Back to blog
US & Americas

The HIPAA Security Rule explained: safeguards, scope and evidence

What the HIPAA Security Rule actually requires - the three safeguard categories, required versus addressable specifications, who is covered, and the evidence that satisfies an investigation.
GRC Copilot Team
The HIPAA Security Rule explained: safeguards, scope and evidence

The HIPAA Security Rule sets the standards for protecting electronic protected health information (ePHI). It is deliberately technology-neutral and scalable - which makes it flexible, and also makes it easy to convince yourself you comply when you cannot evidence it.

Who is covered

  • Covered entities - health plans, healthcare clearinghouses, and healthcare providers who transmit health information electronically in connection with covered transactions.
  • Business associates - anyone performing functions involving ePHI on behalf of a covered entity: cloud hosting, billing, analytics, transcription, IT support.
  • Subcontractors of business associates, who inherit obligations down the chain.

If you are a SaaS vendor whose product touches ePHI, you are almost certainly a business associate - and directly liable, not merely contractually exposed.

The three safeguard categories

Administrative safeguards

The largest group, and where most findings occur: a documented risk analysis and risk management process, assigned security responsibility, workforce security and access authorisation, security awareness training, incident procedures, contingency planning, and periodic evaluation.

Physical safeguards

Facility access controls, workstation use and security, and device and media controls - including how media is disposed of and reused. Media disposal is a recurring gap where old equipment leaves without verified sanitisation.

Technical safeguards

Access control with unique user identification and emergency access, audit controls, integrity controls, person or entity authentication, and transmission security.

Required versus addressable - the most misunderstood point

Some specifications are required; others are addressable. Addressable does not mean optional. It means you must assess whether the specification is reasonable and appropriate for your environment, and then either implement it, or implement an equivalent alternative, or document why neither is reasonable.

Treating "addressable" as "we skipped it" with no documented analysis is one of the clearest ways to fail an investigation. The analysis is the compliance artefact.

Evidence your HIPAA safeguards

GRC Copilot assesses you against the Security Rule, links each safeguard to real evidence, and maps the overlap with ISO 27001 and HITRUST so the work is done once.

The risk analysis is the foundation

Nearly every enforcement narrative starts the same way: no accurate, thorough, organisation-wide risk analysis. It must cover all ePHI wherever it lives - including laptops, backups, third-party systems and anything acquired through a merger. A one-page checklist is not a risk analysis, and it is the single most valuable artefact to get right.

Evidence that satisfies scrutiny

  • A dated, organisation-wide risk analysis with identified risks and a risk management plan.
  • Policies and procedures, approved and communicated.
  • Workforce training records with completion dates.
  • Access authorisation and termination records reconciled against HR data.
  • Audit log review evidence - not merely that logging exists, but that someone looks at it.
  • Business associate agreements for every vendor touching ePHI.
  • Contingency plan testing, including a restoration test.
  • Encryption decisions documented, including where you chose an alternative.

Where organisations fall short

  • Risk analysis limited to the EHR, ignoring email, file shares, backups and endpoints.
  • Business associate agreements missing for smaller vendors.
  • Termination procedures that leave accounts active after departure.
  • Audit logs collected but never reviewed.
  • Addressable specifications skipped with no documented rationale.
  • No evidence of contingency plan testing.

Frequently asked questions

Is HIPAA certifiable?

No. There is no official HIPAA certification. HITRUST CSF is the certifiable framework most often used to demonstrate alignment to partners, and third-party assessments are common, but neither is a government certification.

Is encryption mandatory?

It is an addressable specification, not a flat requirement. In practice, if you decline to encrypt ePHI you need a documented rationale and an equivalent alternative - and that is a difficult argument to sustain today.

Does ISO 27001 satisfy HIPAA?

It covers much of the underlying security substance and gives you the evidence discipline, but HIPAA has specific requirements - risk analysis, business associate agreements, workforce procedures - that must be addressed directly.

How often must the risk analysis be updated?

It is expected to be ongoing rather than a one-off, and updated on significant change - new systems, new locations, mergers, or after an incident.

Key takeaways

  • Business associates are directly liable, not just contractually bound.
  • "Addressable" means analyse and document - never silently skip.
  • An organisation-wide risk analysis is the foundational artefact.
  • Audit logs must be reviewed, not merely collected.
#hipaa #phi #healthcare #safeguards #us-regulation