hipaa.systems
Rule overview · 45 CFR 164.302–164.318

HIPAA Security Rule

What the HIPAA Security Rule requires for electronic protected health information: administrative, physical and technical safeguards, required vs addressable specifications, and the risk analysis behind them.

Checked 2026-10-06Requirements 5

HIPAA Security Rule at a glance

The HIPAA Security Rule (45 CFR Part 164, Subpart C) requires covered entities and business associates to protect the confidentiality, integrity and availability of electronic protected health information with administrative, physical and technical safeguards. Safeguards are chosen based on a documented risk analysis and the organization's size and resources. Some implementation specifications are required; others, like encryption, are addressable — implement them or document an equivalent alternative.

Where45 CFR Part 164, Subpart C (164.302–164.318)
Applies toElectronic PHI only
SafeguardsAdministrative (164.308), physical (164.310), technical (164.312)
Starting pointA documented security risk analysis
Addressable ≠ optionalImplement, or document why not and use an equivalent measure
Status of updateMajor revision proposed January 2025; not final as of October 2026

The structure

Section Safeguards Examples
164.308 Administrative Risk analysis, risk management, sanctions, training, incident procedures, contingency plan, BAAs
164.310 Physical Facility access, workstation use and security, device and media controls
164.312 Technical Access control, audit controls, integrity, authentication, transmission security and encryption
164.314 Organizational Business associate contracts
164.316 Policies and documentation Written policies, six-year retention, periodic review

Flexible by design

Organizations may use any security measures that reasonably and appropriately implement the standards, considering their size, complexity, technical capabilities, costs and risks (164.306(b)). That flexibility only works with a written risk analysis behind each decision.

Required vs addressable

Required specifications must be implemented. Addressable ones — such as encryption and automatic logoff — must be implemented if reasonable and appropriate; otherwise you document why and implement an equivalent alternative measure if that is reasonable and appropriate (164.306(d)).

A proposed update

HHS proposed a major revision in January 2025 that would make most specifications required, including encryption and multi-factor authentication. As of October 2026 it has not been finalized, so the current rule above still applies. We will log changes in Updates.

Requirements explained

Frequently asked questions

What are the three types of safeguards in the Security Rule?

Administrative safeguards (policies, risk analysis, training, contingency planning), physical safeguards (facility access, workstation and device security) and technical safeguards (access control, audit controls, integrity, authentication, transmission security).

Does the Security Rule apply to paper records?

No. It applies to electronic PHI. Paper and spoken PHI are protected by the Privacy Rule's safeguards requirement.

Is the HIPAA Security Rule changing?

HHS proposed a major update in January 2025 that would remove the addressable distinction and add specific requirements such as encryption and MFA. As of October 2026 it has not been finalized.