HIPAA Security Rule policies: what small practices need
The HIPAA Security Rule requires written policies. A plain-English checklist of the safeguards they must cover, required versus addressable, and how long to keep them.
If you are a covered entity, such as a healthcare provider or health plan, or a business associate that handles electronic protected health information (ePHI) for one, the HIPAA Security Rule requires you to put safeguards in place and to document them in written policies and procedures.
NoteThis guide summarizes the current rule. HHS proposed a major update to the Security Rule in January 2025; as of this writing it has not been finalized. This is general information, not legal advice.
Required versus addressable
Each standard has implementation specifications marked required or addressable. Required means you must do it. Addressable does not mean optional: you must assess whether it is reasonable for you, and either implement it, implement an equivalent alternative, or document why neither is reasonable.
Administrative safeguards (45 CFR 164.308)
- Security management processRisk analysis, risk management, a sanction policy for staff who break the rules, and information system activity review (all required).
- Assigned security responsibilityOne named person responsible for security.
- Workforce securityAuthorization or supervision, clearance, and termination procedures (addressable).
- Information access managementHow access to ePHI is authorized, set up and changed.
- Security awareness and trainingReminders, protection from malicious software, log-in monitoring and password management (addressable).
- Security incident proceduresIdentify, respond to, mitigate and document security incidents (required).
- Contingency planData backup, disaster recovery and emergency mode operation plans (required), plus testing and revision, and an applications and data criticality analysis (addressable).
- EvaluationPeriodic technical and non-technical evaluation of your safeguards.
- Business associate contractsWritten agreements with vendors who handle ePHI for you (required).
Physical safeguards (164.310)
- Facility access controls: who can get into areas with systems holding ePHI.
- Workstation use and workstation security.
- Device and media controls: disposal, re-use, tracking and backup of hardware and media.
Technical safeguards (164.312)
- Access control: unique user IDs and emergency access (required), automatic logoff and encryption (addressable).
- Audit controls: record and examine activity in systems with ePHI.
- Integrity: protect ePHI from being changed or destroyed improperly.
- Person or entity authentication: verify that people are who they say they are.
- Transmission security: protect ePHI sent over networks, including encryption where appropriate.
Documentation rules (164.316)
- Keep policies, procedures and required records in writing, which can be electronic.
- Keep them for six years from when they were created or last in effect, whichever is later.
- Make them available to the people responsible for carrying them out.
- Review them periodically and update them when your environment or operations change.
Where small practices usually fall short
- No documented, up-to-date risk analysis, one of the gaps HHS enforcement actions cite most often.
- Policies copied from a template that do not match how the practice actually works.
- Missing business associate agreements with IT providers and software vendors.
- A contingency plan that has never been tested.
General information, not legal advice. Laws, contracts and provider processes change; check the linked sources for current details.