HIPAA Security Rule Safeguards: Administrative, Physical, and Technical

Purpose of the Security Rule

While the Privacy Rule governs PHI in any form, the HIPAA Security Rule specifically protects electronic protected health information, or ePHI. RHIA candidates must know that the Security Rule organizes requirements into three safeguard categories: administrative, physical, and technical, and that each category contains both required and addressable implementation specifications.

Administrative Safeguards

These are the policies and procedures that manage the selection, development, and maintenance of security measures. Key elements include a designated security officer, a risk analysis and risk management process, workforce training, sanction policies for violations, and contingency planning for emergencies such as system outages or natural disasters. The risk analysis is widely regarded as the foundational requirement, since it drives every other security decision.

Physical Safeguards

Physical safeguards protect the actual hardware and facilities that store or access ePHI. This includes facility access controls, workstation use and security policies, and device and media controls governing the disposal and reuse of hardware. A common exam scenario involves an old server being discarded without proper data destruction, which violates device and media control requirements.

Technical Safeguards

Technical safeguards involve the technology and policies that protect ePHI and control access to it. Core components include access control through unique user identification, audit controls that record and examine system activity, integrity controls to prevent improper alteration or destruction of data, and transmission security to protect ePHI sent over networks, typically through encryption.

Required vs. Addressable Specifications

A frequently misunderstood concept is that "addressable" does not mean optional. A covered entity must assess whether an addressable specification is reasonable and appropriate given its environment, and if it decides not to implement it, must document the rationale and implement an equivalent alternative measure if one is reasonable.

Breach Risk and Encryption

Encryption is addressable under the Security Rule but functions as a safe harbor under the Breach Notification Rule. If ePHI is properly encrypted and a device is lost or stolen, the incident is generally not considered a reportable breach because the data is rendered unusable to unauthorized parties.

Exam Tip

When a scenario describes a specific safeguard failure, first determine whether it is administrative, physical, or technical before selecting an answer. Audit trail failures point to technical safeguards, workforce training gaps point to administrative safeguards, and lost devices in unlocked areas point to physical safeguards.

Ready to Start Studying?

Access 500+ flashcards, 30 mini exams, and 7 full-length practice exams.

Get Started Free

RHIApractice is not affiliated with or endorsed by AHIMA or Pearson VUE.