new threats emerge, staff turnover alters who has access, and business relationships shift. Safeguards that were reasonable and appropriate when first implemented can quietly become outdated or ineffective. The Evaluation standard exists to ensure organizations periodically step back and confirm that their policies, procedures, and controls still meet Security Rule requirements for protecting ePHI, rather than assuming a one-time implementation is sufficient indefinitely.
For covered entities and business associates, periodic evaluation also provides a documented basis for demonstrating due diligence. Because evaluations are typically prompted both by scheduled review cycles and by operational or environmental changes, they help organizations catch gaps before those gaps result in unauthorized access to or disclosure of ePHI. It is important to understand, however, that performing an evaluation does not by itself establish overall HIPAA compliance and does not guarantee that breaches will be prevented; it is one administrative safeguard among many.
Readers should also be aware that the Evaluation standard under the Security Rule applies specifically to ePHI and is distinct from the broader dictionary or program-evaluation sense of the word. State law or the HITECH Act may impose additional assessment obligations beyond what the Security Rule requires, so an organization's evaluation practices should be scoped with those potential additional requirements in mind and verified against current regulatory text.
Who it's relevant to
Inside Evaluation
Common questions
Answers to the questions practitioners most commonly ask about Evaluation.