Definition
HIPAA Security Rule
The HIPAA Security Rule sets the federal standards for protecting electronic protected health information through administrative, physical, and technical safeguards. It requires each organization to run a risk analysis, then apply reasonable and appropriate controls such as access management, encryption where warranted, audit logging, and workforce training. The rule is deliberately flexible, letting a small clinic and a national insurer meet the same goals at a scale that fits them. Some safeguards are labeled required and others addressable, but addressable never means optional; it means you either implement the safeguard or document why an equivalent measure serves better.
Related services
Keep exploring
← Back to the full glossary