HIPAAmart

HIPAA guide map

HIPAA Security Guide

Translate administrative, physical, and technical safeguards into implementation and evidence questions.

Reviewed August 2026

Available guidance

  • Administrative Safeguards

    The governance, risk, workforce, incident, and contingency practices that organize Security Rule protection.

  • Physical Safeguards

    Facility, workstation, device, and media controls that help protect ePHI from physical threats.

  • Technical Safeguards

    Access, audit, integrity, authentication, and transmission controls for systems handling ePHI.

  • HIPAA Access Controls

    Designing unique identification, emergency access, automatic logoff, and least-privilege practices around ePHI.

  • Encryption and HIPAA

    How to evaluate encryption for ePHI without reducing a broader risk decision to a yes-or-no checkbox.

  • HIPAA Audit Controls

    Create useful, reviewable records of activity in systems that contain or use ePHI.

  • Ransomware and HIPAA

    A grounded response framework for ransomware risk, availability, evidence, and breach analysis.