Auditen
Home / Frameworks / HIPAA / The Security Rule
HIPAA · 164.302–318

The Security Rule

The Security Rule requires covered entities and business associates to implement national standards to protect the confidentiality, integrity, and availability of electronic protected health information (ePHI). It mandates a combination of administrative, physical, and technical safeguards to ensure that ePHI is secure from unauthorized access or alteration.

What it means

Unlike the Privacy Rule, which covers all forms of PHI, the Security Rule applies specifically to electronic data. Its intent is to provide a flexible framework that allows organizations to scale their security measures based on their specific size, complexity, and risk profile.

In practice, this means an organization must not only implement technical tools (like firewalls) but also organizational processes (like training and auditing). The rule distinguishes between "required" specifications, which must be implemented exactly as stated, and "addressable" specifications, which must be implemented if they are reasonable and appropriate for the environment.

How to meet it

Evidence an auditor asks for

  • The most recent Risk Analysis report and a corresponding Risk Remediation Plan showing how identified gaps were closed.
  • Documentation of security awareness training, including timestamps and signed acknowledgments from employees.
  • User access lists and evidence of periodic "access reviews" to prove that permissions are revoked when staff leave or change roles.
  • Technical configuration screenshots proving encryption is enabled on databases, mobile devices, and communication channels.
  • A complete inventory of hardware and software assets that touch ePHI.

Common pitfalls

  • Treating "addressable" requirements as optional; if an addressable control is not implemented, the organization must document why it was not reasonable and what alternative measure was used.
  • Performing a risk assessment once at startup rather than treating it as a living process that updates when new software or hardware is added.
  • Maintaining "shelfware"—policies that exist in a manual but are not reflected in the actual technical configuration of the systems.