Purpose of the Security Rule
While the Privacy Rule governs PHI in any form, the HIPAA Security Rule specifically protects electronic protected health information, or ePHI. RHIA candidates must know that the Security Rule organizes requirements into three safeguard categories: administrative, physical, and technical, and that each category contains both required and addressable implementation specifications.
Administrative Safeguards
These are the policies and procedures that manage the selection, development, and maintenance of security measures. Key elements include a designated security officer, a risk analysis and risk management process, workforce training, sanction policies for violations, and contingency planning for emergencies such as system outages or natural disasters. The risk analysis is widely regarded as the foundational requirement, since it drives every other security decision.
Physical Safeguards
Physical safeguards protect the actual hardware and facilities that store or access ePHI. This includes facility access controls, workstation use and security policies, and device and media controls governing the disposal and reuse of hardware. A common exam scenario involves an old server being discarded without proper data destruction, which violates device and media control requirements.
Technical Safeguards
Technical safeguards involve the technology and policies that protect ePHI and control access to it. Core components include access control through unique user identification, audit controls that record and examine system activity, integrity controls to prevent improper alteration or destruction of data, and transmission security to protect ePHI sent over networks, typically through encryption.
Required vs. Addressable Specifications
A frequently misunderstood concept is that "addressable" does not mean optional. A covered entity must assess whether an addressable specification is reasonable and appropriate given its environment, and if it decides not to implement it, must document the rationale and implement an equivalent alternative measure if one is reasonable.
Breach Risk and Encryption
Encryption is addressable under the Security Rule but functions as a safe harbor under the Breach Notification Rule. If ePHI is properly encrypted and a device is lost or stolen, the incident is generally not considered a reportable breach because the data is rendered unusable to unauthorized parties.
Exam Tip
When a scenario describes a specific safeguard failure, first determine whether it is administrative, physical, or technical before selecting an answer. Audit trail failures point to technical safeguards, workforce training gaps point to administrative safeguards, and lost devices in unlocked areas point to physical safeguards.