Security obligations for protected health information include risk analysis, workforce training and sanctions, access controls with unique user identification, audit controls, integrity verification, and transmission security.
Requirements apply to covered entities and business associates including law firms.
Alternative Names:
PHI Security, Securing PHI
Why it Matters?
The risk analysis requirement is the foundational obligation and the one most often absent in law firms, since it requires a documented assessment of where protected health information resides and what threats apply. Enforcement actions frequently cite its absence as the underlying failure. For a firm handling medical records across litigation matters, the analysis must cover the review platforms, vendors, and devices where that data actually sits.
Frequently Confused with
Related terms
Frequently asked questions
What is the foundational requirement?
Does it apply to law firms?





