It establishes administrative, physical, and technical safeguards to preserve ePHI confidentiality, integrity, and availability against reasonably anticipated threats, hazards, and impermissible uses or disclosures.
The current rule appears at 45 Code of Federal Regulations Part 160 and Part 164, Subparts A and C. It is risk-based and technology-neutral: regulated entities must analyze risks, choose reasonable and appropriate safeguards, document decisions, assign responsibility, train personnel, manage access, prepare for contingencies, and periodically evaluate their controls. On January 6, 2025, HHS published proposed modifications; as of August 4, 2026, they are not final, and HHS says the current rule remains in effect.
Key points
Know the boundaryInventory all ePHI created, received, maintained, or transmitted, including cloud, mobile, medical-device, backup, and business-associate environments.
Manage riskPerform and document an accurate risk analysis, reduce identified risks to a reasonable and appropriate level, and update safeguards when operations, technology, threats, or law change.
Interpret specifications“Addressable” does not mean optional; the entity must implement the specification when reasonable and appropriate or document why an equivalent measure or another decision is appropriate.
Important limitationThe Security Rule is not a product checklist or a voluntary certification. The Privacy and Breach Notification Rules impose different duties, and only qualified legal analysis can determine an entity’s obligations in a particular incident or arrangement.