# What is the HIPAA Security Rule?

> The Health Insurance Portability and Accountability Act (HIPAA) Security Rule is a United States regulation requiring covered entities and business associates to protect electronic protected health information (ePHI).

- Canonical URL: https://yellowcube.eu/glossary/hipaa-security-rule/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

It establishes administrative, physical, and technical safeguards to preserve ePHI confidentiality, integrity, and availability against reasonably anticipated threats, hazards, and impermissible uses or disclosures.

The current rule appears at 45 Code of Federal Regulations Part 160 and Part 164, Subparts A and C. It is risk-based and technology-neutral: regulated entities must analyze risks, choose reasonable and appropriate safeguards, document decisions, assign responsibility, train personnel, manage access, prepare for contingencies, and periodically evaluate their controls. On January 6, 2025, HHS published proposed modifications; as of August 4, 2026, they are not final, and HHS says the current rule remains in effect.

### Key points

- **Know the boundary:** Inventory all ePHI created, received, maintained, or transmitted, including cloud, mobile, medical-device, backup, and business-associate environments.
- **Manage risk:** Perform and document an accurate risk analysis, reduce identified risks to a reasonable and appropriate level, and update safeguards when operations, technology, threats, or law change.
- **Interpret specifications:** “Addressable” does not mean optional; the entity must implement the specification when reasonable and appropriate or document why an equivalent measure or another decision is appropriate.
- **Important limitation:** The Security Rule is not a product checklist or a voluntary certification. The Privacy and Breach Notification Rules impose different duties, and only qualified legal analysis can determine an entity’s obligations in a particular incident or arrangement.

### Related terms

[Data privacy](<https://yellowcube.eu/glossary/data-privacy/>) · [Data security](<https://yellowcube.eu/glossary/data-security/>) · [Data breach](<https://yellowcube.eu/glossary/data-breach/>) · [Cyber risk](<https://yellowcube.eu/glossary/cyber-risk/>) · [Incident response (IR)](<https://yellowcube.eu/glossary/incident-response/>)

### Sources

[U.S. Department of Health and Human Services, The Security Rule](https://www.hhs.gov/hipaa/for-professionals/security/index.html) · [HHS, Summary of the HIPAA Security Rule](https://www.hhs.gov/hipaa/for-professionals/security/laws-regulations/index.html) · [HHS, Guidance on Risk Analysis](https://www.hhs.gov/hipaa/for-professionals/security/guidance/guidance-risk-analysis/index.html) · [HHS, HIPAA Security Rule NPRM](https://www.hhs.gov/hipaa/for-professionals/security/hipaa-security-rule-nprm/index.html)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

