Skip to content
Bellator Cyber Guard
45 CFR Part 164

The HIPAA Security Rule in Plain Language

The Security Rule protects electronic patient data through specific technical, administrative, and physical safeguards. Here is what it actually requires — without the legalese.

18
Standards in the Security Rule
36
Implementation Specifications
100%
Covered Entities Must Comply

Technical Safeguards — What Your Systems Must Do

These are the technology measures required to protect electronic PHI.

Access Controls

Unique user IDs, emergency access procedures, automatic logoff, and encryption/decryption. Every user must have their own login — no shared accounts.

Audit Controls

Hardware, software, and procedural mechanisms to record and examine activity in systems containing ePHI. You must be able to show who accessed what and when.

Integrity Controls

Policies and procedures to protect ePHI from improper alteration or destruction. Includes mechanisms to authenticate that data has not been tampered with.

Transmission Security

Technical security measures to guard against unauthorized access to ePHI being transmitted over a network. Encryption is addressable but strongly recommended.

Administrative Safeguards — Your Policies & People

The largest category — covering your security program, workforce, and risk management.

Security Management Process

Risk analysis, risk management, sanctions for violations, and information system activity review. The foundation of your HIPAA compliance program.

Workforce Security

Authorization and supervision procedures, workforce clearance, and termination procedures. Ensuring only authorized personnel access ePHI.

Information Access Management

Access authorization, access establishment and modification policies. Role-based access controls for your EHR and patient data systems.

Security Awareness Training

Security reminders, protection from malicious software, login monitoring, and password management training for all workforce members.

Contingency Planning

Data backup plan, disaster recovery plan, emergency mode operation plan. What happens when systems go down — planned and unplanned.

Security Rule FAQ

Required specifications must be implemented as stated — there is no flexibility. Addressable specifications must be assessed: if the specification is reasonable and appropriate for your environment, you must implement it. If not, you must document why and implement an equivalent alternative measure. Addressable does not mean optional.

No. The HIPAA Security Rule applies exclusively to electronic protected health information (ePHI). Paper records are covered by the Privacy Rule. However, most practices today handle nearly all patient data electronically, so the Security Rule applies broadly across EHR systems, billing, scheduling, imaging, and communication platforms.

No. While reputable EHR vendors implement security controls on their platforms, HIPAA compliance is a shared responsibility. You are responsible for how your practice accesses the system, who has credentials, how devices are secured, and how data is handled outside the EHR. A signed Business Associate Agreement with your vendor is required but does not make you compliant.

From requirement to defensible practice

Turn HIPAA requirements into safeguards that fit patient care

A useful compliance path makes the obligation clear, identifies the evidence to retain, and connects written policy to the safeguards used every day.

  • Know what applies
  • Document the evidence
  • Make the safeguard operational

A defensible path

  1. 01

    Confirm the requirement

    Separate what is required from recommendations and vendor language.

  2. 02

    Map it to your environment

    Connect the rule to people, devices, data, vendors, and current procedures.

  3. 03

    Close and document the gaps

    Prioritize changes and keep evidence that the process is being followed.

People also look for

Keep exploring HIPAA security

Connect HIPAA requirements to the safeguards, assessments, and everyday decisions a healthcare practice can actually implement.