Cyber One Solutions logo.
Get Support
Compliance / HIPAA Security

HIPAA Security Rule Compliance for Healthcare Organizations.

Healthcare providers, health plans, clearinghouses, and the vendors that support them handle protected health information (PHI). The Health Insurance Portability and Accountability Act (HIPAA) is designed to protect that information.

The HIPAA Security Rule (45 CFR Parts 160 and 164 Subparts A and C) requires covered entities and business associates to implement administrative, physical, and technical safeguards.

Those safeguards ensure the confidentiality, integrity, and availability of electronic PHI (ePHI). Some frameworks assign compliance to an external auditor or certifier. HIPAA is different: compliance is your responsibility.

What You Get
An annual Security Risk Analysis (SRA) documenting threats, vulnerabilities, and implemented safeguards.
Written policies and procedures for administrative safeguards, including workforce training, access management, and a designated security officer.
Physical safeguards: facility access controls, workstation security policies, and device and media controls.
Technical safeguards: access controls, audit controls, integrity controls, and encryption of ePHI in transit and at rest.
Business Associate Agreements (BAAs) signed with all vendors handling PHI, including managed security providers, EHR vendors, and cloud services.
Breach Notification Rule readiness: breach detection, incident response, and notification procedures for HHS OCR and affected individuals within 60 days.
Why This Matters

You put the safeguards in place and maintain the documentation. You also prepare for audits conducted by the U. S. Department of Health and Human Services Office for Civil Rights (HHS OCR). HHS issues no official HIPAA certification.

Instead, you show compliance through evidence of implemented controls and readiness for an audit.

Cyber One Solutions builds and manages the complete HIPAA Security program. This covers the annual Security Risk Analysis (SRA).

It covers the administrative safeguards (workforce policies, access controls, training) and the physical safeguards (facility controls, workstation security). It covers the technical safeguards (encryption, audit controls, integrity controls).

It also covers Business Associate Agreements (BAAs) with all vendors who touch PHI, breach notification readiness, and the operational controls your auditors expect to see. We do the work, manage the systems, and document the evidence.

Your organization stays compliant as your environment changes.

The Short Answer

Who must comply with the HIPAA Security Rule, and what does it require?

The HIPAA Security Rule applies to healthcare providers, health plans, and clearinghouses (covered entities) and to the business associates that handle electronic protected health information on their behalf.

It requires administrative, physical, and technical safeguards that keep ePHI confidential, intact, and available. There is no official HIPAA certification from HHS. Compliance is shown through implemented controls and readiness for an HHS OCR audit.

Cyber One Solutions, as a business associate, implements and manages those safeguards and signs a Business Associate Agreement.

  • Annual Security Risk Analysis.
  • Administrative, physical, and technical safeguards.
  • Access controls, audit logging, and encryption of ePHI.
  • Business Associate Agreements with every vendor that handles PHI.
  • Breach notification within 60 days.
The HIPAA Security Rule Framework

Core Requirements Every Covered Entity Must Implement.

The HIPAA Security Rule establishes three categories of safeguards. Covered entities and business associates must implement, maintain, and periodically audit each one.

These are the elements every HIPAA-covered organization must have in place, and the work we deliver against each one.

Annual Security Risk Analysis (SRA)

A documented assessment that identifies threats and vulnerabilities to the confidentiality, integrity, and availability of ePHI. It spans your infrastructure, applications, workforce, and vendors.

The SRA identifies safeguards already in place and those that still need to be put in place.

Administrative Safeguards

Policies and procedures governing workforce access, training, authorization, and authentication. This includes designating a security officer, access management policies, security awareness training, contingency planning, and periodic assessment and testing.

Physical Safeguards

Controls that protect physical access to facilities and equipment containing ePHI. This includes facility access controls, visitor logs, workstation use and security policies, workstation access controls, and device and media controls for portable equipment.

Technical Safeguards: Access & Authentication

Access controls enforce the principle of minimum necessary access. They also require unique user identification, emergency access procedures, and encryption or hashing of passwords. Audit controls require logging and monitoring of all ePHI access.

Technical Safeguards: Encryption & Integrity

Encryption of ePHI in transit (in-motion) and at rest (in-storage) using FIPS 140-2 validated cryptography. Integrity controls verify that ePHI has not been altered or destroyed. They include digital signatures and checksums.

Business Associate Agreements (BAAs) & Breach Notification

Signed BAAs with all vendors handling PHI. Breach Notification Rule compliance means you detect breaches and notify affected individuals and HHS OCR within 60 days. You also notify media for breaches affecting 500 or more individuals in a jurisdiction.

Why HIPAA Applies to You

Healthcare organizations and their vendors have no choice in HIPAA compliance.

The HIPAA Security Rule applies to covered entities (healthcare providers, health plans, clearinghouses) and to all business associates who handle electronic protected health information.

If you provide services to healthcare organizations or handle patient data directly, you are covered. HIPAA compliance is not optional. It is a baseline legal requirement that HHS OCR enforces with substantial penalties for violations.

Covered entities include healthcare providers, health plans, and clearinghouses.

A covered entity is any healthcare provider (physician, dentist, hospital, clinic, mental health provider) that transmits PHI electronically in connection with a standard transaction.

Health plans (commercial insurers, Medicare, Medicaid) and health clearinghouses are also covered.

Business associates are vendors or contractors who handle PHI on behalf of covered entities.

This includes managed IT providers, cybersecurity firms, cloud vendors, EHR software providers, and any organization that accesses, processes, stores, or transmits PHI.

The HIPAA Security Rule applies to all of you. There is no opt-out. If you handle ePHI, you must implement and maintain the required safeguards.

The Security Rule's three categories of safeguards are mandatory and interconnected.

Administrative safeguards set the policies and procedures your workforce must follow: access controls, training, security officer designation, risk analysis, and contingency planning. These policies must be written and documented.

Physical safeguards control who can access the buildings, rooms, and equipment that hold ePHI. This includes facility access controls, visitor management, workstation security, and device controls.

Technical safeguards use technology to protect ePHI: encryption, access controls, audit logging, and integrity verification. All three categories work together.

Policies fail without technical enforcement, and technical controls are useless without the administrative structure and physical discipline to support them.

HHS OCR audits HIPAA compliance; enforcement includes substantial civil and criminal penalties.

The U. S. Department of Health and Human Services Office for Civil Rights (HHS OCR) enforces HIPAA. OCR conducts audits and investigates complaints. It brings enforcement actions against covered entities and business associates who fail to comply.

Civil penalties for HIPAA violations range from USD 100 to USD 50,000 per violation. Annual caps reach up to USD 1. 9 million per violation category. A single breach can trigger thousands of violations.

Criminal penalties for knowing misuse or disclosure of PHI include fines up to USD 250,000 and imprisonment up to 10 years.

Beyond fines, a data breach of patient information triggers reputational damage, contractual liability, and loss of patient trust. The compliance program exists to prevent the breach in the first place, not to minimize penalties after one occurs.

The Security Rule is addressable and scalable, not one prescriptive checklist.

The Security Rule divides its implementation specifications into required and addressable. Required specifications must be implemented as written. Addressable specifications are not optional.

You must implement the specification, or document why it is not reasonable and appropriate for your environment and put an equivalent alternative in place. Skipping an addressable item without that written analysis is a common audit finding.

The rule is also intentionally scalable. A solo practice and a regional hospital face the same standards but implement them in proportion to their size, complexity, and risk. That flexibility is why the annual Security Risk Analysis matters so much.

It is the record that justifies the safeguards you chose and the ones you decided were not needed.

Proposed updates to the Security Rule would tighten several of these areas, including encryption, multi-factor authentication, and mandatory verification that safeguards are actually working.

Cyber One Solutions tracks these developments and builds programs that already reflect strong technical controls. If the rule tightens, that is an adjustment rather than a rebuild.

Common Questions

Frequently Asked Questions

Are we a covered entity or a business associate, and does it matter?

If you are a healthcare provider, health plan, or clearinghouse, you are a covered entity. If you provide services to a covered entity and handle PHI (such as IT support, cybersecurity, billing, or cloud hosting), you are a business associate.

Both are subject to HIPAA, though some specific requirements differ. We assess your status during onboarding and scope the program to match. The key point: both covered entities and business associates must implement the same security safeguards.

Is a HIPAA-compliant EHR or cloud platform enough to make us compliant?

No. A platform that supports HIPAA and will sign a Business Associate Agreement is a necessary building block. But compliance applies to your whole organization, not one application.

You are still responsible for your own written policies, workforce training, access controls, and multi-factor authentication.

You also own your annual Security Risk Analysis, your audit logging, your incident response plan, and your oversight of every vendor that touches ePHI. A compliant platform used inside a non-compliant program does not satisfy the Security Rule.

Cyber One Solutions builds the program around your full environment and documents how each safeguard is met.

What is the difference between the HIPAA Privacy Rule and the Security Rule?

The Privacy Rule (45 CFR Parts 160 and 164 Subparts A, E, and F) governs all PHI, regardless of form (paper, electronic, or oral). It sets rules for collection, use, disclosure, and patient rights.

The Security Rule (45 CFR Parts 160 and 164 Subparts A and C) applies only to ePHI and requires specific technical, administrative, and physical safeguards to protect it. Both rules apply to covered entities.

Business associates typically have responsibilities under the Security Rule and the Breach Notification Rule, but not the Privacy Rule itself (unless they have a separate relationship with patients).

Common Questions

HIPAA Security Rule Compliance, Answered.

Common questions from healthcare organizations and business associates on HIPAA applicability, safeguard requirements, audit expectations, and breach response.

Don't see your question?
Our team answers questions like these every day, no sales pitch attached.
Ask a Question