Skip to main content
Category: Regulatory Framework

NIST SP 800-66

Also known as: SP 800-66, NIST Special Publication 800-66, SP 800-66 Rev. 2, SP 800-66r2, Implementing the HIPAA Security Rule: A Cybersecurity Resource Guide
Simply put

NIST SP 800-66 is a guidance document published by the National Institute of Standards and Technology (NIST) that helps organizations understand and implement the safeguards required by the HIPAA Security Rule. It is written for covered entities and business associates that need practical direction on protecting electronic protected health information (ePHI). It is a voluntary resource guide, not a law or regulation, so following it does not by itself guarantee HIPAA compliance.

Formal definition

NIST SP 800-66 (currently Revision 2, published February 2024, titled 'Implementing the Health Insurance Portability and Accountability Act (HIPAA) Security Rule: A Cybersecurity Resource Guide') is a NIST Special Publication that provides practitioner-level guidance for implementing the administrative, physical, and technical safeguards of the HIPAA Security Rule, which focuses on the confidentiality, integrity, and availability of ePHI. It is intended to assist HIPAA covered entities and business associates in understanding and applying the Security Rule's standards and implementation specifications, and it maps Security Rule requirements to broader NIST cybersecurity resources. As a resource guide, SP 800-66 is advisory rather than mandatory: it does not add legal obligations beyond the Security Rule, does not address the HIPAA Privacy or Breach Notification Rules, and its use does not by itself establish compliance, which is determined by HHS OCR against the applicable regulatory text. Readers should confirm they are referencing the current revision and consult the underlying regulation, as well as any applicable state law or HITECH Act requirements that may impose additional obligations.

Why it matters

The HIPAA Security Rule states what covered entities and business associates must accomplish to protect electronic protected health information (ePHI), but its standards and implementation specifications are written at a level of generality that leaves organizations to determine how to implement them. NIST SP 800-66 helps close that gap by translating the Security Rule's administrative, physical, and technical safeguards into practitioner-level guidance, giving compliance, privacy, security, and IT professionals a structured reference for understanding what each requirement is asking and how it connects to broader cybersecurity practices.

Because SP 800-66 maps HIPAA Security Rule requirements to other NIST cybersecurity resources, it is particularly useful for organizations that already rely on NIST frameworks and want a consistent vocabulary across their security program. Using it can help teams reason systematically about safeguards and document their approach, which supports the risk analysis and risk management activities central to the Security Rule.

It is important to keep the document's limits in view. SP 800-66 is a voluntary resource guide, not a law or regulation, and following it does not by itself guarantee HIPAA compliance. Compliance is determined by HHS OCR against the applicable regulatory text, and the guide does not address the HIPAA Privacy Rule or the Breach Notification Rule. State law and the HITECH Act may also impose additional obligations, so SP 800-66 should be treated as a supporting tool rather than a substitute for reading the underlying regulation.

Who it's relevant to

Security Officers and IT Security Teams
Those responsible for implementing and maintaining safeguards for ePHI can use SP 800-66 as a practical reference for interpreting the Security Rule's administrative, physical, and technical safeguards and connecting them to broader NIST cybersecurity resources. It supports the design and documentation of controls but does not replace the risk analysis and risk management the Security Rule requires.
Compliance Officers
Compliance professionals overseeing HIPAA Security Rule obligations can use the guide to help translate regulatory requirements into structured internal practices. They should remember that using SP 800-66 does not by itself establish compliance, which HHS OCR determines against the applicable regulatory text, and that the guide does not cover the Privacy Rule or Breach Notification Rule.
Business Associates and Subcontractors
Vendors and subcontractors that handle ePHI under business associate agreements are within the scope of the Security Rule and can use SP 800-66 for practical direction on implementing safeguards. Their specific obligations flow through their contractual relationships and the regulation, not from the guide itself.
Auditors and Assessors
Professionals evaluating a HIPAA security program may reference SP 800-66 to understand how Security Rule requirements can be implemented and mapped to NIST resources. Because it is advisory guidance rather than a compliance standard, assessments should ultimately be measured against the Security Rule and current guidance, and readers should confirm they are using the current revision.

Inside SP 800-66

Purpose and Scope
NIST SP 800-66 is a NIST Special Publication that provides guidance on implementing the HIPAA Security Rule, which governs the protection of electronic protected health information (ePHI). It is a resource document, not a regulation itself, and does not extend to PHI in oral or paper form, which falls under the HIPAA Privacy Rule.
Mapping to Security Rule Safeguards
The publication generally aligns its guidance with the Security Rule's three safeguard categories, administrative, physical, and technical, helping organizations understand how to approach each area. It typically addresses both required and addressable implementation specifications; readers should note that addressable does not mean optional.
Risk Assessment and Risk Management Focus
NIST SP 800-66 emphasizes the risk analysis and risk management activities that the Security Rule calls for, drawing on broader NIST risk management concepts. It offers practical considerations rather than a binding compliance checklist.
Relationship to Other NIST Guidance
The document generally cross-references other NIST resources (such as the broader 800-series controls and risk management frameworks) to help organizations operationalize Security Rule requirements. Specific referenced publications, control identifiers, and revision numbers should be verified against the current version of SP 800-66.
Intended Audience
It is aimed at covered entities and business associates seeking help interpreting and implementing HIPAA Security Rule obligations. Business associate obligations generally attach through business associate agreements rather than directly from the guidance itself.

Common questions

Answers to the questions practitioners most commonly ask about SP 800-66.

Does following NIST SP 800-66 automatically make an organization HIPAA compliant?
No. NIST SP 800-66 is a guidance document intended to help covered entities and business associates understand and implement the HIPAA Security Rule; it is not itself a regulation and does not carry independent legal force. Following it can support and inform a compliance effort, but compliance is determined by adherence to the Security Rule requirements enforced by HHS OCR, not by adoption of any particular guidance publication. Organizations should treat SP 800-66 as an implementation resource and verify their controls against the current regulatory text.
Is NIST SP 800-66 a mandatory standard that organizations are required to use?
No. NIST SP 800-66 is a voluntary resource published to assist with implementing the HIPAA Security Rule. The Security Rule itself is mandatory for covered entities and business associates handling electronic protected health information (ePHI), but the specific methods and guidance in SP 800-66 are not legally required. An organization may use other approaches to meet Security Rule obligations, provided those obligations are actually satisfied.
How does NIST SP 800-66 relate to the Security Rule's administrative, physical, and technical safeguards?
SP 800-66 is generally organized to help organizations map their activities to the Security Rule's safeguard categories, administrative, physical, and technical, and to the associated standards and implementation specifications. It is intended to assist in understanding what each safeguard aims to achieve and how to approach implementation. It does not replace the regulatory text, so readers should confirm the specific standards and specifications against the current Security Rule.
Can NIST SP 800-66 help with distinguishing required versus addressable implementation specifications?
It can provide context for how to approach both required and addressable implementation specifications under the Security Rule. Importantly, addressable does not mean optional; it generally means an organization must assess whether a specification is reasonable and appropriate in its environment and either implement it, implement an equivalent alternative, or document why it is not applicable. SP 800-66 can support this analysis, but the documentation and decisions must align with the Security Rule's actual requirements.
How does NIST SP 800-66 fit into conducting a Security Rule risk analysis?
SP 800-66 is often used as a reference to help organizations structure a risk analysis process for ePHI, which the Security Rule requires. It can help frame how to identify risks and vulnerabilities and consider safeguards. However, it is guidance rather than a prescriptive checklist that guarantees an adequate risk analysis, and no methodology guarantees the prevention of all breaches. Organizations should ensure their risk analysis meets the current Security Rule expectations and OCR guidance.
How does NIST SP 800-66 relate to the HITRUST CSF and other frameworks?
NIST SP 800-66 is a US government guidance publication focused on the HIPAA Security Rule, whereas the HITRUST CSF is a certifiable control framework maintained by a private organization. They are distinct: using SP 800-66 does not constitute HITRUST certification, and HITRUST certification does not by itself establish HIPAA compliance. Organizations may reference multiple frameworks, but should recognize that state law, the HITECH Act, or other requirements may impose additional obligations beyond what any single guidance document addresses. Verify specifics against the current regulation and the current HITRUST CSF version.

Common misconceptions

Following NIST SP 800-66 guarantees HIPAA Security Rule compliance.
The publication is guidance intended to assist implementation, not a mandatory standard, and following it does not by itself establish or guarantee compliance. Compliance is determined against the actual Security Rule requirements enforced by HHS OCR, and organizations should confirm their approach against the current regulatory text.
NIST SP 800-66 covers all forms of protected health information.
It focuses on the HIPAA Security Rule, which applies only to electronic protected health information (ePHI). Protections for PHI in oral or paper form are addressed by the HIPAA Privacy Rule, which is outside the primary scope of this document.
The addressable implementation specifications discussed in the guidance are optional.
Addressable does not mean optional. For addressable specifications, a covered entity or business associate must generally assess whether the specification is reasonable and appropriate, and implement it, an equivalent alternative, or document why it is not applicable.

Best practices

Use NIST SP 800-66 as an implementation aid, but always validate your approach against the current HIPAA Security Rule text as enforced by HHS OCR, since the guidance itself is not a binding regulation.
Organize your security program around the Security Rule's administrative, physical, and technical safeguard categories, and document how you address both required and addressable implementation specifications.
For each addressable specification, document your assessment of reasonableness and appropriateness and record whether you implemented it, adopted an equivalent alternative, or justified not doing so.
Ground your program in a documented risk analysis and ongoing risk management process, consistent with the risk-based emphasis of the guidance.
Confirm the current revision of SP 800-66 and any cross-referenced NIST publications before relying on specific control mappings or identifiers, as these are updated over time.
Remember that state law and the HITECH Act may impose additional requirements beyond the Security Rule, and that separate frameworks such as the HITRUST CSF are not a substitute for demonstrating HIPAA compliance.