HIPAA Security Rule
What the HIPAA Security Rule requires for electronic protected health information: administrative, physical and technical safeguards, required vs addressable specifications, and the risk analysis behind them.
HIPAA Security Rule at a glance
The HIPAA Security Rule (45 CFR Part 164, Subpart C) requires covered entities and business associates to protect the confidentiality, integrity and availability of electronic protected health information with administrative, physical and technical safeguards. Safeguards are chosen based on a documented risk analysis and the organization's size and resources. Some implementation specifications are required; others, like encryption, are addressable — implement them or document an equivalent alternative.
| Where | 45 CFR Part 164, Subpart C (164.302–164.318) |
|---|---|
| Applies to | Electronic PHI only |
| Safeguards | Administrative (164.308), physical (164.310), technical (164.312) |
| Starting point | A documented security risk analysis |
| Addressable ≠ optional | Implement, or document why not and use an equivalent measure |
| Status of update | Major revision proposed January 2025; not final as of October 2026 |
The structure
| Section | Safeguards | Examples |
|---|---|---|
| 164.308 | Administrative | Risk analysis, risk management, sanctions, training, incident procedures, contingency plan, BAAs |
| 164.310 | Physical | Facility access, workstation use and security, device and media controls |
| 164.312 | Technical | Access control, audit controls, integrity, authentication, transmission security and encryption |
| 164.314 | Organizational | Business associate contracts |
| 164.316 | Policies and documentation | Written policies, six-year retention, periodic review |
Flexible by design
Organizations may use any security measures that reasonably and appropriately implement the standards, considering their size, complexity, technical capabilities, costs and risks (164.306(b)). That flexibility only works with a written risk analysis behind each decision.
Required vs addressable
Required specifications must be implemented. Addressable ones — such as encryption and automatic logoff — must be implemented if reasonable and appropriate; otherwise you document why and implement an equivalent alternative measure if that is reasonable and appropriate (164.306(d)).
A proposed update
HHS proposed a major revision in January 2025 that would make most specifications required, including encryption and multi-factor authentication. As of October 2026 it has not been finalized, so the current rule above still applies. We will log changes in Updates.
Requirements explained
- Access control and sign-in →§ 164.312(a)(1)Only the right people should reach ePHI, each under their own account, with a reliable way to confirm who is signing in. In practice: unique user accounts, strong authentication such as MFA, and automatic logoff.
- Audit controls and activity logs →§ 164.312(b)Systems holding ePHI must record activity so you can review who accessed what. When choosing a tool, check that you — not only the vendor — can see sign-ins and access to records, and for how long.
- Encryption of ePHI →§ 164.312(a)(2)(iv)Encryption is "addressable", not optional: you either encrypt ePHI at rest and in transit, or document why not and use an equivalent safeguard. For email and cloud tools, encrypting is almost always the reasonable choice.
- HIPAA policies and procedures →§ 164.316What written policies and procedures HIPAA requires, how to keep them current, and how long to keep them — for small practices and business associates.
- Security risk analysis →§ 164.308(a)(1)(ii)(A)Every covered entity and business associate must document an accurate and thorough assessment of risks to the ePHI it holds — and then act on it. It is one of the most commonly missing pieces of HIPAA compliance, including in small practices.
Frequently asked questions
What are the three types of safeguards in the Security Rule?
Administrative safeguards (policies, risk analysis, training, contingency planning), physical safeguards (facility access, workstation and device security) and technical safeguards (access control, audit controls, integrity, authentication, transmission security).
Does the Security Rule apply to paper records?
No. It applies to electronic PHI. Paper and spoken PHI are protected by the Privacy Rule's safeguards requirement.
Is the HIPAA Security Rule changing?
HHS proposed a major update in January 2025 that would remove the addressable distinction and add specific requirements such as encryption and MFA. As of October 2026 it has not been finalized.