HIPAA Security Rule
HIPAA Security Rule is a federal rule published as 45 CFR Part 164, Subpart C. Adopted 2003-02-20, applies from 2005-04-20. In force: In force. Covered entities and business associates apply the safeguards to electronic protected health information.
- HIPAA Security Rule covers administrative safeguards, physical safeguards, technical safeguards and business associate contracts.
- HIPAA Security Rule does not settle whether a single company meets it. That is read in the company's own text and its filings.
- Supervised by U.S. Department of Health and Human Services, Office for Civil Rights. The text is published by Electronic Code of Federal Regulations and U.S. Department of Health and Human Services, Office for Civil Rights.
- The text names healthcare, technology and insurance.
- gdpr-2016-679: Both texts require documented security measures and written terms with processors. HIPAA is limited to health data, the EU text is not.
- US regulatory register
- Healthcare
- Technology
- Insurance
- U.S. Department of Health and Human Services, Office for Civil Rights
- GDPR — Regulation (EU) 2016/679
Identity
| Identifier | 45 CFR Part 164, Subpart C |
|---|---|
| Adopted | 2003-02-20 |
| Applies from | 2005-04-20 |
| Status | In force. Covered entities and business associates apply the safeguards to electronic protected health information. |
| Supervision | U.S. Department of Health and Human Services, Office for Civil Rights |
| Sectors named | Healthcare, Technology, Insurance |
| Risk areas | Information security, Personal data |
Requirements in the text
- Administrative safeguards, Reference: 45 CFR 164.308. Risk analysis, workforce access, training and incident procedures.
- Physical safeguards, Reference: 45 CFR 164.310. Facility access, workstation use and media handling.
- Technical safeguards, Reference: 45 CFR 164.312. Access control, audit controls, integrity and transmission security.
- Business associate contracts, Reference: 45 CFR 164.314. Written terms with every party that handles the data on your behalf.
Official sources
- 45 CFR Part 164, Security and Privacy, Electronic Code of Federal Regulations
- HIPAA Security Rule guidance, U.S. Department of Health and Human Services, Office for Civil Rights
ExploreWorldAI is operated by Valkiv Ventures AB (Reg. no. 556995-1311), Kungsgatan 8, 111 43 Stockholm, Sweden. EU-hosted, with data processing assessed against the GDPR. Contact: hello@exploreworldai.com.
Machine-readable summaries for AI agents: /llms.txt and /llms-full.txt.