Skip to main content
Category: Regulatory Framework

Security Standards for the Protection of ePHI

Also known as: HIPAA Security Rule, Security Rule, Security Standards for the Protection of Electronic Protected Health Information
Simply put

The Security Standards for the Protection of ePHI, commonly called the HIPAA Security Rule, are federal standards that require certain healthcare organizations and their vendors to safeguard electronic health information. They call for administrative, physical, and technical protections aimed at keeping electronic protected health information (ePHI) confidential, accurate, and available. Unlike the broader HIPAA Privacy Rule, these standards apply only to health information in electronic form, not to paper or spoken information.

Formal definition

The Security Standards for the Protection of ePHI are the set of HIPAA standards, developed and enforced by HHS, that establish requirements for protecting the confidentiality, integrity, and availability of electronic protected health information (ePHI). The Rule organizes its requirements into three safeguard categories, administrative, physical, and technical, and its implementation specifications are designated as either required or addressable; addressable does not mean optional, but rather that a regulated party must assess whether a specification is reasonable and appropriate and, if not, document that determination and implement an equivalent alternative where reasonable. Its scope is limited to ePHI and is narrower than the HIPAA Privacy Rule, which covers PHI in all forms including oral and paper. The Rule applies to covered entities and to business associates; as of the applicable regulatory text, subcontractors that create, receive, maintain, or transmit ePHI are themselves business associates and are directly subject to the Security Rule, in addition to any obligations imposed through business associate agreements. Compliance with these standards does not by itself satisfy other HIPAA rules, and state law or the HITECH Act may impose additional requirements; readers should verify specific citations, safeguard designations, and current guidance against the applicable regulation.

Why it matters

Electronic protected health information sits at the center of nearly every modern healthcare operation, from electronic health records to billing systems and cloud-hosted analytics. The Security Standards for the Protection of ePHI establish the federal baseline for keeping that information confidential, accurate, and available. Because the Rule is limited to ePHI, it works alongside, rather than in place of, the broader HIPAA Privacy Rule, which covers protected health information in all forms including paper and oral communications. Understanding that boundary matters: satisfying the Security Rule does not by itself demonstrate compliance with the Privacy Rule, the Breach Notification Rule, or other HIPAA requirements.

The Rule's reach is broad in terms of who must comply. It applies to covered entities and to business associates, and as of the applicable regulatory text, subcontractors that create, receive, maintain, or transmit ePHI are themselves business associates directly subject to the Security Rule, not merely bound through a business associate agreement. This means obligations flow down the vendor chain by operation of law, and organizations cannot assume that responsibility stops at their first-tier vendors. Compliance officers should map where ePHI lives across their vendor relationships and confirm that downstream parties understand their direct regulatory exposure.

Beyond the legal framework, the Rule matters because it structures how organizations reason about risk. Its emphasis on the confidentiality, integrity, and availability of ePHI pushes regulated parties to consider not only unauthorized disclosure but also data corruption and loss of access. No set of safeguards guarantees compliance or prevents all breaches, and readers should note that state law and the HITECH Act may impose additional requirements. Specific safeguard designations, penalty tiers, and citations are adjusted over time and should be verified against current HHS guidance and the applicable regulation.

Who it's relevant to

Security and Privacy Officers at Covered Entities
These officers are typically responsible for implementing and maintaining the administrative, physical, and technical safeguards required for ePHI, including conducting risk analysis and documenting decisions about addressable implementation specifications. They should coordinate Security Rule work with Privacy Rule obligations, since compliance with one does not establish compliance with the other.
Business Associates and Their Subcontractors
Business associates that handle ePHI are directly subject to the Security Rule. As of the applicable regulatory text, subcontractors that create, receive, maintain, or transmit ePHI are themselves business associates and are directly regulated, not merely bound through a business associate agreement. Vendors down the chain should confirm their own direct obligations and not assume responsibility ends with a contractual pass-through.
Compliance Officers and Auditors
These professionals assess whether an organization's safeguards align with the Security Rule and whether decisions on addressable specifications are properly documented. They should keep the Rule's ePHI-only scope in view and verify safeguard designations, penalty considerations, and citations against current HHS guidance, since figures and designations are adjusted over time.
IT and Security Engineering Teams
Teams that build and operate systems handling ePHI implement the technical safeguards contemplated by the Rule, such as access controls, audit mechanisms, and transmission protections. While practices like encryption and continuous monitoring can support compliance, no single control guarantees compliance or prevents all breaches, and technical measures should be tied back to a documented risk-based approach.
Legal Counsel Advising Healthcare Organizations
Counsel should distinguish Security Rule obligations from those of the Privacy, Breach Notification, and Enforcement Rules, and advise clients on how obligations attach to covered entities, business associates, and subcontractors. They should also flag that state law and the HITECH Act may impose additional requirements beyond the federal Security Rule.

Inside Security Standards for the Protection of ePHI

Scope Limited to ePHI
The Security Rule (Security Standards for the Protection of ePHI) governs only protected health information that is created, received, maintained, or transmitted in electronic form. PHI in oral or paper form falls under the Privacy Rule, not the Security Rule. Practitioners should not treat the Security Rule as covering all forms of PHI.
Administrative Safeguards
Policies, procedures, and workforce-focused measures such as security management processes, risk analysis and risk management, workforce training, and contingency planning. These generally form the largest category of Security Rule standards and address how an organization manages its security program.
Physical Safeguards
Controls addressing the physical protection of electronic information systems and related facilities and equipment, such as facility access controls, workstation use and security, and device and media controls.
Technical Safeguards
Technology-based controls addressing access to and protection of ePHI, such as access controls, audit controls, integrity controls, authentication of persons or entities, and transmission security.
Required vs. Addressable Implementation Specifications
Each standard may include implementation specifications designated as required or addressable. Required specifications must be implemented. Addressable specifications are not optional; an entity must assess whether the specification is reasonable and appropriate, and if not, implement an equivalent alternative or document why the specification is not reasonable and appropriate. Readers should verify specific designations against the current regulatory text.
Flexibility and Scalability
The Security Rule is generally designed to be technology-neutral and scalable, allowing covered entities and business associates to consider their size, complexity, capabilities, technical infrastructure, and the costs and risks involved when determining how to meet the standards.
Regulated Parties
The Security Rule applies to covered entities and to business associates. Since the 2013 Omnibus Rule, any subcontractor that creates, receives, maintains, or transmits ePHI on behalf of a business associate is itself a business associate and is directly subject to the Security Rule. Business associate agreements document and flow down obligations, but subcontractors are directly regulated, not merely bound by contract.
Enforcement Authority
The Security Rule is enforced by HHS OCR. Penalty tiers and amounts are adjusted over time and should be confirmed against current HHS guidance. State law or the HITECH Act may impose additional requirements beyond the federal Security Rule.

Common questions

Answers to the questions practitioners most commonly ask about Security Standards for the Protection of ePHI.

Does the Security Rule apply to all forms of protected health information, including paper and oral PHI?
No. The Security Rule applies only to electronic protected health information (ePHI), PHI that a covered entity or business associate creates, receives, maintains, or transmits in electronic form. PHI in oral, paper, or other non-electronic forms is generally addressed by the HIPAA Privacy Rule rather than the Security Rule. If you are concerned with safeguarding spoken conversations or paper records, those obligations flow primarily from the Privacy Rule, though the two rules often work together in practice.
Are business associates and their subcontractors regulated directly by the Security Rule, or only through contracts?
Both business associates and their subcontractors are directly subject to the Security Rule, not merely bound through contracts. Since the 2013 Omnibus Rule, any subcontractor that creates, receives, maintains, or transmits ePHI on behalf of a business associate is itself a business associate and is directly obligated to comply with the Security Rule. Business associate agreements remain required to establish and document these relationships, but the compliance obligations attach directly by regulation, not solely by contract. This means a subcontractor can face direct HHS OCR enforcement for Security Rule violations. Readers should verify the specific requirements against the current regulatory text.
How do we decide what safeguards to implement to meet the Security Rule's standards?
The Security Rule is generally intended to be scalable and flexible. Its standards are organized into administrative, physical, and technical safeguard categories, and each standard includes implementation specifications that are either required or addressable. In most cases, entities begin with a thorough risk analysis to identify the risks and vulnerabilities to their ePHI, then implement safeguards reasonable and appropriate to their size, complexity, and technical environment. The current regulation should be consulted for the full set of standards and specifications applicable to your situation.
What does 'addressable' mean for an implementation specification, can we skip it?
Addressable does not mean optional. For an addressable implementation specification, an entity must assess whether it is a reasonable and appropriate safeguard in its environment. If it is, the entity implements it. If it is not, the entity generally must document why, and implement an equivalent alternative measure where reasonable and appropriate. This assessment and its rationale should typically be documented. Simply ignoring an addressable specification without analysis would generally not satisfy the rule.
How does the required risk analysis fit into meeting these standards?
A risk analysis is generally treated as a foundational activity underpinning the entire Security Rule. It typically involves identifying where ePHI is created, received, maintained, or transmitted, and assessing the potential risks and vulnerabilities to its confidentiality, integrity, and availability. The results generally inform which safeguards and implementation specifications are reasonable and appropriate, and how addressable specifications should be handled. Risk analysis is generally viewed as an ongoing process rather than a one-time exercise, and readers should confirm current expectations against applicable guidance.
Does achieving HITRUST CSF certification mean we have satisfied these Security Rule standards?
Not by itself. HITRUST is a private organization, and the HITRUST CSF is a certifiable control framework that can help organizations structure and demonstrate their security controls, but HITRUST certification is not a legal requirement and does not by itself establish HIPAA Security Rule compliance. HIPAA is enforced by HHS OCR, which does not treat any certification as conclusive proof of compliance. Certification may support your compliance efforts, but you remain responsible for meeting the Security Rule's standards directly. Note also that the HITECH Act and state laws may impose additional requirements beyond the Security Rule; verify against the current regulation and the current HITRUST CSF version.

Common misconceptions

The Security Rule protects all protected health information, including paper records and spoken conversations.
The Security Rule applies only to ePHI. Protection of PHI in oral, paper, and other non-electronic forms is generally governed by the Privacy Rule. Organizations should not rely on Security Rule compliance to satisfy Privacy Rule obligations.
Addressable implementation specifications are optional and can be skipped.
Addressable does not mean optional. An entity must evaluate whether the specification is reasonable and appropriate for its environment and either implement it, implement a documented equivalent alternative, or document a justification for not implementing it where it is not reasonable and appropriate.
Subcontractors that handle ePHI are only bound by contract and are not directly regulated by the Security Rule.
Since the 2013 Omnibus Rule, a subcontractor that creates, receives, maintains, or transmits ePHI on behalf of a business associate is itself a business associate and is directly subject to the Security Rule and to HHS OCR enforcement. Business associate agreements document these obligations but do not replace direct regulatory liability.

Best practices

Conduct and periodically update a documented, enterprise-wide risk analysis of ePHI, and use it to drive risk management decisions across administrative, physical, and technical safeguards.
Treat addressable implementation specifications deliberately: document your assessment of each, and record either the implemented control, an equivalent alternative, or a written justification for not implementing it.
Map exactly where ePHI is created, received, maintained, and transmitted, and ensure that all business associates and their subcontractors handling ePHI are identified and covered by appropriate business associate agreements, recognizing that subcontractors are directly subject to the Security Rule.
Keep Security Rule efforts distinct from Privacy Rule efforts, and confirm that PHI in oral and paper form is separately addressed under the Privacy Rule.
Maintain current documentation of policies, procedures, and safeguard decisions, and retain it as evidence for potential HHS OCR review, verifying retention requirements against current regulatory guidance.
Confirm current penalty tiers, deadlines, and any additional obligations under state law, the HITECH Act, or frameworks such as the HITRUST CSF, remembering that HITRUST certification does not by itself establish HIPAA compliance.