HIPAA Security Rule: The Foundation of Healthcare Data Security
The Health Insurance Portability and Accountability Act of 1996 (HIPAA) Security Rule — codified at 45 CFR Part 164 Subpart C — sets the national standard for protecting electronic protected health information (ePHI). Originally finalised in 2003 (effective 2005), the Security Rule applies to all HIPAA Covered Entities (healthcare providers, health plans, and healthcare clearinghouses) and, since the 2009 HITECH Act and 2013 Omnibus Rule, to all Business Associates that create, receive, maintain, or transmit ePHI on behalf of a Covered Entity.
In 2024, the Department of Health and Human Services (HHS) issued a Notice of Proposed Rulemaking (NPRM) proposing the most significant Security Rule update in 20 years. The 2024 NPRM proposes to make most "addressable" implementation specifications required, mandate MFA for all ePHI access, require annual technology asset inventories, and shorten breach notification to 72 hours. While the final rule is pending, organisations should begin preparing now.
Who Must Comply: Covered Entities and Business Associates
Covered Entities include: (1) healthcare providers that transmit health information electronically in connection with standard transactions (claims, eligibility, referrals); (2) health plans including individual and group plans, HMOs, Medicare/Medicaid; (3) healthcare clearinghouses. Business Associates — any person or entity that creates, receives, maintains, or transmits PHI on behalf of a Covered Entity in performing certain functions. Since the 2013 Omnibus Rule, BAs have direct liability for HIPAA Security Rule compliance; this includes cloud service providers (CSPs), EHR vendors, analytics companies, billing processors, and SaaS platforms handling ePHI. Subcontractors of Business Associates are also Business Associates.
Three Categories of Safeguards
Administrative Safeguards (§164.308)
Administrative safeguards are the policies, procedures, and management activities that protect ePHI. The most critical requirements:
- Security Officer (§164.308(a)(2)): Every HIPAA-covered organisation must designate a Security Officer with documented authority and responsibility for developing and implementing security policies. For small practices, this can be the owner or office manager — the requirement is designation, documentation, and actual authority.
- Risk Analysis (§164.308(a)(1)(ii)(A)): Arguably the most frequently cited violation in OCR investigations. The risk analysis must be: comprehensive (covering all ePHI regardless of location — cloud, workstation, mobile, paper-linked systems), documented, and updated regularly (at minimum annually and after significant changes). OCR's guidance specifies it must include: (1) scope definition; (2) data collection; (3) threat identification; (4) vulnerability identification; (5) current security controls assessment; (6) likelihood determination; (7) impact determination; (8) risk level determination; (9) risk prioritisation. The ONC and HHS jointly released a free Security Risk Assessment (SRA) Tool that walks through this process.
- Risk Management (§164.308(a)(1)(ii)(B)): Implement security measures to reduce identified risks to a reasonable and appropriate level. This is your risk treatment plan — accept, mitigate, transfer, or avoid each identified risk.
- Business Associate Agreements (§164.308(b)): Every Business Associate relationship requires a written BAA. Required elements: permitted uses and disclosures, BA must implement appropriate safeguards, BA must report breaches and security incidents, BA must comply with HIPAA's individual rights provisions where applicable, and return/destroy PHI upon termination. BAAs must be reviewed and updated — courts have held that outdated BAAs that don't reflect actual data flows are not compliant.
- Contingency Plan (§164.308(a)(7)): Five required components: (1) data backup plan; (2) disaster recovery plan; (3) emergency mode operation plan; (4) testing and revision procedures; (5) applications and data criticality analysis. Annual testing of backup restoration is a critical requirement the 2024 NPRM proposes to formalise.
Physical Safeguards (§164.310)
Physical safeguards limit physical access to systems containing ePHI. Key requirements: facility access controls (document who can access server rooms/data centres; visitor logs; access logs); workstation use policies (document what can and cannot be done on workstations accessing ePHI); workstation security (screen locks, cable locks, clean desk); device and media controls (documented disposal using NIST SP 800-88 for secure media sanitisation; accountability for all hardware containing ePHI).
Technical Safeguards (§164.312)
Technical safeguards are the technology controls protecting ePHI. Key requirements:
- Access Controls (§164.312(a)): Unique user identification (no shared accounts in ePHI systems); automatic logoff; encryption and decryption; emergency access procedures (break-glass access for disasters).
- Audit Controls (§164.312(b)): Implement hardware, software, and procedural mechanisms to record and examine activity in systems containing ePHI. What to log: login/logout, ePHI access, create/read/update/delete operations. Log retention: HIPAA requires 6-year document retention — logs should be retained for 6 years. Logs must be protected from tampering.
- Integrity Controls (§164.312(c)): Mechanisms to authenticate that ePHI has not been altered or destroyed without authorisation — checksums, digital signatures, hash validation.
- Encryption (§164.312(a)(2)(iv) and (e)(2)(ii)): Addressable under the current rule (but proposed as required under 2024 NPRM). In practice, OCR treats encryption as the primary mechanism to make a breach non-reportable. NIST standards: AES-256 for data at rest (NIST SP 800-111); TLS 1.2+ for data in transit (NIST SP 800-52 Rev 2).
HHS 2024 Security Rule NPRM: What's Proposed
The HHS 2024 NPRM (89 FR 43988, published May 6, 2024) proposes major changes:
- Eliminate "addressable" specifications: Most addressable specifications would become required, including encryption, audit controls, and automatic logoff. There will still be some flexibility in "how" to implement, but "whether" to implement will be eliminated for most.
- Technology asset inventory and network map: Mandatory documentation of all technology assets that create, receive, maintain, or transmit ePHI, and a network map showing ePHI data flows.
- Mandatory MFA: Multi-factor authentication for all access to ePHI systems — no exceptions. Currently an addressable specification; would become required for every user accessing any system containing ePHI.
- Vulnerability management timelines: Critical vulnerabilities must be patched within 15 days; high-severity vulnerabilities within 30 days. Annual vulnerability scans required.
- 72-hour breach notification: Current rule requires notification "as soon as possible" but no later than 60 days. NPRM proposes reducing to 72 hours for reporting to HHS — aligning with GDPR and HIPAA Breach Notification Rule enforcement practice.
- Annual contingency plan testing: Annual testing of backup and restoration procedures (restoring from backup, not just verifying backup completion).
- Anti-malware and network segmentation: Explicit requirements for anti-malware on all ePHI-handling systems and network segmentation of ePHI systems.
Breach Notification Rule: The Four-Factor Test
Not every security incident is a reportable breach. Under 45 CFR §164.402, an impermissible use or disclosure of PHI is presumed to be a breach UNLESS the covered entity or business associate demonstrates a low probability that PHI has been compromised based on a risk assessment of at least four factors:
- Nature and extent of the PHI: What types of identifiers were involved? What was the sensitivity of the clinical information? Social Security numbers, financial account numbers, and mental health information increase the probability of compromise.
- Who accessed or could have accessed the information: An impermissible disclosure to another healthcare provider is lower risk than disclosure to a known bad actor. Workforce member snooping is different from external attacker.
- Whether PHI was actually acquired or viewed: Evidence that PHI was not opened, accessed, or viewed (e.g. encrypted at rest; forensic evidence of no access) can reduce the breach probability.
- Extent to which risk has been mitigated: Did the impermissible recipient sign a BAA or confidentiality agreement? Did they confirm destruction of the data? Mitigation reduces probability of compromise.
If the risk assessment shows high probability of compromise, notification must occur. Timelines: individual notification within 60 days of discovery; HHS notification simultaneously for 500+ (via HHS Breach Portal — the "Wall of Shame"); small breaches (under 500) can be reported in an annual log to HHS within 60 days of year-end; media notification required for 500+ residents of a State or jurisdiction.
OCR Enforcement Priorities in 2026
The Office for Civil Rights (OCR) has published its enforcement priorities and investigation patterns show consistent focus areas:
- Hacking and IT incidents: Account for 70%+ of reported large breaches. Ransomware, phishing, and credential compromise dominate. OCR investigations consistently find inadequate risk analysis, missing MFA, and poor patch management.
- Risk analysis failures: The most commonly cited violation in OCR corrective action plans. Many organisations have never performed a formal risk analysis or have outdated analyses.
- Business Associate issues: Missing BAAs, outdated BAAs, BA breaches without proper notification to covered entities.
- Right of access: Individual access to their own records within 30 days. OCR has settled multiple enforcement actions specifically for excessive fees or delays.
Civil Money Penalty structure (annual per-violation-category caps): Unknowing: $137–$68,928; Reasonable cause: $1,379–$68,928; Willful neglect (corrected): $13,785–$68,928; Willful neglect (uncorrected): $68,928–$1,919,173. Notable settlements: Advocate Health $5.55M (2016); Dignity Health/CommonSpirit $875K (2023); Banner Health $1.25M (2023).
HIPAA Security Rule Gap Assessment Tool
The HIPAA Security Rule v2 Gap Assessment covers 42 key requirements across six categories:
- Administrative Safeguards (§164.308): Security Officer designation, risk analysis (scope/threats/vulnerabilities/controls/risk levels), risk management plan, workforce training (at hire and annually), access management procedures, contingency plan (backup/DR/emergency mode/annual testing), BAAs with all business associates
- Physical Safeguards (§164.310): Facility access controls, workstation use policies, workstation security (screen locks/cable locks/clean desk), device and media disposal (NIST 800-88), media movement tracking, physical audit logs and visitor controls, emergency physical access procedures
- Technical Safeguards (§164.312): Unique user IDs (no shared accounts), automatic logoff, AES-256 encryption at rest, TLS 1.2+ encryption in transit, audit controls (login/access/create/modify/delete; 6-year retention), integrity controls (checksums/hashing), emergency access procedures
- HHS 2024 NPRM Requirements: Technology asset inventory (all ePHI systems), network map (data flow diagram), vulnerability management (critical: 15-day patching), annual contingency plan testing, network segmentation, anti-malware/EDR on all ePHI systems, MFA for all ePHI access
- Breach Notification Rule: HHS notification within 60 days (proposed 72 hours), individual notification procedures, media notification for 500+, four-factor breach risk assessment documentation, incident response plan, breach register (6-year retention), annual HHS Wall of Shame monitoring
- Privacy Rule & Governance: Privacy Officer designation, NPP (updated for 2024 Reproductive Health Rule), minimum necessary standard, individual rights implementation (access 30-day/amendment/accounting/restriction), BAA audit programme, OCR audit readiness, state law pre-emption analysis
Who it's for: Covered Entities (hospitals, physician practices, health plans); Business Associates (EHR vendors, health tech SaaS, cloud providers, analytics companies, billing processors); digital health startups determining HIPAA applicability; compliance teams preparing for OCR audit or post-breach corrective action plan.