The Security Rule requires covered entities and business associates to protect electronic protected health information through administrative safeguards such as risk analysis and workforce training, physical safeguards for facilities and devices, and technical safeguards including access control, audit controls, and transmission security.
Specifications are either required or addressable, with addressable items demanding documented assessment rather than being optional.
Alternative Names:
Security Rule, HIPAA Security Standards
Why it Matters?
Law firms handling medical records in injury, malpractice, and long-term care litigation are business associates and are directly subject to the rule. That obligation extends to their vendors, which is why business associate agreements are required down the chain. Firms frequently underestimate this, treating HIPAA as the client's compliance problem rather than their own.
Frequently Confused with
Related terms
Frequently asked questions
Are law firms subject to the HIPAA Security Rule?
What does addressable mean?





