HIPAA Security Rule

HIPAA Security Rule

HIPAA Security Rule

The Security Rule requires covered entities and business associates to protect electronic protected health information through administrative safeguards such as risk analysis and workforce training, physical safeguards for facilities and devices, and technical safeguards including access control, audit controls, and transmission security.

Specifications are either required or addressable, with addressable items demanding documented assessment rather than being optional.

Alternative Names:

Security Rule, HIPAA Security Standards

Why it Matters?

Law firms handling medical records in injury, malpractice, and long-term care litigation are business associates and are directly subject to the rule. That obligation extends to their vendors, which is why business associate agreements are required down the chain. Firms frequently underestimate this, treating HIPAA as the client's compliance problem rather than their own.

Frequently Confused with

Related terms

Frequently asked questions

Are law firms subject to the HIPAA Security Rule?

Are law firms subject to the HIPAA Security Rule?

Yes, when handling protected health information on behalf of a covered entity. The firm is a business associate with direct compliance obligations.

What does addressable mean?

What does addressable mean?

Not optional. The organization must assess whether the specification is reasonable and appropriate, implement it if so, and document the analysis if not.