What is HIPAA Security Rule (HIPAA)?
HIPAA Security Rule (HIPAA) is a US federal regulation that sets minimum standards for protecting electronic protected health information (ePHI) held or transmitted by covered entities and their business associates. It requires organizations to implement administrative, physical, and technical safeguards to ensure the confidentiality, integrity, and availability of ePHI.
What it is
The HIPAA Security Rule is one part of the broader Health Insurance Portability and Accountability Act of 1996. It applies specifically to electronic protected health information (ePHI). Covered entities include health plans, healthcare clearinghouses, and most healthcare providers. Business associates, such as cloud vendors or billing services that handle ePHI on behalf of covered entities, must also comply.
The rule organizes its requirements into three categories of safeguards:
- Administrative safeguards: Risk analysis, workforce training, access management policies, and incident response procedures.
- Physical safeguards: Controls over physical access to systems that store ePHI, including workstation policies and device disposal.
- Technical safeguards: Audit controls, automatic logoff, encryption of ePHI in transit and at rest, and unique user identification.
The rule uses a mix of "required" and "addressable" specifications. Addressable does not mean optional. It means an organization must implement the specification, document an equivalent alternative, or document why it is not reasonable and appropriate for their environment.
Why it matters
The Office for Civil Rights (OCR) at the US Department of Health and Human Services enforces the rule. Penalties range from $100 to $50,000 per violation, with annual caps up to $1.9 million per violation category. Breaches affecting 500 or more individuals trigger mandatory public reporting and media notification. Non-compliance also creates civil liability exposure.
Beyond fines, a breach of ePHI damages patient trust and can disrupt care delivery.
How tools address it
Compliance management platforms help organizations map controls to HIPAA requirements, track evidence, and manage risk assessments. Some tools automate control testing and generate audit-ready reports. GRC platforms can centralize policy management, vendor risk tracking for business associates, and continuous controls monitoring across the required safeguard categories. Tools like these do not make an organization compliant on their own. They reduce the manual work of documenting and demonstrating compliance.