Compliance · US
HIPAA Security RuleCovered entities & business associates

HIPAA

Plain-English definition

HIPAA's Security Rule requires administrative, physical, and technical safeguards for electronic protected health information (ePHI). It applies directly to covered entities (healthcare providers, health plans, clearinghouses) and extends to business associates, any vendor that handles ePHI on a covered entity's behalf, through a mandatory Business Associate Agreement.

This page covers the Security Rule specifically; the Privacy Rule and Breach Notification Rule impose related but distinct obligations.

Who needs it

Healthcare providers, health plans, and healthcare clearinghouses directly, and any technology vendor, cloud provider, or contractor that creates, receives, maintains, or transmits ePHI on their behalf.

Key requirements

Documented risk analysis and risk management process, access controls and audit logging for ePHI, encryption of ePHI at rest and in transit (addressable but expected in practice), workforce training, and signed Business Associate Agreements with every vendor touching ePHI.

Cyber/privacy implications

The Security Rule's risk analysis requirement means controls must be justified by a documented risk assessment specific to your environment, not a generic policy template copied from another organization.

Assessment methodology

ePHI data-flow mapping, risk analysis against the Security Rule's administrative, physical, and technical safeguard categories, and a Business Associate Agreement inventory and review.

Implementation phases

01
Assess

Map ePHI flows and complete a formal risk analysis.

02
Remediate

Close safeguard gaps and formalize Business Associate Agreements.

03
Sustain

Ongoing workforce training and periodic risk analysis refresh.

Evidence & documentation requirements

Documented risk analysis, signed Business Associate Agreements, access and audit logs for systems handling ePHI, workforce training records, and breach-response procedures.

Common mistakes

Treating HIPAA as satisfied by a signed Business Associate Agreement alone without actually implementing the underlying safeguards; skipping the formal, documented risk analysis, which is the specific requirement regulators check first during an investigation.

Related standards

Expert review

Nitzan Levi
Nitzan Levi
Co-Founder, Cybecs · Co-Founder, RedRok · Executive Director, Privacy & GRC · CISM, CISSP, CDPSE, CCSK, CSA

FAQ

We're a vendor, not a healthcare provider, does this still apply?
Yes, if you create, receive, maintain, or transmit ePHI on behalf of a covered entity, you're a business associate and the Security Rule applies to you directly.
Is encryption mandatory?
Encryption is technically an 'addressable' specification, meaning you must implement it or document a specific, defensible reason you didn't; in practice, regulators expect encryption absent an unusual justification.
Do you handle Business Associate Agreement review?
Yes, reviewing and standardizing BAAs across your vendor relationships is part of our Regulatory Compliance engagement scope.

Request a Risk Analysis

Get the documented risk analysis HIPAA actually requires, not a generic template.

Request a Risk Analysis →