Skip to main content
Category: Regulatory Framework

Security Rule

Also known as: HIPAA Security Rule
Simply put

The HIPAA Security Rule is a set of national standards that requires organizations to protect electronic health information they create, receive, maintain, or transmit. Unlike the broader Privacy Rule, which covers health information in all forms, the Security Rule applies specifically to health information in electronic form (ePHI). It calls for administrative, physical, and technical safeguards to keep that electronic data confidential, available, and secure.

Formal definition

The HIPAA Security Rule establishes a national set of security standards for safeguarding electronic protected health information (ePHI) that is maintained or transmitted by regulated entities. It requires the implementation of administrative, physical, and technical safeguards, along with associated risk management practices, to protect the confidentiality, integrity, and availability of ePHI. The Security Rule is narrower in scope than the HIPAA Privacy Rule: it applies only to ePHI, not to PHI in oral or paper form. Its standards are generally organized into required and addressable implementation specifications, where 'addressable' does not mean optional but rather permits reasonable, documented flexibility based on an entity's risk analysis. Readers should verify specific standards, safeguard requirements, and CFR citations against the current regulatory text, and note that the HITECH Act, state laws, or other frameworks may impose additional obligations.

Why it matters

The Security Rule matters because it defines the baseline expectations for how regulated entities must protect electronic protected health information (ePHI) against unauthorized access, alteration, loss, or disclosure. As healthcare data has shifted overwhelmingly into electronic systems, the Security Rule has become the operational backbone of most HIPAA compliance programs, translating the broader confidentiality goals of HIPAA into concrete administrative, physical, and technical safeguards. For compliance, privacy, and security officers, understanding its scope is essential to allocating resources correctly and avoiding gaps in protection.

A key reason the Security Rule demands careful attention is that its scope is narrower than many practitioners assume: it applies only to ePHI, not to PHI in oral or paper form, which remains governed by the broader Privacy Rule. Misunderstanding this boundary can lead organizations to either over-apply technical controls where physical or procedural Privacy Rule measures are needed, or to overlook non-electronic information entirely. Because the Rule is built around administrative, physical, and technical safeguards paired with risk management practices, it is less a checklist than a framework requiring ongoing analysis of an organization's specific environment.

No set of Security Rule safeguards can guarantee that a breach will never occur; the Rule instead requires reasonable, documented, risk-based protection of ePHI. Organizations should also recognize that the HITECH Act, state laws, and other frameworks may impose additional obligations beyond the Security Rule, and that specific safeguard requirements and CFR citations should be verified against the current regulatory text.

Who it's relevant to

Security Officers and IT Compliance Teams
These professionals are typically responsible for designing and maintaining the administrative, physical, and technical safeguards the Security Rule requires. They rely on risk analysis to determine which controls are reasonable and appropriate, and they must document decisions about addressable implementation specifications, since addressable does not mean optional.
Privacy Officers
Privacy officers need to understand where the Security Rule ends and the broader Privacy Rule begins. Because the Security Rule covers only ePHI while the Privacy Rule covers PHI in all forms, coordinating the two is essential to ensure that oral and paper health information is not overlooked.
Covered Entities and Business Associates
Both covered entities and business associates that create, receive, maintain, or transmit ePHI are generally subject to Security Rule obligations. Business associates should note that specific obligations may also flow through business associate agreements, and all parties should confirm current requirements against the applicable regulatory text.
Auditors and Legal Professionals
Auditors assessing an organization's HIPAA posture and legal counsel advising on compliance need to evaluate whether safeguards and risk management practices meet Security Rule standards. They should also account for additional obligations that may arise under the HITECH Act, state laws, or other frameworks, and verify penalty and enforcement details against current HHS OCR guidance.

Inside Security Rule

Scope: Electronic Protected Health Information (ePHI)
The Security Rule applies specifically to ePHI that a covered entity or business associate creates, receives, maintains, or transmits. Unlike the Privacy Rule, it does not cover PHI in oral or paper form; those forms fall under the Privacy Rule.
Administrative Safeguards
Policies, procedures, and workforce-focused measures such as risk analysis, risk management, security management processes, workforce training, and assignment of security responsibility. These generally form the largest category of Security Rule requirements.
Physical Safeguards
Measures that protect physical access to systems and facilities housing ePHI, including facility access controls, workstation use and security, and device and media controls.
Technical Safeguards
Technology-based controls addressing access control, audit controls, integrity, person or entity authentication, and transmission security for ePHI.
Required vs. Addressable Implementation Specifications
Within the safeguard standards, implementation specifications are labeled required or addressable. Required specifications must be implemented as written. Addressable specifications are not optional; an entity must assess whether the specification is reasonable and appropriate, implement it if so, or document why not and adopt an equivalent alternative where reasonable.
Applicability to Covered Entities and Business Associates
The Security Rule directly obligates covered entities and, following the HITECH Act, business associates. Obligations extend to subcontractors that handle ePHI through business associate agreements rather than through a direct relationship with the covered entity.
Enforcement Authority
The Security Rule is enforced by HHS OCR. Penalties are structured in tiers and adjusted over time; specific amounts should be confirmed against current OCR guidance.

Common questions

Answers to the questions practitioners most commonly ask about Security Rule.

Does the Security Rule protect all protected health information, including paper and oral PHI?
No. The Security Rule applies only to electronic protected health information (ePHI). PHI in paper, oral, or other non-electronic forms falls under the HIPAA Privacy Rule rather than the Security Rule. Covered entities and business associates generally must look to the Privacy Rule for obligations governing PHI in all forms, while the Security Rule specifically addresses the confidentiality, integrity, and availability of ePHI.
If an implementation specification is labeled 'addressable,' does that mean it is optional?
No. 'Addressable' does not mean optional. For an addressable implementation specification, a covered entity or business associate generally must assess whether it is a reasonable and appropriate safeguard in its environment and then either implement it, implement an equivalent alternative measure, or document why it is not reasonable and appropriate. This differs from 'required' implementation specifications, which must be implemented. Both categories reflect obligations that should be evaluated and documented rather than skipped.
What are the main safeguard categories the Security Rule organizes its requirements under?
The Security Rule generally organizes its safeguards into three categories: administrative safeguards, physical safeguards, and technical safeguards. Administrative safeguards typically address policies, workforce training, and risk management processes; physical safeguards address facility and device protections; and technical safeguards address controls such as access and audit mechanisms for ePHI. Within these categories, requirements appear as required or addressable implementation specifications. Readers should verify the specific safeguards against the current regulatory text.
How should an organization begin working toward Security Rule compliance?
A risk analysis is generally treated as a foundational step. Organizations typically identify where ePHI is created, received, maintained, or transmitted, assess potential risks and vulnerabilities to that ePHI, and then implement administrative, physical, and technical safeguards to reduce risks to a reasonable and appropriate level. Documentation of these assessments and decisions is important, particularly for addressable specifications. Approaches vary by organization size and complexity, so specifics should be confirmed against current guidance.
Do business associates have to comply with the Security Rule, or only covered entities?
Business associates are generally subject to Security Rule obligations with respect to ePHI, and these obligations are typically also reflected in business associate agreements. Subcontractors that create, receive, maintain, or transmit ePHI on behalf of a business associate may likewise be subject to obligations that flow through the relevant agreements. Organizations should confirm the precise scope of their obligations based on their defined relationships and current regulatory requirements.
Does achieving HITRUST CSF certification mean an organization has met the Security Rule?
Not by itself. HITRUST is a private organization and the HITRUST CSF is a certifiable control framework; certification is not a legal requirement and does not by itself establish HIPAA Security Rule compliance. While a control framework can help an organization structure and demonstrate its safeguards, Security Rule compliance is assessed under HIPAA as enforced by HHS OCR. Organizations should treat any framework as a supporting tool and verify their obligations against the current regulation.

Common misconceptions

Addressable implementation specifications are optional and can be ignored.
Addressable does not mean optional. An entity must evaluate whether the specification is reasonable and appropriate for its environment and either implement it, adopt a documented equivalent alternative, or document a justification for not doing so.
The Security Rule protects PHI in all forms, including paper records and verbal disclosures.
The Security Rule governs only electronic PHI. PHI in paper, oral, or other non-electronic forms is addressed by the Privacy Rule, not the Security Rule.
Achieving HITRUST CSF certification means an organization is compliant with the Security Rule.
HITRUST is a private organization and the HITRUST CSF is a certifiable control framework, not a legal requirement. Certification may support and demonstrate security efforts but does not by itself establish HIPAA Security Rule compliance, which is determined under HHS OCR enforcement.

Best practices

Conduct and regularly update a risk analysis of ePHI, and use it to drive a documented risk management process, since these are core administrative safeguard requirements.
For each addressable implementation specification, document your assessment of whether it is reasonable and appropriate, and record either the implementation, an equivalent alternative, or a justification for not implementing it.
Map your controls across the administrative, physical, and technical safeguard categories to confirm each standard and required specification is addressed rather than assuming a single category is sufficient.
Ensure business associate agreements flow Security Rule obligations to business associates and their subcontractors that create, receive, maintain, or transmit ePHI.
Verify penalty tiers, deadlines, and specific regulatory citations against current HHS OCR guidance rather than relying on prior figures, as these are adjusted over time.
Treat any HITRUST CSF certification as a complement to, not a substitute for, a direct assessment of Security Rule compliance, and check for additional requirements under the HITECH Act or applicable state law.