HIPAA guide map
HIPAA Security Guide
Translate administrative, physical, and technical safeguards into implementation and evidence questions.
Reviewed August 2026
Available guidance
- Administrative Safeguards
The governance, risk, workforce, incident, and contingency practices that organize Security Rule protection.
- Physical Safeguards
Facility, workstation, device, and media controls that help protect ePHI from physical threats.
- Technical Safeguards
Access, audit, integrity, authentication, and transmission controls for systems handling ePHI.
- HIPAA Access Controls
Designing unique identification, emergency access, automatic logoff, and least-privilege practices around ePHI.
- Encryption and HIPAA
How to evaluate encryption for ePHI without reducing a broader risk decision to a yes-or-no checkbox.
- HIPAA Audit Controls
Create useful, reviewable records of activity in systems that contain or use ePHI.
- Ransomware and HIPAA
A grounded response framework for ransomware risk, availability, evidence, and breach analysis.