2.2 HIPAA Security Rule, Safeguards & Breach Notification

Key Takeaways

  • The HIPAA Security Rule (45 CFR Part 164, Subpart C) establishes administrative, physical, and technical safeguards specifically protecting electronic Protected Health Information (ePHI).

  • Implementation specifications are categorized as either 'Required' (strictly mandatory) or 'Addressable' (must implement, implement an equivalent alternative, or formally justify non-implementation).

  • The HITECH Act establishes a statutory presumption that any unauthorized acquisition or disclosure of unencrypted PHI constitutes a breach unless a 4-factor risk assessment proves a low probability of compromise.

  • Encryption that meets the NIST-based HHS guidance makes PHI "secured," so loss or theft of properly encrypted data with an uncompromised key is not a reportable breach.

  • Breaches affecting 500 or more individuals require individual notifications within 60 calendar days, notification to major media outlets, and concurrent electronic notice to the HHS Secretary.

Last updated: September 2026

2.2 HIPAA Security Rule, Safeguards & Breach Notification

While the HIPAA Privacy Rule establishes broad protections for patient health data across all formats (paper, oral, and electronic), the HIPAA Security Rule, codified at 45 CFR Part 164, Subpart C (§§ 164.302–164.318), focuses specifically on safeguarding electronic Protected Health Information (ePHI). In the modern cancer registry, virtually 100% of casefinding, abstracting, electronic data linkage, and central registry transmission is conducted electronically. Consequently, oncology data specialists must understand the operational mechanics of the Security Rule, the distinction between required and addressable specifications, and the statutory mandates governing data breach investigation and reporting.


The CIA Triad & Statutory Purpose

Under 45 CFR § 164.306(a), covered entities and business associates must ensure three fundamental security principles known in information security as the CIA Triad:

  1. Confidentiality: Ensuring that ePHI is not made available or disclosed to unauthorized persons or processes.
  2. Integrity: Ensuring that ePHI has not been altered, corrupted, or destroyed in an unauthorized manner.
  3. Availability: Ensuring that ePHI is accessible and usable upon demand by an authorized person (e.g., ensuring cancer registry databases are operational during clinical multidisciplinary conferences and emergency care).

Additionally, covered entities must protect against any reasonably anticipated threats or hazards to the security or integrity of ePHI, protect against reasonably anticipated unauthorized uses or disclosures, and ensure compliance by their workforce.


Required vs. Addressable Implementation Specifications

Within the Security Rule, standards are operationalized through Implementation Specifications. A critical concept tested on national credentialing examinations is the legal distinction between Required and Addressable specifications (45 CFR § 164.306(d)):

  • Required Specifications: The covered entity or business associate must implement the specification exactly as outlined in the regulation. Compliance is non-negotiable.
  • Addressable Specifications: The term "addressable" does NOT mean optional or voluntary. When confronted with an addressable specification, the covered entity must assess whether the specification is a reasonable and appropriate safeguard in its specific operating environment. The entity must then choose one of three actions:
    1. Implement the addressable specification as written;
    2. Implement one or more alternative security measures that achieve the same statutory purpose; or
    3. If neither is reasonable and appropriate, formally document the rationale, risk assessment, and justification showing how the standard is otherwise met.

Failing to address an addressable specification or treating it as optional represents a direct federal regulatory violation.


The Tripartite Safeguard Framework

The Security Rule organizes all protective controls into three discrete categories: Administrative, Physical, and Technical Safeguards.

Safeguard CategoryRegulatory CitationSafeguard StandardRequired vs. Addressable Specification
Administrative45 CFR § 164.308Security Management: Risk AnalysisRequired: Comprehensive assessment of potential vulnerabilities
Administrative45 CFR § 164.308Security Management: Risk ManagementRequired: Measures to reduce risks to reasonable levels
Administrative45 CFR § 164.308Sanction PolicyRequired: Disciplinary consequences for workforce non-compliance
Administrative45 CFR § 164.308Information System Activity ReviewRequired: Routine audit of logs, access reports, and tracking
Administrative45 CFR § 164.308Workforce SecurityRequired standard with addressable specifications: authorization/supervision, workforce clearance, termination procedures
Administrative45 CFR § 164.308Security Awareness & TrainingRequired standard with addressable specifications: security reminders, protection from malicious software, log-in monitoring, password management
Administrative45 CFR § 164.308Contingency PlanRequired: data backup plan, disaster recovery plan, emergency mode operation plan; Addressable: testing and revision, applications and data criticality analysis
Physical45 CFR § 164.310Facility Access ControlsAddressable: Contingency operations, access validation, facility security plan
Physical45 CFR § 164.310Workstation UseRequired: Policies governing workstation functions and permissible environments
Physical45 CFR § 164.310Workstation SecurityRequired: Physical safeguards (e.g., privacy screens, locked registry rooms)
Physical45 CFR § 164.310Device & Media Controls: DisposalRequired: Permanent degaussing, cross-cut shredding, physical destruction
Physical45 CFR § 164.310Device & Media Controls: Re-useRequired: Data sanitization before hardware reallocation
Physical45 CFR § 164.310Device & Media Controls: TrackingAddressable: Record of device movement and responsible custodian
Technical45 CFR § 164.312Unique User IdentificationRequired: Assigning an individual name or number for tracking user identity
Technical45 CFR § 164.312Emergency Access ProcedureRequired: Documented break-glass protocol to obtain ePHI during crises
Technical45 CFR § 164.312Automatic LogoffAddressable: Terminating electronic sessions after a specified period of inactivity
Technical45 CFR § 164.312Encryption and DecryptionAddressable: Algorithmic transformation of ePHI at rest and in transit
Technical45 CFR § 164.312Audit ControlsRequired: Hardware, software, and procedural activity recording and examination
Technical45 CFR § 164.312Integrity ControlsAddressable: Electronic verification (e.g., checksums, hashes) against improper alteration
Technical45 CFR § 164.312Person or Entity AuthenticationRequired: Procedures to verify that a person seeking access to ePHI is who they claim to be
Technical45 CFR § 164.312Transmission SecurityAddressable: Integrity controls and encryption for ePHI sent over electronic networks

Practical Cancer Registry Safeguards

In daily operations, oncology data specialists must adhere to rigorous safeguard practices:

  1. Workstation Security: Registrars working on dual monitors reviewing pathology reports, imaging scans, and staging algorithms must ensure screens cannot be viewed by visitors, transport staff, or non-clinical personnel. Privacy filters and password-protected screen locks are common safeguards; the lock interval is set by each organization's risk analysis, not by the Security Rule.
  2. Remote Abstracting Protocols: Remote or telecommuting registrars must access facility EHR and registry databases exclusively through encrypted Virtual Private Networks (VPN) with Multi-Factor Authentication (MFA). Printing paper records at a home office is strictly prohibited; if printed, documents must be stored in locked file cabinets and disposed of via certified cross-cut shredding.
  3. Audit Trails: Modern cancer registry database systems maintain automated audit logs capturing every user login, record creation, record edit, export, and deletion. Compliance teams routinely audit these logs to detect unauthorized access to medical records of public figures, hospital colleagues, or relatives (a practice known as "snooping"), which triggers immediate disciplinary termination under mandatory sanction policies.

The HITECH Act & Breach Notification Rule (45 CFR §§ 164.400–414)

Enacted as part of the American Recovery and Reinvestment Act of 2009, the Health Information Technology for Economic and Clinical Health (HITECH) Act dramatically expanded HIPAA enforcement, increased civil monetary penalties, extended direct liability to business associates, and created the Breach Notification Rule.

Definition of a Breach

A Breach is defined under 45 CFR § 164.402 as the unauthorized acquisition, access, use, or disclosure of protected health information in a manner not permitted under the HIPAA Privacy Rule which compromises the security or privacy of the protected health information.

The Statutory Presumption & The 4-Factor Risk Assessment

Under federal law, any unauthorized acquisition, access, use, or disclosure of unencrypted PHI is presumed to be a breach unless the covered entity or business associate demonstrates through a formal risk assessment that there is a low probability that the PHI has been compromised.

The covered entity must evaluate all four statutory factors:

  1. The Nature and Extent of the PHI: Evaluates the types of identifiers and the likelihood of re-identification (e.g., does the exposed data contain patient names, Social Security numbers, clinical cancer stages, or detailed pathology text?).
  2. The Unauthorized Person Who Used or Received the Data: Evaluates whether the unauthorized recipient is another covered entity bound by HIPAA (e.g., a misdirected fax sent to an affiliated oncologist's office) versus an unknown external entity or malicious attacker.
  3. Whether the PHI Was Actually Acquired or Viewed: Forensic evaluation to determine if files were opened, copied, or accessed (e.g., forensic analysis of a recovered stolen laptop showing files were never opened or accessed).
  4. The Extent to Which Risk Has Been Mitigated: Immediate corrective actions taken, such as obtaining a reliable, signed legal attestation of destruction from a trusted recipient or immediate remote device wiping.

The Encryption "Safe Harbor"

Under the HHS guidance issued under HITECH, PHI is secured (not "unsecured") when it is encrypted consistent with the NIST publications HHS cites (NIST SP 800-111 for data at rest and NIST standards such as SP 800-52 for data in motion) or when the media have been destroyed. Strong algorithms such as AES are typical examples.

The Safe Harbor Rule: If an encrypted laptop, thumb drive, or backup tape containing cancer registry files is lost or stolen, and the encryption key was not compromised, the event is NOT classified as a breach under federal law. No individual notifications, media notices, or reports to HHS OCR are required, because the data remained unreadable, unusable, and indecipherable to unauthorized individuals.


Breach Notification Requirements & Deadlines

If a breach of unsecured (unencrypted) PHI occurs, the covered entity must execute strict statutory notifications without unreasonable delay:

                                  BREACH DISCOVERY
                                         │
                  ┌──────────────────────┴──────────────────────┐
                  ▼                                             ▼
          Fewer than 500 Individuals                     500 or More Individuals
                  │                                             │
      ┌───────────┴───────────┐                     ┌───────────┼───────────┐
      ▼                       ▼                     ▼           ▼           ▼
Individual Notice      HHS OCR Notice       Individual Notice  Media Notice  HHS OCR Notice
(Within 60 Days)     (Annual Submission:    (Within 60 Days)  (Within 60     (Within 60 Days
                      Within 60 Days of                        Days: 500+     Electronic via
                       End of Cal. Yr.)                        Residents)       OCR Portal)

1. Individual Notification (45 CFR § 164.404)

  • Timeline: Written notice must be provided without unreasonable delay and in no case later than 60 calendar days after discovery of the breach.
  • Method: Written notification sent via first-class mail to the last known address of the individual, or secure email if the individual has formally consented to electronic notices.
  • Substitute Notice: If contact information for 10 or more individuals is insufficient or out-of-date, the entity must post a conspicuous notice on its website home page for at least 90 days or publish notice in major print/broadcast media, including a toll-free telephone number.

2. Media Notice (45 CFR § 164.406)

  • Threshold: Required when a breach of unsecured PHI affects 500 or more residents of a single State or jurisdiction.
  • Timeline: Without unreasonable delay and within 60 calendar days of discovery.
  • Method: Formal press release issued to prominent media outlets serving the state or jurisdiction.

3. Notice to the Secretary of HHS (45 CFR § 164.408)

  • Breaches Affecting 500 or More Individuals: The covered entity must notify the Secretary of HHS electronically via the OCR website concurrently with individual notifications (within 60 calendar days of discovery). These breaches are publicly posted on the federal HHS breach portal.
  • Breaches Affecting Fewer Than 500 Individuals: The covered entity must maintain an internal breach log and report all smaller breaches to HHS OCR electronically no later than 60 days following the end of the calendar year in which the breaches were discovered.

4. Business Associate Notification (45 CFR § 164.410)

A business associate that discovers a breach must notify the covered entity without unreasonable delay and in no case later than 60 calendar days (though standard BAA contracts routinely enforce a much shorter window, such as 24 to 72 hours).

Loading diagram...
HITECH Breach Risk Assessment and Statutory Notification Protocol
Test Your Knowledge

An unencrypted external hard drive containing 750 abstracted oncology patient records—including full names, Social Security numbers, primary sites, histology codes, and stage groupings—is stolen from an oncology data specialist's vehicle. A subsequent forensic risk assessment fails to establish a low probability of data compromise. All 750 affected patients reside within the same state. Under the HITECH Breach Notification Rule, what notifications are legally required?

A

Individual written notices must be mailed within 180 days, with an annual summary submitted to the state medical board.

B

Only the hospital cancer committee must be notified, because cancer data is protected under state epidemiological reporting immunity.

C

Notice is required only to the Secretary of HHS at the end of the calendar year, because the total number of records is under 1,000.

D

Individual written notices must be sent within 60 calendar days, prominent media outlets in the state must be notified within 60 calendar days, and the Secretary of HHS must be notified via the OCR portal within 60 calendar days.

Test Your Knowledge

Under the HIPAA Security Rule (45 CFR § 164.306(d)), how must a covered entity or business associate legally treat an 'Addressable' implementation specification?

A

The entity must assess whether the measure is reasonable and appropriate, and either implement it, implement an equivalent alternative, or formally document why it is not reasonable and appropriate.

B

The specification represents an optional best-practice recommendation that may be ignored without compliance documentation.

C

The entity must seek an advance formal waiver from the Department of Health and Human Services before omitting the control.

D

The specification applies exclusively to academic medical centers and is not applicable to community hospital registries.

Test Your Knowledge

A cancer registrar reviewing an operative report steps away from their computer workstation to attend an unscheduled one-hour cancer conference without locking their terminal. A non-clinical visitor walking through the registry office observes detailed patient diagnostic and staging data displayed on the screen. Which technical safeguard defined under 45 CFR § 164.312 directly mitigates this vulnerability?

A

Automatic logoff mechanism

B

Emergency access 'break-glass' protocol

C

Cryptographic hashing integrity controls

D

Deterministic record linkage matching

Sections you finish are checked off in the contents.