Jump to a page

32 pages.

All servicesAssessments, testing, and advisory work for security and compliance programs.
PCI DSS readinessScoping, readiness, and remediation for card-payment environments
Penetration testingAuthorized testing of apps, APIs, and networks
Compliance readinessSOC 2, ISO/IEC 27001, HIPAA, and CMMC readiness
Cloud & application securityArchitecture, configuration, and identity reviews
vCISO advisorySecurity leadership without a full-time hire
Incident readinessResponse plans and tabletop exercises
Risk assessmentsWhere you stand against NIST CSF 2.0 and CIS Controls
Policies, controls & evidenceA security program you can repeat and prove
Vendor riskThird-party reviews with clear priorities
Find the right service
SOC 2 readiness
ISO/IEC 27001 readiness
HIPAA Security Rule readiness
CMMC readiness
Assurance and trust centerHow to check credentials, how engagements run, how we stay independent, and how this website handles your data.
Credentials & authorizationsHow credentials and authorizations work, and how to check them
MethodologyHow engagements are scoped, run, and reported
IndependenceHow advisory work stays separate from formal assessment
Responsible disclosureHow to report a security issue in our website or systems
About
Team
Industries
Pricing
Contact
InsightsPlain-language articles on security and compliance topics
GlossarySecurity and compliance terms, defined in plain language
Search the siteServices, readiness guides, glossary terms, and articles
Privacy notice
Terms of use
Accessibility
Privacy choices

Compliance readiness

HIPAA Security Rule readiness: risk analysis and safeguards review

Risk analysis support, a safeguards review against the HIPAA Security Rule, and a remediation plan, with a clear line between the rule in force and changes HHS has only proposed.

Version as of

45 CFR Part 164, Subpart C, as last substantively revised in 2013

Originally published February 20, 2003; last substantively revised January 25, 2013

As of 2026-09-26, HHS's proposed rule to update the Security Rule (published January 6, 2025, RIN 0945-AA22) has not been finalized or withdrawn. Its proposals aren't law.

Check the official HIPAA Security Rule source (external site)

Regulatory status changes — last checked September 26, 2026

HHS's January 2025 proposal to update the Security Rule had not been finalized or withdrawn as of 2026-09-26, so the 2013 rule text is still the law in force. Check the Federal Register for the proposal's current status before relying on this page.

What is the HIPAA Security Rule?

The HIPAA Security Rule (45 CFR Part 164, Subpart C) is a federal regulation that sets security standards for the electronic protected health information (ePHI) that covered entities and business associates create, receive, maintain, or transmit.

The rule mixes required and addressable implementation specifications (45 CFR 164.306(d)), and it requires a periodic technical and nontechnical evaluation of how well your security policies and procedures meet it (164.308(a)(8)).

There is no official HIPAA certification. HHS says it doesn't endorse or otherwise recognize private organizations' certifications regarding the Security Rule, and that such certifications don't absolve covered entities of their legal obligations.

By law, HHS must consider whether an organization had recognized security practices in place for the previous 12 months when it decides on fines, audits, and other remedies (Public Law 116-321).

Type
Federal regulation
Current version, as of
45 CFR Part 164, Subpart C, as last substantively revised in 2013. Originally published February 20, 2003; last substantively revised January 25, 2013. Version source for HIPAA Security Rule (external site)

Who needs HIPAA Security Rule readiness?

  • Healthcare providers, health plans, and other organizations subject to HIPAA that handle ePHI
  • Vendors and service providers that handle ePHI for healthcare organizations and are asked to show how they protect it
  • Organizations that haven't refreshed their risk analysis since their systems or vendors changed
  • Teams that want to plan for HHS's proposed changes without treating them as current law

The risk analysis at the center of the rule

The first administrative safeguard in the HIPAA Security Rule is the security management process, and its first two implementation specifications are both required. The risk analysis specification says to “conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information held by the covered entity or business associate” (45 CFR 164.308(a)(1)(ii)(A)).

Risk management then says to “implement security measures sufficient to reduce risks and vulnerabilities to a reasonable and appropriate level” (164.308(a)(1)(ii)(B)). The rule's own term is risk analysis, though many people call it a HIPAA risk assessment or a security risk assessment.

The rule sets no fixed interval for redoing the analysis. It does require a periodic technical and nontechnical evaluation, first against the standards and then in response to environmental or operational changes that affect the security of ePHI (164.308(a)(8)). Documentation must be reviewed periodically, updated as needed, and kept for six years from its creation or the date it was last in effect, whichever is later (164.316(b)(2)).

Sources: eCFR: 45 CFR 164.308, administrative safeguards; eCFR: 45 CFR 164.316, policies, procedures and documentation

Administrative, physical and technical safeguards

The Security Rule groups its standards into three families of safeguards, alongside organizational requirements (164.314) and policy and documentation requirements (164.316). The table lists every safeguard standard by the name the rule gives it.

Each standard may carry implementation specifications, and each specification is marked in the rule as required or addressable.

HIPAA Security Rule safeguard standards (45 CFR 164.308, 164.310 and 164.312)
Safeguard familySectionStandards
Administrative safeguards164.308Security management process; assigned security responsibility; workforce security; information access management; security awareness and training; security incident procedures; contingency plan; evaluation; business associate contracts and other arrangements
Physical safeguards164.310Facility access controls; workstation use; workstation security; device and media controls
Technical safeguards164.312Access control; audit controls; integrity; person or entity authentication; transmission security

Sources: eCFR: 45 CFR 164.308, administrative safeguards; eCFR: 45 CFR 164.310, physical safeguards; eCFR: 45 CFR 164.312, technical safeguards

Required vs addressable implementation specifications

Every implementation specification in the Security Rule is labeled either required or addressable (45 CFR 164.306(d)). Required specifications must be implemented.

Addressable doesn't mean optional. For each addressable specification, you assess whether it is a reasonable and appropriate safeguard in your environment. If it is, you implement it. If it isn't, you document why, and you implement an equivalent alternative measure if that is reasonable and appropriate (164.306(d)(3)).

The technical safeguards show both kinds side by side. Under access control, unique user identification and an emergency access procedure are required, while automatic logoff and encryption and decryption are addressable (164.312(a)(2)). When choosing security measures, the rule lets you weigh your size, complexity and capabilities, your technical infrastructure, the costs of the measures, and the probability and criticality of potential risks to ePHI (164.306(b)(2)).

HHS's January 2025 proposal would remove the distinction between required and addressable specifications. As of 2026-09-27, the proposal hasn't been finalized or withdrawn, so the distinction still applies.

Sources: eCFR: 45 CFR 164.306, security standards: general rules; eCFR: 45 CFR 164.312, technical safeguards; Federal Register: HIPAA Security Rule To Strengthen the Cybersecurity of ePHI (proposed rule, 90 FR 898, January 6, 2025)

Vendors that handle ePHI for you

A business associate is a person or organization, other than a member of the workforce, that creates, receives, maintains, or transmits protected health information on behalf of a covered entity for a function or activity the HIPAA rules regulate, or that provides certain services to a covered entity, such as legal, accounting, or consulting services, involving protected health information. The definition also includes subcontractors that do the same on behalf of a business associate (45 CFR 160.103).

Before a business associate creates, receives, maintains, or transmits electronic protected health information for a covered entity, the covered entity must obtain satisfactory assurances, documented in a written contract or other arrangement, that the business associate will appropriately safeguard it. A business associate needs the same from its own subcontractors (164.308(b)). Under 164.314(a)(2)(i), the contract must provide that the business associate will:

  • Comply with the applicable requirements of the Security Rule
  • Ensure that subcontractors handling ePHI on its behalf agree to the same requirements through their own contract or arrangement
  • Report to the covered entity any security incident it becomes aware of, including breaches of unsecured protected health information

Sources: eCFR: 45 CFR 160.103, definitions (business associate, covered entity, ePHI); eCFR: 45 CFR 164.308, administrative safeguards; eCFR: 45 CFR 164.314, organizational requirements (business associate contracts)

Government resources for HIPAA security

Two government resources, both available to download from official sites, help with the risk analysis and the safeguards. Neither is a certification, and using them doesn't establish compliance on its own.

Whichever you use, the risk analysis still has to reflect your own systems, locations, and service providers, and it has to be documented and kept current as the rule requires.

  • NIST SP 800-66 Rev. 2, Implementing the HIPAA Security Rule: A Cybersecurity Resource Guide (February 2024), offers practical guidance and resources that regulated entities of all sizes can use to safeguard ePHI and to understand the security concepts in the rule.
  • The Security Risk Assessment (SRA) Tool, developed by the Office of the National Coordinator for Health IT in collaboration with the HHS Office for Civil Rights, was at version 3.7 when checked on 2026-09-27. Its stated target audience is small and medium providers, and its page says: “Use of this tool is neither required by nor guarantees compliance with federal, state or local laws.”

Sources: NIST SP 800-66 Rev. 2, Implementing the HIPAA Security Rule: A Cybersecurity Resource Guide (February 2024); HealthIT.gov: Security Risk Assessment (SRA) Tool

Formal assessment: who performs it, and on whose authority

Readiness work prepares you. The formal outcome below comes only from the organization the program authorizes.

No official certificationNo official certification exists for the HIPAA Security Rule. Readiness here means meeting the rule itself and being able to show how you meet it.

Formal outcome
None. There is no official HIPAA certification or HHS-approved assessment.
Who performs it
Not applicable. HHS's Office for Civil Rights enforces the rule. The periodic evaluation the rule requires (164.308(a)(8)) may be done by your own staff or by an outside organization, but no one can issue an official HIPAA certification.

Outside our services

Security Inspect is not a law firm, a CPA firm, or an ISO/IEC 27001 certification body. We don't give legal opinions, issue SOC 2 reports or ISO/IEC 27001 certificates, or guarantee that a client will pass an assessment.

What we do and don’t do

HIPAA Security Rule readiness — risk analysis support, safeguards review, and remediation planning.

What we do

  • Support for your risk analysis: where ePHI lives and moves, threats and vulnerabilities, and risk ratings
  • Safeguards review and gap assessment against 45 CFR Part 164, Subpart C
  • A prioritized remediation plan tied to your risk analysis
  • Policy and procedure recommendations that your team adopts
  • Planning notes on HHS's proposed 2025 changes, clearly labeled as proposals
  • Mapping to recognized security practices, such as NIST CSF 2.0, where it helps

What we don’t do

  • Certify, attest to, or approve your HIPAA compliance; no one can issue an official HIPAA certification
  • Give legal advice about HIPAA obligations, breach notification, or business associate agreements
  • Present the proposed rule's requirements as current law
  • Make risk decisions for you; your organization decides and documents them

Independence

Because HIPAA has no official certification or assessor program, there's no assessor independence rule like the ones PCI DSS, CMMC, SOC 2, and ISO/IEC 27001 impose. If you use an outside organization for your periodic evaluation, choose one whose objectivity you can rely on, and remember that HHS doesn't recognize private certifications.

When a program requires a formal assessment, audit, or certification, it's performed by an independent, authorized assessor. We keep advisory work and formal assessment apart: a practitioner never assesses controls they designed, developed, or implemented.

How advisory work and formal assessment stay separate

How readiness works

Every engagement begins with a written scope and proposal.

  1. Map ePHI

    Identify where ePHI is created, received, stored, and transmitted, including the vendors and service providers involved.

  2. Analyze risk

    Assess threats and vulnerabilities to ePHI, and rate the risks together with your team.

  3. Review safeguards

    Compare your safeguards with the Security Rule's standards and implementation specifications, including which are required and which are addressable.

  4. Plan remediation

    Agree on a prioritized plan. Your organization decides what to implement and documents its reasoning.

  5. Keep it current

    Organize the records that show your analysis and decisions, and set up the periodic evaluation the rule requires.

Deliverables

  • Risk analysis support: ePHI inventory, risk register, and ratings
  • Safeguards gap assessment against 45 CFR Part 164, Subpart C
  • Prioritized remediation plan
  • Summary of HHS's proposed changes and how they would affect you, labeled as proposals

What HIPAA Security Rule readiness costs

  • HIPAA Security Readiness

    From $8,000

    Typical scoped range: $8,000 to $20,000

    One-time project

Non-binding. Final pricing follows a written scope and proposal.

What affects the final price

Pricing depends on environment size, complexity, testing depth, locations, applications, accounts, user roles, compliance objectives, and delivery timeline. Every engagement begins with a written scope and proposal. Taxes, travel, remediation, third-party audit or certification fees, licensing, and emergency work are separate. Readiness services do not include independent certification, attestation, legal advice, or a guarantee of passing.

Compare published prices for every service

Guides

Frequently asked questions

Does the HIPAA Security Rule cover paper records?

No. The Security Rule applies to electronic protected health information (45 CFR 164.302). Protected health information can also be held on paper or in other forms, and the HIPAA Privacy Rule requires covered entities to have appropriate administrative, technical, and physical safeguards to protect its privacy (45 CFR 160.103 and 164.530(c)).

Is the 2025 proposed Security Rule update in effect?

No. As of 2026-09-26, HHS's proposed rule (published January 6, 2025, RIN 0945-AA22) has not been finalized or withdrawn, and the 2013 rule text is still the law in force. The proposal would, among other things, remove the distinction between required and addressable specifications and add requirements such as encryption, multifactor authentication, regular vulnerability scanning, and annual penetration testing. Treat these as possible future requirements, not current law.

Does an outside review make us HIPAA compliant?

No outside review can confer compliance. Compliance depends on your organization putting the rule's safeguards in place, keeping them working, and documenting its decisions. An outside review helps you find and prioritize gaps. Separately, HHS must consider recognized security practices you've had in place for the previous 12 months when it decides on fines, audits, and remedies (Public Law 116-321).

How should we plan for the proposed changes?

Build your plan on a current risk analysis under the rule in force, and track the proposal's status in the Federal Register before treating any of it as a requirement. Some proposed safeguards, such as multifactor authentication and encryption, may already be on your list for risk reasons; if so, note that they would also line up with the proposal.

Educational information, not legal advice

Information on this website is general and educational. It isn't legal advice, and it doesn't create a client relationship.

Primary sources

Talk to a practitioner about HIPAA Security Rule readiness

Tell us what’s driving the work and who’s asking for it, and we’ll help you judge where you stand and whether readiness support makes sense.

What happens next

  1. Tell us about your environment and the formal outcome you're working toward.
  2. Talk through scope, timing, and options with a practitioner.
  3. Review the proposal and decide whether to go ahead.