NIST SP 800-66
NIST SP 800-66 is a guidance document published by the National Institute of Standards and Technology (NIST) that helps organizations understand and implement the safeguards required by the HIPAA Security Rule. It is written for covered entities and business associates that need practical direction on protecting electronic protected health information (ePHI). It is a voluntary resource guide, not a law or regulation, so following it does not by itself guarantee HIPAA compliance.
NIST SP 800-66 (currently Revision 2, published February 2024, titled 'Implementing the Health Insurance Portability and Accountability Act (HIPAA) Security Rule: A Cybersecurity Resource Guide') is a NIST Special Publication that provides practitioner-level guidance for implementing the administrative, physical, and technical safeguards of the HIPAA Security Rule, which focuses on the confidentiality, integrity, and availability of ePHI. It is intended to assist HIPAA covered entities and business associates in understanding and applying the Security Rule's standards and implementation specifications, and it maps Security Rule requirements to broader NIST cybersecurity resources. As a resource guide, SP 800-66 is advisory rather than mandatory: it does not add legal obligations beyond the Security Rule, does not address the HIPAA Privacy or Breach Notification Rules, and its use does not by itself establish compliance, which is determined by HHS OCR against the applicable regulatory text. Readers should confirm they are referencing the current revision and consult the underlying regulation, as well as any applicable state law or HITECH Act requirements that may impose additional obligations.
Why it matters
The HIPAA Security Rule states what covered entities and business associates must accomplish to protect electronic protected health information (ePHI), but its standards and implementation specifications are written at a level of generality that leaves organizations to determine how to implement them. NIST SP 800-66 helps close that gap by translating the Security Rule's administrative, physical, and technical safeguards into practitioner-level guidance, giving compliance, privacy, security, and IT professionals a structured reference for understanding what each requirement is asking and how it connects to broader cybersecurity practices.
Because SP 800-66 maps HIPAA Security Rule requirements to other NIST cybersecurity resources, it is particularly useful for organizations that already rely on NIST frameworks and want a consistent vocabulary across their security program. Using it can help teams reason systematically about safeguards and document their approach, which supports the risk analysis and risk management activities central to the Security Rule.
It is important to keep the document's limits in view. SP 800-66 is a voluntary resource guide, not a law or regulation, and following it does not by itself guarantee HIPAA compliance. Compliance is determined by HHS OCR against the applicable regulatory text, and the guide does not address the HIPAA Privacy Rule or the Breach Notification Rule. State law and the HITECH Act may also impose additional obligations, so SP 800-66 should be treated as a supporting tool rather than a substitute for reading the underlying regulation.
Who it's relevant to
Inside SP 800-66
Common questions
Answers to the questions practitioners most commonly ask about SP 800-66.