HIPAAmart

Security Rule explorer

Explore the HIPAA Security Rule safeguards.

Review regulatory requirements alongside practical implementation guidance and verified NIST relationships.

Last verified August 28, 2026

Administrative, physical, and technical safeguards

Security Management Process

45 CFR § 164.308(a)(1) · Administrative

Conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI, implement security measures to reduce those risks, apply appropriate sanctions, and regularly review information-system activity.

Assigned Security Responsibility

45 CFR § 164.308(a)(2) · Administrative

Identify the security official who is responsible for developing and implementing the policies and procedures required by the Security Rule.

Workforce Security

45 CFR § 164.308(a)(3) · Administrative

Implement policies and procedures to ensure that all members of the workforce have appropriate access to ePHI and to prevent workforce members from obtaining access not appropriate to their role.

Information Access Management

45 CFR § 164.308(a)(4) · Administrative

Implement policies and procedures for authorizing access to ePHI and for establishing, documenting, reviewing, and modifying access as appropriate to a workforce member's role and the organization's environment.

Security Awareness and Training

45 CFR § 164.308(a)(5) · Administrative

Implement a security-awareness and training program for all members of the workforce, including management.

Security Incident Procedures

45 CFR § 164.308(a)(6) · Administrative

Implement policies and procedures to address security incidents, including identifying and responding to suspected or known incidents, mitigating harmful effects, and documenting incidents and outcomes.

Contingency Plan

45 CFR § 164.308(a)(7) · Administrative

Establish and implement policies and procedures for responding to an emergency or other occurrence that damages systems containing ePHI.

Evaluation

45 CFR § 164.308(a)(8) · Administrative

Perform a periodic technical and nontechnical evaluation, based initially upon the standards implemented under the Security Rule and subsequently in response to environmental or operational changes affecting the security of ePHI.

Business Associate Contracts and Other Arrangements

45 CFR § 164.308(b)(1) · Administrative

Obtain satisfactory assurances from a business associate that it will appropriately safeguard ePHI, documented through a written contract or other arrangement as required.

Facility Access Controls

45 CFR § 164.310(a) · Physical

Implement policies and procedures to limit physical access to electronic information systems and the facilities in which they are housed, while ensuring properly authorized access.

Workstation Use

45 CFR § 164.310(b) · Physical

Implement policies and procedures that specify the proper functions to be performed and the manner in which workstations may be used to access ePHI.

Workstation Security

45 CFR § 164.310(c) · Physical

Implement physical safeguards for all workstations that access ePHI to restrict access to authorized users.

Device and Media Controls

45 CFR § 164.310(d) · Physical

Implement policies and procedures that govern the receipt and removal of hardware and electronic media containing ePHI, including disposal, re-use, accountability, and data backup or storage.

Access Control

45 CFR § 164.312(a) · Technical

Implement technical policies and procedures for electronic information systems that maintain ePHI to allow access only to people or software programs that have been granted access rights.

Audit Controls

45 CFR § 164.312(b) · Technical

Implement hardware, software, and/or procedural mechanisms that record and examine activity in information systems that contain or use ePHI.

Integrity

45 CFR § 164.312(c) · Technical

Implement policies and procedures to protect ePHI from improper alteration or destruction.

Person or Entity Authentication

45 CFR § 164.312(d) · Technical

Implement procedures to verify that a person or entity seeking access to ePHI is the one claimed.

Transmission Security

45 CFR § 164.312(e) · Technical

Implement technical security measures to guard against unauthorized access to ePHI that is being transmitted over an electronic communications network.

References