What is HIPAA Security Rule?
The HIPAA Security Rule is the part of the Health Insurance Portability and Accountability Act regulations that sets national standards for protecting electronic protected health information. It applies to covered entities, meaning health care providers, health plans, and clearinghouses, and to the business associates that handle patient data for them, which includes IT providers. Where the Privacy Rule says what may be done with patient information, the Security Rule says how the electronic form of it must be guarded.
The rule is organized into three groups of safeguards. Administrative safeguards cover the management side: a documented risk analysis, a security officer, workforce training, sanctions for violations, contingency planning, and business associate agreements. Physical safeguards cover facility access controls, workstation use, workstation security, and device and media controls. Technical safeguards cover access control, audit logs, integrity checks, authentication, and transmission security. Historically each standard has been either required or addressable, where addressable means the organization must implement it or document why an alternative is reasonable. Recent rulemaking from the Department of Health and Human Services moves the rule toward specific mandatory controls, including multi-factor authentication, encryption at rest and in transit, a written asset inventory and network map, and regular testing of the ability to restore systems.
The Security Rule is deliberately scalable. A two-physician practice and a hospital system face the same standards but are expected to implement them in proportion to their size and risk. That flexibility cuts both ways for a small practice: it allows sensible choices, but it also means the practice must document those choices, and the risk analysis is the document regulators ask for first after a breach. A missing or outdated risk analysis is a recurring finding in enforcement settlements involving small providers.
NetSys's HIPAA compliance service maps the Security Rule's safeguards to controls a small practice can run, most of them inside Microsoft 365: conditional access and multi-factor authentication in Entra ID, device encryption and compliance policies through Intune, audit logging, encrypted email, and backups with tested restores to satisfy the contingency planning standard. Joel Baum writes about the rule's requirements and the changes that are coming for medical and dental practices.
Why it matters for a small business
For a medical or dental practice, the Security Rule is the standard you will be measured against after a lost laptop or a ransomware attack. It is also the standard a business associate must meet if you are the IT firm or billing company that handles patient data. Most of what it asks for is ordinary good practice: know where the data is, limit who can reach it, keep logs, encrypt, train people, and be able to restore. The risk analysis and the written policies are what turn those practices into evidence of compliance, and evidence is what an investigator asks for.
HIPAA Security Rule: FAQs
What does the HIPAA Security Rule require?
It requires covered entities and business associates to protect electronic patient information through administrative, physical, and technical safeguards. Concretely that means a documented risk analysis, a named security officer, staff training, access controls with unique user accounts, audit logs, encryption of data in transit and increasingly at rest, controls on devices and media, business associate agreements with vendors, and a contingency plan with tested backups. Each safeguard must be documented, and the documentation must be kept current and retained for six years.
Does the HIPAA Security Rule apply to IT companies?
Yes, when the IT company creates, receives, maintains, or transmits electronic patient data on behalf of a covered entity. That makes it a business associate, and since the 2013 Omnibus Rule business associates are directly liable for Security Rule compliance in their own right, rather than through their contract with the practice alone. An IT provider with administrator access to a practice's servers or backups falls squarely into that category and must sign a business associate agreement and apply the safeguards to its own operations.
What is the difference between the HIPAA Privacy Rule and the Security Rule?
The Privacy Rule governs how protected health information in any form may be used and disclosed, and it gives patients rights such as access to their records. The Security Rule applies only to the electronic form of that information and specifies how it must be protected from unauthorized access or loss. A practice can follow the Privacy Rule perfectly and still violate the Security Rule if its server has no access controls or its backups have never been tested. Compliance programs need to cover both.
More terms
Immutable Backup
An immutable backup is a copy of data that cannot be altered, encrypted or deleted by anyone, even an administrator, until its retention period has passed.
Extended Detection and Response (XDR)
Extended detection and response (XDR) correlates signals from endpoints, email, identities and cloud apps into single incidents with a coordinated response.
Managed Detection and Response (MDR)
Managed detection and response (MDR) is an outsourced security service whose analysts monitor endpoints and identities around the clock and act on threats.
Endpoint Detection and Response (EDR)
Endpoint detection and response (EDR) is software that records activity on computers and servers, detects attacker behavior and isolates a device remotely.
Get the controls, not just the definition.
A NetSys engineer can tell you in fifteen minutes whether you have this covered, and what it would take if you do not. Month to month, no long-term contract.
