Skip to main content
Category: OCR Enforcement and Penalties

Recognized Security Practices

Also known as: RSP, Recognized Security Practices (RSP), RSPs
Simply put

Recognized Security Practices are established cybersecurity standards, guidelines, and processes that a healthcare organization can voluntarily adopt to help protect health information. Under a 2021 amendment to the HITECH Act, HHS OCR is required to take an organization's use of these practices into account when it investigates security incidents or determines potential penalties. Adopting them is optional, and an organization generally does not face direct penalties simply for choosing not to implement them.

Formal definition

Recognized Security Practices (RSP), as defined under the 2021 HITECH Act amendment, are the standards, guidelines, best practices, methodologies, procedures, and processes developed under certain statutory authorities, for example, practices developed under the National Institute of Standards and Technology (NIST) framework, among others referenced in the amendment. The amendment requires HHS OCR to consider whether a regulated entity had, in the prior 12 months, adequately demonstrated the use of RSPs when making certain enforcement determinations, including audits, resolution of potential penalties, and mitigation. Implementation of RSPs is voluntary; a regulated entity that elects not to adopt them does not, per the evidence, suffer direct repercussions solely for that choice. Important limitations: RSPs operate as a mitigating factor in the enforcement context and do not amend, replace, or expand the underlying obligations of the HIPAA Security Rule, nor does adopting RSPs by itself establish or guarantee HIPAA compliance. Practitioners should verify the specific enumerated authorities, applicability, and any evidentiary expectations against the current statutory text and OCR guidance, and note that state law or other frameworks may impose additional requirements.

Why it matters

For covered entities and business associates, the practical significance of Recognized Security Practices lies in how they can influence HHS OCR enforcement outcomes. Under the 2021 HITECH Act amendment, OCR is required to consider whether a regulated entity had adequately demonstrated the use of RSPs during the prior 12 months when making certain enforcement determinations, including audits, the resolution of potential penalties, and mitigation. In practice, this means an organization that has invested in and can document its use of established security practices may be positioned more favorably when it is under investigation following a security incident.

At the same time, it is important to understand the limits of what RSPs accomplish. They function as a mitigating factor in the enforcement context; they do not amend, replace, or expand the underlying obligations of the HIPAA Security Rule. Adopting RSPs does not by itself establish or guarantee HIPAA compliance, and an entity still must meet the Security Rule's administrative, physical, and technical safeguard requirements regardless of whether it adopts RSPs. Conversely, implementation is voluntary, and per the available evidence a regulated entity that chooses not to adopt RSPs does not suffer direct repercussions solely for that choice.

Because the value of RSPs is realized largely through documentation and demonstrable use over a trailing period, organizations should treat evidence-keeping as central rather than incidental. The specific enumerated authorities, applicability, and evidentiary expectations should be verified against the current statutory text and OCR guidance, and readers should note that state law or other frameworks may impose additional requirements beyond what the HITECH amendment addresses.

Who it's relevant to

Security Officers and Compliance Teams
Those responsible for a regulated entity's security program are the primary decision-makers on whether to adopt RSPs and how to document their ongoing use. Because OCR's consideration looks at the prior 12 months, these roles should focus on maintaining continuous evidence of implementation rather than relying on point-in-time attestations, while remembering that RSPs supplement rather than substitute for Security Rule compliance.
Covered Entities and Business Associates
Both categories of regulated entity fall within the scope of the HITECH amendment and may adopt RSPs voluntarily. The potential enforcement benefit accrues to the entity that can demonstrate use of RSPs, so each should assess independently whether and how to implement them, keeping in mind that adoption does not by itself establish HIPAA compliance.
Legal Counsel and Privacy/Compliance Advisors
Advisors counseling organizations on enforcement risk should understand that RSPs operate as a mitigating factor in OCR's enforcement determinations, not as a safe harbor or guarantee. They should verify the specific enumerated statutory authorities and evidentiary expectations against current OCR guidance and flag where state law or other frameworks may impose additional requirements.
Organizations Facing or Anticipating OCR Investigation
Entities under audit or investigating a security incident may find that documented use of RSPs over the preceding 12 months is relevant to how OCR resolves potential penalties and mitigation. These organizations should confirm current guidance on how such use may be demonstrated, since penalty determinations remain within OCR's authority and turn on the facts presented.

Inside RSP

Statutory Basis (HITECH Amendment)
Recognized Security Practices are a concept introduced through an amendment to the HITECH Act that directs HHS to take into consideration whether a regulated entity had, for a specified prior period, adequately demonstrated the use of recognized security practices when making certain enforcement and audit determinations. Readers should verify the current statutory text and effective dates against authoritative sources.
Sources of Recognized Security Practices
RSP generally refers to standards, guidelines, best practices, methodologies, procedures, and processes developed under specified statutory authorities and other recognized approaches. In common practice these are understood to include cybersecurity frameworks and industry-recognized security practices; entities should confirm which specific sources qualify under current HHS guidance.
Voluntary Nature
Adoption of Recognized Security Practices is voluntary. RSP is not an additional mandatory requirement layered on top of the HIPAA Security Rule; it is a mechanism that may be considered by HHS OCR in certain contexts rather than a new compliance obligation.
Mitigating Consideration in Enforcement
Where a regulated entity can demonstrate it had recognized security practices in place for the relevant lookback period, HHS OCR is directed to consider that fact in ways that may mitigate certain enforcement outcomes, such as reducing fines, decreasing the length or extent of audits, or otherwise favorably resolving certain matters, subject to current guidance.
Burden of Demonstration on the Entity
The regulated entity generally bears the responsibility for demonstrating that recognized security practices were in place and were in use over the applicable period. Mere adoption on paper is typically insufficient; evidence of actual, sustained implementation is what is considered.
Relationship to the HIPAA Security Rule
RSP operates in the context of the Security Rule, which governs only electronic protected health information (ePHI) through administrative, physical, and technical safeguards. Demonstrating recognized security practices does not replace the underlying obligation to comply with the Security Rule's required and addressable implementation specifications.

Common questions

Answers to the questions practitioners most commonly ask about RSP.

Does having Recognized Security Practices in place guarantee that HHS OCR will not impose penalties after a breach?
No. Recognized Security Practices (RSP) do not guarantee any particular outcome and do not prevent enforcement action or breach investigations. Under the applicable statutory framework, having RSP in place for a sufficient prior period is a factor that HHS OCR may consider, generally in ways such as mitigating potential fines, reducing the length or extent of audits, or otherwise favorably affecting the resolution of an enforcement matter. It does not establish HIPAA compliance by itself, nor does it create a safe harbor from liability. Covered entities and business associates remain obligated to meet the underlying HIPAA Security Rule requirements, and readers should verify how OCR is currently applying this consideration against the current regulatory text and guidance.
Are Recognized Security Practices a mandatory requirement that organizations must adopt under HIPAA?
No. Adopting RSP is generally voluntary rather than a HIPAA requirement in itself. The concept functions as an incentive: an organization that has demonstrably had recognized security practices in place may have that fact considered by HHS OCR in certain enforcement and audit contexts. Organizations are still required to comply with the HIPAA Security Rule's administrative, physical, and technical safeguards regardless of whether they pursue RSP. Choosing not to adopt a specific recognized framework does not, by itself, create a HIPAA violation, though it may forgo the potential mitigating benefit.
What types of frameworks or standards can qualify as Recognized Security Practices?
In general, RSP refers to standards, guidelines, and practices developed under recognized approaches to cybersecurity, which may include practices developed under certain federal statutory authorities as well as other recognized cybersecurity frameworks and programs. Because the specific categories and any named frameworks are defined by statute and interpreted through HHS guidance, readers should confirm the current definition and any qualifying frameworks against the applicable statutory text and OCR guidance rather than assuming a particular framework qualifies.
How long do Recognized Security Practices need to be in place to be considered by HHS OCR?
The applicable framework generally contemplates that the practices must have been in place over a defined prior period rather than adopted only after a breach or investigation. Because the specific duration is set by statute, organizations should verify the current time period requirement against the applicable regulatory text before relying on it. As a practical matter, implementing and maintaining practices continuously, rather than temporarily, is consistent with the intent of the provision.
How can an organization demonstrate that it had Recognized Security Practices in place?
Demonstration typically relies on documentation. Organizations generally maintain records showing which recognized framework or practices were adopted, evidence of consistent implementation across relevant systems and operations, and dated artifacts establishing that the practices were operational over the relevant prior period. Because OCR would assess this in context, contemporaneous documentation, policies, risk analyses, and records of ongoing operation are generally more persuasive than after-the-fact assertions. Organizations should align their evidence with how OCR is currently requesting or evaluating such documentation.
How do Recognized Security Practices relate to the required HIPAA Security Rule safeguards and risk analysis?
RSP does not replace or substitute for the HIPAA Security Rule's required and addressable implementation specifications across the administrative, physical, and technical safeguard categories, nor does it replace the required risk analysis. An organization must still meet its underlying Security Rule obligations. Adopting a recognized framework may support and overlap with those obligations, but the two are distinct: satisfying a recognized framework does not automatically satisfy every Security Rule requirement, and readers should treat the framework as complementary to, not a replacement for, HIPAA compliance.
Does adopting a certifiable framework such as the HITRUST CSF count as having Recognized Security Practices?
Whether any particular framework, including a private certifiable framework, qualifies as RSP depends on how the applicable statute and HHS guidance define recognized practices. It is important to keep two things separate: HITRUST is a private organization and its CSF is a private, certifiable control framework, while RSP is a concept established under federal law and considered by HHS OCR. HITRUST certification does not by itself establish HIPAA compliance and does not automatically constitute RSP for enforcement purposes. Organizations should verify against current statutory text and OCR guidance whether a given framework qualifies, and should note that state law or other frameworks may impose additional requirements.

Common misconceptions

Implementing Recognized Security Practices makes an organization HIPAA compliant or guarantees it will avoid penalties.
RSP is a mitigating consideration that HHS OCR may take into account in certain enforcement and audit contexts; it does not by itself establish HIPAA compliance and does not guarantee that penalties will be avoided. Entities must still comply with the applicable HIPAA rules, and outcomes depend on current HHS guidance and the specific facts.
Recognized Security Practices are a new mandatory requirement that entities are legally obligated to adopt.
Adoption of RSP is voluntary. It is not an additional mandate beyond the HIPAA Security Rule; rather, it is a mechanism that may benefit an entity if it chooses to adopt and can demonstrate sustained use of qualifying practices.
Obtaining a certification such as HITRUST CSF certification automatically qualifies as, or satisfies, Recognized Security Practices.
HITRUST is a private organization and HITRUST certification is not a legal requirement and does not by itself establish HIPAA compliance. While recognized frameworks and industry practices may be relevant to demonstrating RSP, entities should not assume any particular certification automatically qualifies; the demonstration turns on whether qualifying practices were actually in use for the applicable period, subject to current HHS guidance.

Best practices

Maintain documented evidence that recognized security practices were not only adopted but actively in use throughout the applicable lookback period, since the burden of demonstration generally falls on the regulated entity.
Map your chosen security practices to a recognized source or framework and retain records showing which standards or methodologies you rely on, verifying eligibility against current HHS guidance.
Do not treat RSP as a substitute for compliance with the HIPAA Security Rule; continue to address all required implementation specifications and to document decisions on addressable specifications, remembering that addressable does not mean optional.
Keep implementation evidence current and continuous rather than point-in-time, so you can show sustained use of practices over the relevant period rather than a paper-only program.
If you rely on a certification such as HITRUST, treat it as supporting evidence of security practices rather than as automatic proof of RSP or of HIPAA compliance, and confirm how it aligns with current HHS expectations.
Verify the current statutory text, effective dates, and applicable lookback period against authoritative sources before relying on RSP in an enforcement or audit posture, and consider that state law or other frameworks may impose additional requirements.