Definition
Administrative safeguards are the administrative actions, policies, and procedures used to manage the selection, development, and implementation of security measures for ePHI.
In practice
- A phishing exercise can be tied to awareness training, incident reporting, and follow-up remediation.
- A vendor review can feed both risk analysis and business associate oversight.
Who this applies to
- Covered entities
- Business associates
- Privacy, security, compliance, and workforce leaders
What the rule asks for
- Conduct risk analysis and risk management.
- Establish workforce security, information access, security awareness, incident procedures, and contingency planning.
- Evaluate security measures and maintain required documentation.
How teams put it into practice
- Connect each policy to an owner, procedure, training need, and evidence source.
- Exercise incident and recovery processes with the people who would perform them.
- Use change management to trigger risk review when systems or vendors change.
Common mistakes
- Confusing a policy library with an operating control.
- Leaving workforce termination, access review, or contingency testing informal.
- Not recording why addressable implementation choices were made.
Questions that come up
Are administrative safeguards only paperwork?
No. They include management processes and workforce practices that direct and verify how security measures operate.
References
- Administrative safeguards guidance HHS Office for Civil Rights