What the Security Rule covers
The HIPAA Security Rule is a US federal regulation administered by the Department of Health and Human Services (HHS). It sets national standards for protecting electronic protected health information (ePHI) that an organization creates, receives, maintains or transmits. It applies to covered entities (health plans, health care clearinghouses and health care providers that conduct certain transactions electronically) and to their business associates.
The rule is flexible by design. Each organization chooses safeguards that are reasonable for its size, systems and risks, based on a documented risk analysis. HHS does not certify organizations as HIPAA compliant. Organizations show their position through their risk analysis, policies, safeguards and records, and the HHS Office for Civil Rights (OCR) can review these during an investigation or audit.
Key requirements
Risk analysis
An accurate and thorough assessment of risks and vulnerabilities to the confidentiality, integrity and availability of ePHI. It is a required implementation specification and the basis for other decisions.
Risk management
Security measures that reduce the risks found in the analysis to a reasonable and appropriate level, with the decisions documented.
Three safeguard categories
Administrative, physical and technical safeguards. Each standard has implementation specifications marked required or addressable.
Required and addressable
Addressable does not mean optional. The organization implements the specification, an equivalent alternative, or documents why neither is reasonable and appropriate.
Business associates
Vendors that handle ePHI on behalf of a covered entity must comply with the Security Rule and sign a business associate agreement.
Breach Notification Rule
After a breach of unsecured protected health information, notice goes to affected individuals, to HHS and in some cases to the media. Business associates notify the covered entity.
Documentation
Policies, procedures and required records are kept for six years from creation or the date last in effect, whichever is later.
How the work runs with us
We identify where ePHI is created, received, stored and sent: applications, endpoints, cloud services, backups and vendors. We confirm whether your organization acts as a covered entity, a business associate or both, based on your counsel's view. You receive a scope statement, a data flow map and a plan with dates.
We perform or update the security risk analysis and compare current safeguards with each Security Rule standard and implementation specification. Each gap is recorded with its risk, the systems affected and the effort to close it.
We turn the findings into a prioritized risk management plan. Our engineers implement or improve technical safeguards such as access control, audit logging, encryption and backups. We update policies and procedures where needed, for review by your privacy and security officers and counsel.
We organize evidence by standard so your team can answer customer questionnaires, OCR requests or an external assessment. We test selected safeguards and can support your team during a review. Retainers are available for yearly risk analysis updates and ongoing support.
What you receive
Each engagement has a fixed scope agreed in writing. The deliverables below are typical. The exact set depends on your scope.
Risk analysis
- ePHI inventory and data flow map
- Threats, vulnerabilities and likelihood ratings
- Risk register with owners
Gap assessment
- Status for each Security Rule standard
- Notes on addressable specifications
- Gaps ranked by risk
Remediation and policy
- Prioritized risk management plan
- Safeguards implemented by our engineers
- Updated policies and procedures for your review
Evidence
- Evidence organized by standard
- Safeguard test results
- Summary for leadership and customers
Safeguards we help implement
These areas map to Security Rule standards. We work inside your existing systems where possible.
Access control and identity
Unique user IDs, multi-factor authentication, role-based access, emergency access and automatic logoff. We can deploy Keycloak privately where it fits.
Audit logging and monitoring
Logs that record activity in systems holding ePHI, with regular review. We can deploy Wazuh privately where it fits.
Encryption
Encryption of ePHI at rest and in transit, with key management recorded. Encryption also affects whether data counts as unsecured under the Breach Notification Rule.
Vulnerability management
Scanning, patching and secure configuration for systems in scope. Penetration testing can confirm results.
Incident response
Security incident procedures linked to breach assessment steps. We also offer incident response training.
Backup and contingency
Data backup, disaster recovery and emergency mode operation plans, with restore tests.
Vendor risk
Inventory of vendors that handle ePHI, security review steps and tracking of business associate agreements.
Device and media controls
Tracking of devices and media that hold ePHI, with secure reuse and disposal.
Security Rule safeguard categories
Selected standards in each category, with examples of how organizations meet them.
| Category | Example standards | Typical controls |
|---|---|---|
| Administrative | Security management process, assigned security responsibility, workforce security, security awareness and training, security incident procedures, contingency plan, evaluation | Risk analysis, named security official, onboarding and offboarding steps, training records, incident plan, periodic evaluation |
| Physical | Facility access controls, workstation use, workstation security, device and media controls | Badge access, screen locks, asset tracking, secure disposal of drives |
| Technical | Access control, audit controls, integrity, person or entity authentication, transmission security | Single sign-on with MFA, central logging, file integrity checks, TLS for data in transit |
Who does what
We scope systems and data flows, perform the risk analysis, implement agreed technical safeguards, draft or update policies, organize evidence and test controls. Your team appoints the security official, approves risk decisions, runs safeguards day to day and keeps records current.
We are not a law firm and do not give legal advice. Questions such as whether your organization is a covered entity or business associate, whether an incident is a reportable breach, or what a business associate agreement must say belong with your legal counsel and privacy officer. HHS does not issue HIPAA certifications, and neither do we. We work alongside your counsel, any external assessor and your compliance platform.
Common questions
How long does it take?
It depends on the number of systems and vendors that handle ePHI and on how much remediation is needed. We agree a plan with dates during scoping.
Can you make us HIPAA certified?
There is no official HIPAA certification from HHS. We help you complete the risk analysis, put safeguards in place and keep evidence that shows how you meet the Security Rule.
We already did a risk analysis. Can you update it?
Yes. We review the existing analysis, check it against current systems and data flows, and update risks and decisions where the environment has changed.
Can you tell us whether an incident is a reportable breach?
No. That is a legal determination for your counsel and privacy officer. We can help with the technical investigation and provide facts they need for the decision.
Can you sign an NDA or a business associate agreement?
We sign an NDA on request. If the work requires access to ePHI, we discuss the need for a business associate agreement with your team and counsel during scoping.
Do you offer ongoing support?
Yes. Engagements have a fixed scope, and we offer retainers for yearly risk analysis updates, control testing and evidence upkeep.
How to prepare
Gather your most recent risk analysis, current security policies, a list of systems and vendors that handle ePHI, signed business associate agreements, and any recent audit or penetration test reports.
Name your security official and privacy officer, and the owners of identity, infrastructure, applications and vendor management. Let us know about any customer questionnaires, OCR correspondence or assessment deadlines.
Business associates and their agreements
A business associate is a person or organization that creates, receives, maintains or transmits protected health information on behalf of a covered entity. Examples include cloud hosting providers, billing companies and software vendors. Business associates are directly liable for compliance with the Security Rule, and their subcontractors that handle ePHI are business associates too.
A business associate agreement sets out how the business associate will protect the information and report security incidents and breaches. Your counsel drafts and negotiates these agreements. We help you keep an inventory of vendors that handle ePHI and check that the security commitments in each agreement match the controls in place.

