Definition
Technical safeguards are the technology and related policies and procedures used to protect ePHI and control access to it.
In practice
- A service can combine unique IDs, MFA, role-based access, audit review, and encrypted transport for a patient portal.
- An API gateway can enforce authentication while application logs support investigation.
Who this applies to
- Engineering and security teams
- Covered entities and business associates operating ePHI systems
- Vendors providing applications, infrastructure, or managed services
What the rule asks for
- Implement access controls, audit controls, integrity controls, person or entity authentication, and transmission security as appropriate.
- Review risks and document addressable implementation decisions.
- Monitor whether technical controls operate as intended.
How teams put it into practice
- Map each safeguard to a system owner, configuration, log, and review cadence.
- Test role changes, break-glass access, logging, and transmission paths.
- Use layered controls instead of relying on one technology.
Common mistakes
- Buying a security product without defining the risk it addresses.
- Collecting logs without review, alerting, retention, or investigation ownership.
- Treating MFA or encryption as a complete program.
Questions that come up
Does HIPAA prescribe one technical stack?
The Security Rule is generally technology-neutral and calls for reasonable and appropriate measures based on the organization's environment and risks.
References
- Technical safeguards guidance HHS Office for Civil Rights
- NIST SP 800-66 Rev. 2 National Institute of Standards and Technology