Skip to main content
Category: OCR Enforcement and Penalties

Recognized Security Practices Consideration

Also known as: RSP, Recognized Security Practices, RSP Consideration, HITECH Section 13412 Consideration
Simply put

Recognized Security Practices are cybersecurity measures that a healthcare organization can put in place to help protect health data, such as recognized standards, guidelines, and best practices. Under a 2021 amendment to the HITECH Act, if an organization can show it had these practices in place for a period of time before an incident, HHS may take that into account as a mitigating factor when deciding on enforcement actions or penalties. Having recognized security practices in place does not guarantee HIPAA compliance and does not prevent enforcement; it is one consideration that may reduce potential consequences.

Formal definition

Recognized Security Practices Consideration refers to the mechanism established by Section 13412 of the HITECH Act, as amended in 2021, requiring HHS to take into consideration whether a regulated entity had certain recognized security practices in place when making specified HIPAA Security Rule enforcement determinations. As reflected in the evidence, the amendment adds three enforcement considerations (generally described as affecting matters such as potential penalty amounts and the scope of certain remedies/audits) applicable where the entity can demonstrate the practices were in place for the prior 12 months. The statute defines recognized security practices as including standards, guidelines, best practices, methodologies, procedures, and processes, and a practice must be 'in place' to be considered as a possible mitigating factor. Important limitations: this is a discretionary consideration by HHS OCR, not a safe harbor and not evidence of full HIPAA compliance; the burden of demonstrating that practices were in place rests with the regulated entity; and the specific applicable practices, the 12-month look-back, and the enforcement effects should be verified against the current statutory text and HHS guidance. Practitioners should also note that this consideration applies within HIPAA/HITECH enforcement and does not displace obligations under the Privacy Rule, Breach Notification Rule, state law, or other frameworks.

Why it matters

For healthcare organizations subject to the HIPAA Security Rule, the Recognized Security Practices Consideration created by the 2021 amendment to Section 13412 of the HITECH Act offers a meaningful, if limited, incentive to invest in mature cybersecurity programs. When HHS OCR makes certain enforcement determinations, it is required to take into account whether a regulated entity had recognized security practices in place, which can affect matters such as potential penalty amounts and the scope of certain remedies or audits. In practice, this means the effort an organization puts into adopting recognized standards, guidelines, and best practices before an incident occurs may reduce the potential consequences it faces afterward.

It is critical to understand what this consideration is not. Having recognized security practices in place is not a safe harbor, does not establish full HIPAA compliance, and does not prevent OCR from pursuing enforcement. It is a discretionary mitigating factor, and the burden of demonstrating that the practices were actually in place, generally for the prior 12 months, rests with the regulated entity. An organization that cannot produce evidence of its practices, or that adopted them only after an incident, is unlikely to benefit from this consideration.

Because the consideration applies specifically within HIPAA and HITECH Security Rule enforcement, it does not displace obligations under the Privacy Rule, the Breach Notification Rule, state law, or other frameworks. Organizations should treat recognized security practices as one component of a broader compliance and risk management posture rather than a substitute for one, and should verify the current statutory text and HHS guidance, as the specific applicable practices, the look-back period, and the enforcement effects are subject to change.

Who it's relevant to

Security Officers and Compliance Leaders at Covered Entities
Those responsible for the HIPAA Security Rule program at health plans, healthcare clearinghouses, and covered healthcare providers should understand that adopting recognized security practices and maintaining evidence that they were in place, generally for the prior 12 months, may serve as a mitigating factor in OCR enforcement. They should build documentation and evidence-retention processes so the organization can substantiate its practices if questioned.
Business Associates and Their Security Teams
Business associates are regulated entities subject to the HIPAA Security Rule and may similarly be positioned to benefit from the Recognized Security Practices Consideration in enforcement determinations. They should be prepared to demonstrate that recognized security practices were in place, recognizing that this consideration does not by itself establish full HIPAA compliance and does not displace their obligations under business associate agreements or other rules.
Healthcare Legal and Privacy Counsel
Attorneys advising on HIPAA enforcement should be prepared to help clients demonstrate recognized security practices during OCR investigations and audits, while clearly explaining that the consideration is discretionary, is not a safe harbor, and does not prevent enforcement. Counsel should also flag that it applies within HIPAA/HITECH Security Rule enforcement and does not affect Privacy Rule, Breach Notification Rule, or state-law obligations.
Auditors and Risk Assessors
Professionals who assess healthcare security programs should evaluate not only whether recognized standards, guidelines, and best practices exist on paper but whether they are actually 'in place' and supported by evidence over time. This evidence trail is central to whether an organization can claim the consideration, and assessors should verify current HHS guidance since the applicable practices and look-back requirements may change.

Inside RSP

Statutory Basis
Recognized Security Practices Consideration derives from an amendment to the HITECH Act that directs HHS OCR to take into account whether a regulated entity had, for a specified prior period, adequately demonstrated the use of recognized security practices. The relevant time period and mechanics should be confirmed against the current statutory text and HHS guidance.
Definition of Recognized Security Practices
The term generally refers to standards, guidelines, best practices, methodologies, procedures, and processes developed under recognized statutory frameworks, such as the NIST Cybersecurity Framework and other approaches recognized by applicable law. Entities should verify the precise categories against current regulatory and statutory sources.
Discretionary Mitigating Effect
Where demonstrated, recognized security practices may be considered by HHS OCR when determining certain outcomes, such as the calculation of potential penalties, the extent of an audit, or the resolution of an enforcement matter. This is a mitigating consideration, not a safe harbor that eliminates liability.
Burden of Demonstration
The regulated entity generally bears the responsibility of demonstrating that recognized security practices were in place and actively used for the applicable prior period. Mere adoption on paper is typically insufficient without evidence of implementation.
Relationship to the Security Rule
This consideration operates within HIPAA Security Rule enforcement, which governs electronic protected health information (ePHI). It does not replace or reduce the underlying obligation to comply with the Security Rule's administrative, physical, and technical safeguards, including required and addressable implementation specifications.

Common questions

Answers to the questions practitioners most commonly ask about RSP.

Does adopting recognized security practices guarantee that HHS OCR will not impose penalties after a breach?
No. The consideration of recognized security practices does not guarantee any particular outcome. Where a regulated entity demonstrates that it had recognized security practices in place for a qualifying prior period, HHS OCR is generally directed to take that into account, which may mitigate fines, reduce the extent of certain audits, or favorably affect resolution of enforcement. However, it does not create a safe harbor, does not prevent enforcement, and does not immunize an entity from liability. The weight given is at the discretion of the authority, and outcomes depend on the specific facts. Readers should confirm the current statutory language and OCR guidance.
Does having recognized security practices in place mean an entity is compliant with the HIPAA Security Rule?
No. Recognized security practices and HIPAA Security Rule compliance are distinct concepts. The Security Rule imposes its own required and addressable implementation specifications across administrative, physical, and technical safeguards, and those obligations remain in force regardless of whether an entity also maintains recognized security practices. Recognized security practices function as a mitigating consideration in enforcement and audit contexts, not as a substitute for meeting the Security Rule's requirements. An entity can have recognized practices and still be found noncompliant with specific Security Rule provisions.
How does an entity demonstrate to HHS OCR that it had recognized security practices in place?
Generally, the burden is on the regulated entity to show that recognized security practices were in place, typically for a qualifying period preceding the incident or investigation. In most cases this involves producing documentation such as evidence of the security framework or practices adopted, records showing the practices were actually implemented and operating rather than merely written, and materials tied to the entity's risk analysis and safeguard activities. The specific evidentiary expectations are shaped by OCR guidance, so entities should review current guidance and retain contemporaneous records rather than assembling documentation only after an incident.
What kinds of security practices generally qualify for this consideration?
The consideration generally contemplates standards, guidelines, best practices, methodologies, procedures, and processes developed under recognized statutory approaches or industry-recognized frameworks. Practices aligned with widely recognized cybersecurity frameworks and applicable statutory approaches are typically the intended reference points. Because the qualifying categories are defined by statute and elaborated in guidance, entities should verify against the current regulatory text and OCR guidance which specific frameworks and approaches are recognized rather than assuming any given framework qualifies.
Can a HITRUST CSF certification serve as evidence of recognized security practices?
A HITRUST CSF certification may serve as supporting evidence that an entity has adopted a structured, industry-recognized set of controls, which could be relevant to demonstrating recognized security practices. However, HITRUST is a private organization and the CSF is a certifiable control framework, not a legal requirement; certification does not by itself establish HIPAA compliance and does not automatically satisfy the recognized security practices consideration. The determination of whether practices qualify and how much weight they carry rests with HHS OCR, and entities should confirm current expectations rather than assume certification alone is sufficient.
How long do recognized security practices need to have been in place to be considered?
The consideration generally looks to whether the entity had recognized security practices in place over a defined prior period rather than adopting them only at or after the time of an incident. Practices must typically be demonstrably operational during that period, not merely documented on paper. Because the specific look-back timeframe is set by statute and interpreted through OCR guidance, and because such details are subject to change, entities should confirm the current required period against the applicable regulatory text and OCR guidance rather than relying on a fixed number.

Common misconceptions

Demonstrating recognized security practices guarantees HIPAA compliance or prevents enforcement action.
It does not. The consideration is generally a discretionary mitigating factor that HHS OCR may weigh; it does not establish compliance, create a legal safe harbor, or guarantee against penalties. The underlying HIPAA obligations remain in force, and no measure prevents all breaches or enforcement outcomes.
Achieving HITRUST CSF certification automatically satisfies the recognized security practices consideration and HIPAA generally.
HITRUST is a private organization and the HITRUST CSF is a certifiable control framework, not a legal requirement. Certification by itself does not establish HIPAA compliance and does not automatically satisfy this statutory consideration. Whether a given framework qualifies, and how it is credited, should be confirmed against current HHS guidance and the applicable statute.
Simply adopting a framework document is enough to receive credit for recognized security practices.
The consideration generally turns on practices that were adequately demonstrated and in use over the applicable prior period. Documented policies without evidence of active, ongoing implementation are typically insufficient.

Best practices

Maintain contemporaneous evidence (policies, configurations, logs, training records, risk analyses) showing that recognized security practices were actively implemented, not merely adopted, throughout the applicable prior period.
Map your security program to a recognized statutory framework such as the NIST Cybersecurity Framework, and verify that the chosen framework and its scope align with current HHS guidance and statutory text before relying on it.
Treat this consideration as a supplement to, not a substitute for, full HIPAA Security Rule compliance, ensuring administrative, physical, and technical safeguards are addressed, including addressable specifications which are not optional.
Document decisions and implementation for addressable specifications, recording the rationale and any equivalent alternative measures adopted.
If pursuing HITRUST CSF certification or another framework, document how it supports your recognized security practices posture while recognizing it does not by itself establish HIPAA compliance.
Confirm applicable time periods, qualifying frameworks, and enforcement mechanics against the current statute and HHS OCR guidance, and account for any additional obligations imposed by the HITECH Act or state law.