9.3 HIPAA Security Rule: Administrative, Physical & Technical Safeguards

Key Takeaways

  • The HIPAA Security Rule specifically protects electronic Protected Health Information (ePHI) across Administrative, Physical, and Technical safeguard domains.
  • Implementation specifications are designated as either Required (mandatory compliance) or Addressable (flexible alternative safeguard evaluation).
  • Administrative Safeguards mandate risk analysis, formal security governance, workforce sanction policies, and periodic security training.
  • Physical Safeguards enforce facility access controls, workstation positioning and shielding rules, and NIST 800-88 media sanitization standards.
  • Technical Safeguards make Unique User Identification, Emergency Access Procedure, Audit Controls, and Person or Entity Authentication Required, while Automatic Logoff, Encryption and Decryption, Integrity controls, and Transmission Security mechanisms are Addressable.
Last updated: August 2026

HIPAA Security Rule: Administrative, Physical & Technical Safeguards

Scope of the HIPAA Security Rule

While the Privacy Rule protects PHI in all formats (paper, oral, electronic), the HIPAA Security Rule specifically governs electronic Protected Health Information (ePHI) created, received, maintained, or transmitted by covered entities and business associates. The rule establishes technical and operational standards across three safeguard pillars: Administrative, Physical, and Technical.

Required vs. Addressable Implementation Specifications

Within the Security Rule standards, individual implementation specifications are designated as either Required or Addressable:

  • Required (R): The covered entity or business associate must implement the specification exactly as stated in the regulation. No alternative compliance paths are permitted.
  • Addressable (A): The entity must assess whether the specification is reasonable and appropriate for its technical environment. If appropriate, it must implement it. If not, the entity must formally document why it is not appropriate and implement an equivalent, effective alternative safeguard. Addressable does not mean optional.

1. Administrative Safeguards

Administrative Safeguards account for more than half of the Security Rule requirements. They establish the organizational policies, security governance, and workforce management protocols required to safeguard ePHI.

Administrative Safeguard StandardSpecification StatusStatutory Operational Mandate
Security Management ProcessRequiredPerform comprehensive Risk Analysis to identify ePHI vulnerabilities; enact Risk Management plans; enforce a formal Sanction Policy for non-compliant staff; conduct Information System Activity Reviews (audit log monitoring).
Assigned Security ResponsibilityRequired (no separate specifications)Identify the security official responsible for developing and implementing the entity's security policies and procedures.
Workforce SecurityStandard Required; all three specifications AddressableAuthorization and/or supervision, workforce clearance procedure, and termination procedures for access to ePHI.
Information Access ManagementStandard Required; Isolating Clearinghouse Functions Required, Access Authorization and Access Establishment/Modification AddressableImplement policies restricting ePHI access strictly to authorized personnel.
Security Awareness & TrainingStandard Required; all four specifications AddressableSecurity reminders, protection from malicious software, log-in monitoring, and password management for all workforce members including management.
Security Incident ProceduresStandard Required; Response and Reporting RequiredIdentify and respond to suspected or known security incidents, mitigate their harmful effects to the extent practicable, and document each incident and its outcome. This is the standard that obliges the specialist to escalate rather than quietly fix (Section 9.7), and it operates independently of whether the incident later proves to be a reportable breach (Section 9.4).
Contingency PlanStandard Required; Data Backup, Disaster Recovery, and Emergency Mode Operation Required; Testing/Revision and Applications & Data Criticality Analysis AddressableEstablish written backup, disaster recovery, and emergency mode operation plans, with testing procedures.
EvaluationRequiredPerform periodic technical and non-technical evaluations of security policies in response to environmental or operational changes.

One further administrative standard, Business Associate Contracts and Other Arrangements at 45 CFR 164.308(b)(1), is Required and is covered in Section 9.4 with the rest of the BAA material.


2. Physical Safeguards

Physical Safeguards protect physical facilities, computer hardware, and data storage media from unauthorized entry, environmental hazards, and theft.

Facility Access Controls

Covered entities must implement physical perimeter controls for buildings housing server infrastructure or workstations. Specifications include contingency operations access, facility security plans, access control and validation (badge readers, visitor logging), and maintenance recordkeeping.

Workstation Use & Workstation Security

  • Workstation Use: Defined policies governing the proper functions performed on computer terminals, laptops, and tablets.
  • Workstation Security: Physical safeguards preventing unauthorized viewing or access (e.g., privacy screen filters preventing shoulder surfing, cable locks securing hardware, and monitor positioning angled away from public view).

Device and Media Controls

Regulates the movement, disposal, and re-use of hardware and electronic media containing ePHI (hard drives, backup tapes, USB drives):

  • Disposal (Required): Implement policies for the final disposal of ePHI and hardware.
  • Media Re-Use (Required): Mandate complete sanitization of media before re-allocation to other staff.
  • Sanitization Standards: Media destruction must comply with NIST SP 800-88 guidelines (degaussing, purging, or physical destruction of storage media).

3. Technical Safeguards

Technical Safeguards encompass the technical software and policy controls that protect ePHI and control access to electronic systems.

Access Control Specifications

  • Unique User Identification (Required): Assign a unique name or number (User ID) to track individual user activity. Generic or shared staff logins are strictly illegal under HIPAA.
  • Emergency Access Procedure ("Break-Glass") (Required): Protocols granting emergency access to ePHI during critical care situations when standard access controls must be overridden.
  • Automatic Logoff (Addressable): Configure systems to terminate an inactive session after a set period of user inactivity (e.g., 5-10 minutes) to prevent unauthorized viewing of unattended terminals.
  • Encryption & Decryption (Addressable): Implement technical mechanisms rendering ePHI unreadable without a decryption key. The rule names no algorithm; organizations that implement it commonly use AES-256 at rest. Encryption meeting HHS guidance also triggers the breach notification safe harbor (Section 9.4), which is why most entities implement it despite the addressable designation.

Audit Controls (Required)

Facilities must implement software and hardware mechanisms to record and examine system activity in information systems containing ePHI. Audit logs track user logins, record views, edits, deletions, and export events. Audit trails must be tamper-evident and reviewed routinely.

Integrity Controls & Person Authentication

  • Integrity Controls (Addressable): Enforce policies and technical safeguards (such as SHA-256 cryptographic hashing) ensuring ePHI is not altered or destroyed without detection.
  • Person or Entity Authentication (Required): Technical verification that a user requesting ePHI access is who they claim to be. The rule requires authentication but does not mandate a specific method; passwords, PINs, smart cards, tokens, and biometrics all qualify, and multi-factor authentication (MFA) is the strongest common implementation.

Transmission Security

Technical measures protecting ePHI transmitted over communication networks:

  • Integrity Controls and Encryption (both Addressable): The Transmission Security standard is Required, and both of its implementation specifications — integrity controls and encryption — are Addressable. Organizations typically encrypt ePHI in transit using TLS 1.2 or higher.
Loading diagram...
HIPAA Security Rule: 3 Safeguard Pillars Architecture
Test Your Knowledge

During a emergency trauma code, an ED physician needs immediate access to a patient's electronic chart but lacks assigned clinical permissions for that specific module. What Technical Safeguard specification permits temporary access?

A
B
C
D
Test Your Knowledge

A hospital IT department is decommissioning old desktop computer hard drives that previously stored ePHI. Which physical safeguard standard governs their destruction?

A
B
C
D
Test Your Knowledge

Under the HIPAA Security Rule, how is an 'Addressable' implementation specification correctly defined?

A
B
C
D