The Security Rule
The Security Rule requires covered entities and business associates to implement national standards to protect the confidentiality, integrity, and availability of electronic protected health information (ePHI). It mandates a combination of administrative, physical, and technical safeguards to ensure that ePHI is secure from unauthorized access or alteration.
What it means
Unlike the Privacy Rule, which covers all forms of PHI, the Security Rule applies specifically to electronic data. Its intent is to provide a flexible framework that allows organizations to scale their security measures based on their specific size, complexity, and risk profile.
In practice, this means an organization must not only implement technical tools (like firewalls) but also organizational processes (like training and auditing). The rule distinguishes between "required" specifications, which must be implemented exactly as stated, and "addressable" specifications, which must be implemented if they are reasonable and appropriate for the environment.
How to meet it
- Conduct a comprehensive Risk Analysis to identify all locations where ePHI is created, received, maintained, or transmitted.
- Develop written security policies and procedures that govern access control, workstation security, and incident response.
- Implement technical access controls, such as unique user identifiers, multi-factor authentication (MFA), and automatic log-offs.
- Encrypt ePHI both at rest (on servers/laptops) and in transit (via email or API) whenever reasonable and appropriate.
- Establish physical safeguards to limit access to facilities and workstations containing ePHI, such as badge entries or privacy screens.
- Execute Business Associate Agreements (BAAs) with all third-party vendors that handle or store ePHI on your behalf.
Evidence an auditor asks for
- The most recent Risk Analysis report and a corresponding Risk Remediation Plan showing how identified gaps were closed.
- Documentation of security awareness training, including timestamps and signed acknowledgments from employees.
- User access lists and evidence of periodic "access reviews" to prove that permissions are revoked when staff leave or change roles.
- Technical configuration screenshots proving encryption is enabled on databases, mobile devices, and communication channels.
- A complete inventory of hardware and software assets that touch ePHI.
Common pitfalls
- Treating "addressable" requirements as optional; if an addressable control is not implemented, the organization must document why it was not reasonable and what alternative measure was used.
- Performing a risk assessment once at startup rather than treating it as a living process that updates when new software or hardware is added.
- Maintaining "shelfware"—policies that exist in a manual but are not reflected in the actual technical configuration of the systems.