HIPAA Security Rule Overview
The HIPAA Security Rule establishes standards for protecting electronic protected health information (ePHI). It applies to all covered entities and business associates that create, receive, maintain, or transmit ePHI. The rule requires three categories of safeguards: administrative, physical, and technical.
Required vs. Addressable Specifications
| Type | Obligation |
|---|---|
| Required (R) | Must be implemented as specified - no flexibility |
| Addressable (A) | Must assess whether the specification is reasonable and appropriate. If yes, implement it. If not, document why and implement an equivalent alternative measure, or document why neither the specification nor an alternative is reasonable. |
Key point: "Addressable" does not mean "optional." The entity must still address the specification through assessment and documentation.
Administrative Safeguards (Section 164.308)
Administrative safeguards are the policies and procedures designed to manage the selection, development, implementation, and maintenance of security measures. They make up the largest portion of the Security Rule.
| Standard | Key Specifications | R/A |
|---|---|---|
| Security Management Process | Risk analysis | R |
| Risk management | R | |
| Sanction policy | R | |
| Information system activity review | R | |
| Assigned Security Responsibility | Designate a security official | R |
| Workforce Security | Authorization and/or supervision | A |
| Workforce clearance procedure | A | |
| Termination procedures | A | |
| Information Access Management | Access authorization | A |
| Access establishment and modification | A | |
| Security Awareness and Training | Security reminders | A |
| Protection from malicious software | A | |
| Log-in monitoring | A | |
| Password management | A | |
| Security Incident Procedures | Response and reporting | R |
| Contingency Plan | Data backup plan | R |
| Disaster recovery plan | R | |
| Emergency mode operation plan | R | |
| Testing and revision procedures | A | |
| Applications and data criticality analysis | A | |
| Evaluation | Periodic technical and nontechnical evaluation | R |
| Business Associate Contracts | Written contract or arrangement | R |
Physical Safeguards (Section 164.310)
Physical safeguards are the physical measures, policies, and procedures to protect electronic information systems, buildings, and equipment from natural and environmental hazards and unauthorized intrusion.
| Standard | Key Specifications | R/A |
|---|---|---|
| Facility Access Controls | Contingency operations | A |
| Facility security plan | A | |
| Access control and validation procedures | A | |
| Maintenance records | A | |
| Workstation Use | Policies for proper workstation use | R |
| Workstation Security | Physical safeguards restricting access to workstations | R |
| Device and Media Controls | Disposal | R |
| Media re-use | R | |
| Accountability (tracking hardware/media) | A | |
| Data backup and storage | A |
Technical Safeguards (Section 164.312)
Technical safeguards are the technology, policies, and procedures used to protect ePHI and control access to it.
| Standard | Key Specifications | R/A |
|---|---|---|
| Access Control | Unique user identification | R |
| Emergency access procedure | R | |
| Automatic logoff | A | |
| Encryption and decryption | A | |
| Audit Controls | Hardware, software, and procedural mechanisms to record and examine activity | R |
| Integrity | Mechanism to authenticate ePHI | A |
| Person or Entity Authentication | Procedures to verify identity of person or entity seeking access | R |
| Transmission Security | Integrity controls | A |
| Encryption | A |
Risk Analysis Requirements
The risk analysis is a required administrative safeguard and a foundational element of the Security Rule. It involves:
- Scope: Identify all ePHI the organization creates, receives, maintains, or transmits
- Threats: Identify and document reasonably anticipated threats to ePHI
- Vulnerabilities: Identify and document vulnerabilities that could be exploited by threats
- Current controls: Assess the effectiveness of existing security measures
- Likelihood and impact: Determine the likelihood and potential impact of threat occurrence
- Risk level: Assign risk levels based on the combined likelihood and impact
- Documentation: Maintain documentation of the risk analysis process and findings
Organizational Requirements
- Business Associate Agreements (BAAs): Must be in place before sharing ePHI with business associates
- Group health plan requirements: Plan documents must incorporate safeguard provisions
- Policies and procedures: Must be maintained in written form (electronic or paper) for 6 years from date of creation or last effective date
Key Exam Tips
- The Security Rule applies only to ePHI, while the Privacy Rule applies to all forms of PHI
- A security official must be designated - this is a required specification
- Encryption is addressable, not required, under both access control and transmission security
- The contingency plan must include data backup, disaster recovery, and emergency mode operation plans - all three are required
- Risk analysis must be performed regularly - it is not a one-time event