Cybersecurity Compliance Guide for Businesses
HIPAA Security Requirements: Safeguards for Health Data
HIPAA Security Rule requires three categories of safeguards for electronic Protected Health Information (ePHI): administrative safeguards (risk analysis, workforce training, contingency planning), physical safeguards (facility access, workstation security), and technical safeguards (access control, audit controls, transmission security, integrity controls).

Andreas Johansson · Chief Executive Officer
Senior IT management leader with 25 years of experience in Cloud, Security, and Datacenter infrastructure.
HIPAA Security Rule Overview
The HIPAA Security Rule (45 CFR Part 164 Subpart C) establishes national standards for protecting electronic Protected Health Information (ePHI). It applies to covered entities (healthcare providers, health plans, healthcare clearinghouses) and their business associates (organizations that handle ePHI on their behalf).
The Security Rule requires implementing safeguards that are "reasonable and appropriate" — recognizing that smaller organizations may implement different solutions than large health systems while meeting the same security objectives.
Administrative Safeguards (§164.308)
Administrative safeguards are the policies, procedures, and management practices that protect ePHI:
- Risk analysis (Required). Conduct an accurate and thorough assessment of potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI. Risk analysis is the foundation — every other safeguard should address identified risks.
- Risk management (Required). Implement security measures sufficient to reduce risks to a reasonable and appropriate level. Document decisions and rationale for accepted risks.
- Sanction policy (Required). Apply appropriate sanctions against workforce members who violate security policies.
- Information system activity review (Required). Regularly review audit logs, access reports, and security incident tracking. This is HIPAA's monitoring requirement.
- Workforce security. Implement procedures for authorizing access to ePHI. Ensure workforce members have appropriate access based on their role. Terminate access when no longer needed.
- Security awareness and training (Required). Train all workforce members on security policies, phishing recognition, password management, and incident reporting. Training should be ongoing, not one-time.
- Security incident procedures (Required). Identify and respond to suspected or known security incidents. Document incidents and their outcomes.
- Contingency plan (Required). Establish data backup, disaster recovery, and emergency operations plans. Test plans periodically.
- Business associate agreements (Required). Establish BAAs with all organizations that access, store, or transmit ePHI on your behalf. BAAs must specify security obligations and breach notification requirements.
Physical Safeguards (§164.310)
- Facility access controls. Implement policies and procedures to limit physical access to systems containing ePHI. Include visitor management, access logs, and restricted areas.
- Workstation use. Define policies for the appropriate use and protection of workstations that access ePHI. Address screen locking, clean desk policies, and remote work security.
- Workstation security. Implement physical protections for workstations — preventing theft, unauthorized access, and unauthorized viewing.
- Device and media controls. Establish procedures for disposal, re-use, and transfer of electronic media containing ePHI. Ensure data is properly destroyed when devices are decommissioned.
Technical Safeguards (§164.312)
- Access control (Required). Implement technical policies and procedures to limit access to ePHI to authorized persons:
- Unique user identification (required) — Each user has a unique identifier
- Emergency access procedure (required) — Access ePHI during emergencies
- Automatic logoff (addressable) — Session timeout after inactivity
- Encryption and decryption (addressable) — Encrypt ePHI at rest
- Audit controls (Required). Implement hardware, software, and procedural mechanisms to record and examine access and activity in systems containing ePHI. Log access to ePHI, configuration changes, and authentication events.
- Integrity controls. Implement policies and procedures to protect ePHI from improper alteration or destruction. Use checksums, digital signatures, or other integrity verification mechanisms.
- Person or entity authentication (Required). Verify that persons or entities seeking access to ePHI are who they claim to be. Implement strong authentication — multi-factor authentication is strongly recommended though not explicitly required.
- Transmission security. Implement technical security measures to guard against unauthorized access to ePHI transmitted over electronic networks. Use encryption for ePHI in transit (TLS 1.2+).
Required vs Addressable Specifications
HIPAA uses "required" and "addressable" classifications:
- Required specifications must be implemented as written — there's no flexibility.
- Addressable specifications must be assessed — if the measure is reasonable and appropriate for your environment, implement it. If not, document why and implement an equivalent alternative. "Addressable" does not mean "optional."
HIPAA in Cloud Environments
- Business Associate Agreements. Your cloud provider must sign a BAA before hosting ePHI. AWS, Azure, and GCP all offer BAAs — but signing the BAA is your responsibility.
- Encryption. Encrypt ePHI at rest and in transit. Use cloud-native encryption with customer-managed keys for maximum control.
- Access logging. Enable comprehensive logging for all systems handling ePHI. Retain logs per your retention policy (HIPAA doesn't specify a period, but 6 years is common practice aligned with the general HIPAA record retention requirement).
- Segmentation. Isolate systems containing ePHI from general-purpose infrastructure. Use separate VPCs, accounts, or subscriptions for healthcare workloads.
HIPAA Breach Notification
- Individual notification. Notify affected individuals within 60 days of discovering a breach affecting their ePHI.
- HHS notification. Report breaches to the Department of Health and Human Services. Breaches affecting 500+ individuals must be reported within 60 days. Smaller breaches can be reported annually.
- Media notification. Breaches affecting 500+ individuals in a single jurisdiction require notification to prominent media outlets.
How SeqOps fits
SeqOps checks your cloud and server configuration against many compliance frameworks, shows which controls pass or fail, and sends scheduled reports you can share with management and auditors. It supports your compliance work; it doesn't certify you.
Sources
- 45 CFR Part 164 Subpart C, HIPAA Security Standards for the Protection of ePHI (Cornell LII)
- 45 CFR 160.404, HIPAA civil money penalty amounts for violations on or after 18 Feb 2009 (Cornell LII) (2009)
- 42 U.S.C. 1320d-6, Wrongful disclosure of individually identifiable health information (Cornell LII) (1996)