Service
Risk assessments
Where you stand against NIST CSF 2.0 and CIS Controls
Compliance readiness
Risk analysis support, a safeguards review against the HIPAA Security Rule, and a remediation plan, with a clear line between the rule in force and changes HHS has only proposed.
45 CFR Part 164, Subpart C, as last substantively revised in 2013
Originally published February 20, 2003; last substantively revised January 25, 2013
As of 2026-09-26, HHS's proposed rule to update the Security Rule (published January 6, 2025, RIN 0945-AA22) has not been finalized or withdrawn. Its proposals aren't law.
Check the official HIPAA Security Rule source (external site)
HHS's January 2025 proposal to update the Security Rule had not been finalized or withdrawn as of 2026-09-26, so the 2013 rule text is still the law in force. Check the Federal Register for the proposal's current status before relying on this page.
The HIPAA Security Rule (45 CFR Part 164, Subpart C) is a federal regulation that sets security standards for the electronic protected health information (ePHI) that covered entities and business associates create, receive, maintain, or transmit.
The rule mixes required and addressable implementation specifications (45 CFR 164.306(d)), and it requires a periodic technical and nontechnical evaluation of how well your security policies and procedures meet it (164.308(a)(8)).
There is no official HIPAA certification. HHS says it doesn't endorse or otherwise recognize private organizations' certifications regarding the Security Rule, and that such certifications don't absolve covered entities of their legal obligations.
By law, HHS must consider whether an organization had recognized security practices in place for the previous 12 months when it decides on fines, audits, and other remedies (Public Law 116-321).
The first administrative safeguard in the HIPAA Security Rule is the security management process, and its first two implementation specifications are both required. The risk analysis specification says to “conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information held by the covered entity or business associate” (45 CFR 164.308(a)(1)(ii)(A)).
Risk management then says to “implement security measures sufficient to reduce risks and vulnerabilities to a reasonable and appropriate level” (164.308(a)(1)(ii)(B)). The rule's own term is risk analysis, though many people call it a HIPAA risk assessment or a security risk assessment.
The rule sets no fixed interval for redoing the analysis. It does require a periodic technical and nontechnical evaluation, first against the standards and then in response to environmental or operational changes that affect the security of ePHI (164.308(a)(8)). Documentation must be reviewed periodically, updated as needed, and kept for six years from its creation or the date it was last in effect, whichever is later (164.316(b)(2)).
Sources: eCFR: 45 CFR 164.308, administrative safeguards; eCFR: 45 CFR 164.316, policies, procedures and documentation
Read the full guide: HIPAA security risk analysis: what the rule requires
The Security Rule groups its standards into three families of safeguards, alongside organizational requirements (164.314) and policy and documentation requirements (164.316). The table lists every safeguard standard by the name the rule gives it.
Each standard may carry implementation specifications, and each specification is marked in the rule as required or addressable.
| Safeguard family | Section | Standards |
|---|---|---|
| Administrative safeguards | 164.308 | Security management process; assigned security responsibility; workforce security; information access management; security awareness and training; security incident procedures; contingency plan; evaluation; business associate contracts and other arrangements |
| Physical safeguards | 164.310 | Facility access controls; workstation use; workstation security; device and media controls |
| Technical safeguards | 164.312 | Access control; audit controls; integrity; person or entity authentication; transmission security |
Sources: eCFR: 45 CFR 164.308, administrative safeguards; eCFR: 45 CFR 164.310, physical safeguards; eCFR: 45 CFR 164.312, technical safeguards
Read the full guide: HIPAA Security Rule checklist: every standard, explained
Every implementation specification in the Security Rule is labeled either required or addressable (45 CFR 164.306(d)). Required specifications must be implemented.
Addressable doesn't mean optional. For each addressable specification, you assess whether it is a reasonable and appropriate safeguard in your environment. If it is, you implement it. If it isn't, you document why, and you implement an equivalent alternative measure if that is reasonable and appropriate (164.306(d)(3)).
The technical safeguards show both kinds side by side. Under access control, unique user identification and an emergency access procedure are required, while automatic logoff and encryption and decryption are addressable (164.312(a)(2)). When choosing security measures, the rule lets you weigh your size, complexity and capabilities, your technical infrastructure, the costs of the measures, and the probability and criticality of potential risks to ePHI (164.306(b)(2)).
HHS's January 2025 proposal would remove the distinction between required and addressable specifications. As of 2026-09-27, the proposal hasn't been finalized or withdrawn, so the distinction still applies.
Sources: eCFR: 45 CFR 164.306, security standards: general rules; eCFR: 45 CFR 164.312, technical safeguards; Federal Register: HIPAA Security Rule To Strengthen the Cybersecurity of ePHI (proposed rule, 90 FR 898, January 6, 2025)
A business associate is a person or organization, other than a member of the workforce, that creates, receives, maintains, or transmits protected health information on behalf of a covered entity for a function or activity the HIPAA rules regulate, or that provides certain services to a covered entity, such as legal, accounting, or consulting services, involving protected health information. The definition also includes subcontractors that do the same on behalf of a business associate (45 CFR 160.103).
Before a business associate creates, receives, maintains, or transmits electronic protected health information for a covered entity, the covered entity must obtain satisfactory assurances, documented in a written contract or other arrangement, that the business associate will appropriately safeguard it. A business associate needs the same from its own subcontractors (164.308(b)). Under 164.314(a)(2)(i), the contract must provide that the business associate will:
Sources: eCFR: 45 CFR 160.103, definitions (business associate, covered entity, ePHI); eCFR: 45 CFR 164.308, administrative safeguards; eCFR: 45 CFR 164.314, organizational requirements (business associate contracts)
Read the full guide: HIPAA for SaaS companies: when you're a business associate
Two government resources, both available to download from official sites, help with the risk analysis and the safeguards. Neither is a certification, and using them doesn't establish compliance on its own.
Whichever you use, the risk analysis still has to reflect your own systems, locations, and service providers, and it has to be documented and kept current as the rule requires.
Sources: NIST SP 800-66 Rev. 2, Implementing the HIPAA Security Rule: A Cybersecurity Resource Guide (February 2024); HealthIT.gov: Security Risk Assessment (SRA) Tool
Readiness work prepares you. The formal outcome below comes only from the organization the program authorizes.
No official certificationNo official certification exists for the HIPAA Security Rule. Readiness here means meeting the rule itself and being able to show how you meet it.
Security Inspect is not a law firm, a CPA firm, or an ISO/IEC 27001 certification body. We don't give legal opinions, issue SOC 2 reports or ISO/IEC 27001 certificates, or guarantee that a client will pass an assessment.
HIPAA Security Rule readiness — risk analysis support, safeguards review, and remediation planning.
Because HIPAA has no official certification or assessor program, there's no assessor independence rule like the ones PCI DSS, CMMC, SOC 2, and ISO/IEC 27001 impose. If you use an outside organization for your periodic evaluation, choose one whose objectivity you can rely on, and remember that HHS doesn't recognize private certifications.
When a program requires a formal assessment, audit, or certification, it's performed by an independent, authorized assessor. We keep advisory work and formal assessment apart: a practitioner never assesses controls they designed, developed, or implemented.
Every engagement begins with a written scope and proposal.
Identify where ePHI is created, received, stored, and transmitted, including the vendors and service providers involved.
Assess threats and vulnerabilities to ePHI, and rate the risks together with your team.
Compare your safeguards with the Security Rule's standards and implementation specifications, including which are required and which are addressable.
Agree on a prioritized plan. Your organization decides what to implement and documents its reasoning.
Organize the records that show your analysis and decisions, and set up the periodic evaluation the rule requires.
From $8,000
Typical scoped range: $8,000 to $20,000
One-time project
Non-binding. Final pricing follows a written scope and proposal.
Pricing depends on environment size, complexity, testing depth, locations, applications, accounts, user roles, compliance objectives, and delivery timeline. Every engagement begins with a written scope and proposal. Taxes, travel, remediation, third-party audit or certification fees, licensing, and emergency work are separate. Readiness services do not include independent certification, attestation, legal advice, or a guarantee of passing.
No. The Security Rule applies to electronic protected health information (45 CFR 164.302). Protected health information can also be held on paper or in other forms, and the HIPAA Privacy Rule requires covered entities to have appropriate administrative, technical, and physical safeguards to protect its privacy (45 CFR 160.103 and 164.530(c)).
No. As of 2026-09-26, HHS's proposed rule (published January 6, 2025, RIN 0945-AA22) has not been finalized or withdrawn, and the 2013 rule text is still the law in force. The proposal would, among other things, remove the distinction between required and addressable specifications and add requirements such as encryption, multifactor authentication, regular vulnerability scanning, and annual penetration testing. Treat these as possible future requirements, not current law.
No outside review can confer compliance. Compliance depends on your organization putting the rule's safeguards in place, keeping them working, and documenting its decisions. An outside review helps you find and prioritize gaps. Separately, HHS must consider recognized security practices you've had in place for the previous 12 months when it decides on fines, audits, and remedies (Public Law 116-321).
Build your plan on a current risk analysis under the rule in force, and track the proposal's status in the Federal Register before treating any of it as a requirement. Some proposed safeguards, such as multifactor authentication and encryption, may already be on your list for risk reasons; if so, note that they would also line up with the proposal.
Information on this website is general and educational. It isn't legal advice, and it doesn't create a client relationship.
Tell us what’s driving the work and who’s asking for it, and we’ll help you judge where you stand and whether readiness support makes sense.