HIPAA Security Rule Safeguards

HIPAA Security Rule Overview

The HIPAA Security Rule establishes standards for protecting electronic protected health information (ePHI). It applies to all covered entities and business associates that create, receive, maintain, or transmit ePHI. The rule requires three categories of safeguards: administrative, physical, and technical.

Required vs. Addressable Specifications

TypeObligation
Required (R)Must be implemented as specified - no flexibility
Addressable (A)Must assess whether the specification is reasonable and appropriate. If yes, implement it. If not, document why and implement an equivalent alternative measure, or document why neither the specification nor an alternative is reasonable.

Key point: "Addressable" does not mean "optional." The entity must still address the specification through assessment and documentation.

Administrative Safeguards (Section 164.308)

Administrative safeguards are the policies and procedures designed to manage the selection, development, implementation, and maintenance of security measures. They make up the largest portion of the Security Rule.

StandardKey SpecificationsR/A
Security Management ProcessRisk analysisR
Risk managementR
Sanction policyR
Information system activity reviewR
Assigned Security ResponsibilityDesignate a security officialR
Workforce SecurityAuthorization and/or supervisionA
Workforce clearance procedureA
Termination proceduresA
Information Access ManagementAccess authorizationA
Access establishment and modificationA
Security Awareness and TrainingSecurity remindersA
Protection from malicious softwareA
Log-in monitoringA
Password managementA
Security Incident ProceduresResponse and reportingR
Contingency PlanData backup planR
Disaster recovery planR
Emergency mode operation planR
Testing and revision proceduresA
Applications and data criticality analysisA
EvaluationPeriodic technical and nontechnical evaluationR
Business Associate ContractsWritten contract or arrangementR

Physical Safeguards (Section 164.310)

Physical safeguards are the physical measures, policies, and procedures to protect electronic information systems, buildings, and equipment from natural and environmental hazards and unauthorized intrusion.

StandardKey SpecificationsR/A
Facility Access ControlsContingency operationsA
Facility security planA
Access control and validation proceduresA
Maintenance recordsA
Workstation UsePolicies for proper workstation useR
Workstation SecurityPhysical safeguards restricting access to workstationsR
Device and Media ControlsDisposalR
Media re-useR
Accountability (tracking hardware/media)A
Data backup and storageA

Technical Safeguards (Section 164.312)

Technical safeguards are the technology, policies, and procedures used to protect ePHI and control access to it.

StandardKey SpecificationsR/A
Access ControlUnique user identificationR
Emergency access procedureR
Automatic logoffA
Encryption and decryptionA
Audit ControlsHardware, software, and procedural mechanisms to record and examine activityR
IntegrityMechanism to authenticate ePHIA
Person or Entity AuthenticationProcedures to verify identity of person or entity seeking accessR
Transmission SecurityIntegrity controlsA
EncryptionA

Risk Analysis Requirements

The risk analysis is a required administrative safeguard and a foundational element of the Security Rule. It involves:

  • Scope: Identify all ePHI the organization creates, receives, maintains, or transmits
  • Threats: Identify and document reasonably anticipated threats to ePHI
  • Vulnerabilities: Identify and document vulnerabilities that could be exploited by threats
  • Current controls: Assess the effectiveness of existing security measures
  • Likelihood and impact: Determine the likelihood and potential impact of threat occurrence
  • Risk level: Assign risk levels based on the combined likelihood and impact
  • Documentation: Maintain documentation of the risk analysis process and findings

Organizational Requirements

  • Business Associate Agreements (BAAs): Must be in place before sharing ePHI with business associates
  • Group health plan requirements: Plan documents must incorporate safeguard provisions
  • Policies and procedures: Must be maintained in written form (electronic or paper) for 6 years from date of creation or last effective date

Key Exam Tips

  • The Security Rule applies only to ePHI, while the Privacy Rule applies to all forms of PHI
  • A security official must be designated - this is a required specification
  • Encryption is addressable, not required, under both access control and transmission security
  • The contingency plan must include data backup, disaster recovery, and emergency mode operation plans - all three are required
  • Risk analysis must be performed regularly - it is not a one-time event

Ready to Start Studying?

Access 500+ flashcards, 30 mini exams, and 7 full-length practice exams.

Get Started Free

RHIApractice is not affiliated with or endorsed by AHIMA or Pearson VUE.