Managed IT and Managed Security · Leesburg, VA

HIPAA Security Rule

HIPAA Security Rule Safeguards, Run as Part of Your IT.

The HIPAA Security Rule asks a practice to protect electronic patient records with administrative, physical and technical safeguards. We run the technical ones every day, and our Compliance Division delivers the formal compliance work.

For dental practices, DSOs and other healthcare practices that hold electronic protected health information (ePHI).

What Does the HIPAA Security Rule Require?

The Security Rule is 45 CFR Part 164, Subpart C. It applies to covered entities and their business associates, for electronic protected health information (ePHI) (45 CFR 164.302). They must ensure the confidentiality, integrity and availability of all ePHI they create, receive, maintain or transmit, and protect it against reasonably anticipated threats (164.306(a)).

The standards come in three groups: administrative safeguards (164.308), physical safeguards (164.310) and technical safeguards (164.312), plus organizational requirements (164.314) and written policies, procedures and documentation (164.316).

What Is the Difference Between Required and Addressable?

Each standard has implementation specifications marked Required or Addressable (164.306(d)). A required one must be implemented. An addressable one is not optional: the practice must assess whether it is reasonable and appropriate, implement it if it is, and if it is not, document why and implement an equivalent alternative measure if that is reasonable and appropriate.

Encryption of ePHI is addressable (164.312(a)(2)(iv) and 164.312(e)(2)(ii)), so a practice that does not encrypt needs a written reason and an alternative. In practice, encrypting laptops, servers and backups is usually simpler than defending that decision.

Which Safeguards Do We Run as Your IT and Security Provider?

The technical safeguards and the operational parts of the administrative ones: unique user identification and automatic logoff (164.312(a)), audit controls that record activity on systems holding ePHI (164.312(b)), verifying that a person is who they claim to be, which is where multi-factor authentication comes in (164.312(d)), and transmission security (164.312(e)).

From the administrative safeguards we run protection from malicious software, log-in monitoring and password management (164.308(a)(5)), the data backup and disaster recovery plans (164.308(a)(7)), and security awareness training for the whole workforce.

Who Does the Risk Analysis and the Documentation?

The risk analysis and risk management process (164.308(a)(1)), the policies and procedures, and the documentation the rule asks you to keep are formal compliance work. That work is delivered by our Compliance Division, Capital Cyber Compliance, so the documents describe the controls we actually run.

Does Our IT Provider Need a Business Associate Agreement?

If a provider creates, receives, maintains or transmits ePHI on your behalf, the rule requires satisfactory assurances that it will safeguard that information, documented in a written contract or other arrangement (164.308(b) and 164.314(a)). That contract is commonly called a business associate agreement. Ask any IT provider with access to your systems about it before work starts.

What Is Included

6 PARTS

Access and Authentication

Individual accounts for every user, multi-factor authentication and automatic logoff on systems that hold patient data.

Protection From Malicious Software

Endpoint detection and response on every workstation and server, watched around the clock.

Audit Logs and Log-In Monitoring

Activity recorded on systems that hold ePHI, and failed or unusual log-ins flagged.

Backup and Disaster Recovery

Retrievable copies of ePHI and a tested way to restore them after loss or an attack.

Encryption

Encryption on laptops, servers, backups and data in transit, or a documented alternative where it is not reasonable.

Security Awareness Training

Training for the whole workforce, management included, with phishing simulations.

Frequently Asked Questions

5 QUESTIONS
Does the HIPAA Security Rule apply to paper records?

No. The Security Rule covers electronic protected health information (45 CFR 164.302). Paper records fall outside the Security Rule, though other parts of HIPAA, such as the Privacy Rule in Subpart E of Part 164, still apply to them.

Does HIPAA require encryption?

Encryption is an addressable implementation specification (45 CFR 164.312(a)(2)(iv) and (e)(2)(ii)). The practice must implement it if reasonable and appropriate, or document why not and use an equivalent alternative measure if reasonable and appropriate.

How long must HIPAA security documentation be kept?

Six years from the date it was created or the date it was last in effect, whichever is later, and it must be reviewed periodically and updated as the environment changes (45 CFR 164.316(b)(2)).

Has the HIPAA Security Rule changed recently?

The Subpart C text in force on eCFR, current to 2026-10-07, was last amended in 2013 (78 FR 5693). We re-read the rule before relying on it and will update this page if it changes.

Who delivers a formal HIPAA compliance engagement?

Our Compliance Division, Capital Cyber Compliance. We run the IT and security safeguards; the Compliance Division delivers the risk analysis, policies and documentation. This page explains the rule and is not legal advice.

Related Services and Industries

MFA and Endpoint Protection (EDR)

Multi-factor authentication, endpoint detection and response, and application control on every device.

Backup and Ransomware Recovery

Encrypted, off-site backups that are tested, and a plan to restore the business after an attack.

Managed Security Monitoring (MDR and SOC)

Round the clock monitoring, detection and response from a security operations center.

Security Awareness Training

Training and phishing simulations that turn staff into a line of defense.

For Dental Practices

Managed IT, managed security and HIPAA compliance management for dental practices and DSOs.

Talk Through Your Practice's Safeguards.

Pick a time. Tell us which systems hold patient data and who runs them today.

Looking for CMMC? Our Compliance Division, Capital Cyber Compliance, delivers it.

Book a 30-Minute Call