O Oluma Cyber Security Framework Files · No. 07 Law · Health Information HIPAA Security Rule The U.S. law that turns “protect patient data” into a legal duty — and the Security Rule that spells out how to guard every byte of electronic health information. 1996 · Rule 20053 Safeguard TypesePHI scope2025 NPRM pending HIPAA ADMINPHYSTECH How we’ll read this 01 The Problem02 Why It Exists03 The Story04 How It Works05 Example06 Who Uses It07 Career08 Strengths & Challenges09 Takeaway 01 The Problem Your most private records, one keystroke away As health records went digital, a person’s most sensitive information — diagnoses, medications, mental-health history — could be copied, shared, or leaked with a single keystroke. And there was no federal floor requiring anyone to protect it. A hospital, an insurer, and a billing vendor could each handle the same patient’s data with wildly different care. Patients had no guarantee their records were safe anywhere in the chain. 02 Why It Was Created A national baseline for health data HIPAA (1996) set national standards for protecting health information. The Security Rule — effective in 2005 — is the piece that governs electronic protected health information (ePHI): a mandatory, technology-neutral baseline every covered entity and their vendors must meet. The core ideaDon’t dictate specific products — require every organization to assess its own risks and put reasonable safeguards in place, scaled to its size and complexity. That flexibility is why the same rule fits a solo practice and a national hospital system — and why a genuine risk analysis sits at its very center. 03 The Story Behind It From privacy promise to enforced duty 1996HIPAA becomes lawSet national standards for the privacy and portability of health information. 2003–05Privacy & Security Rules take effectThe Security Rule established the required safeguards for electronic PHI specifically. 2009 · HITECHTeeth and breach notificationThe HITECH Act added breach-notification duties, stronger penalties, and extended the rules directly to “business associates” — the vendors who touch ePHI. 2025 · proposedThe biggest overhaul in 20 yearsA January 2025 proposed rule would sharply strengthen the Security Rule. It is still proposed — not yet law — with final action pushed to roughly 2027. The current rule remains fully in force. 04 How It Works Three safeguards, one mandatory risk analysis The Security Rule sorts its protections into three families of safeguards — and the whole thing rests on a risk analysis that’s the single most-cited deficiency in federal investigations. Skip it, and nothing else you do is defensible. AdministrativePhysicalTechnical+ Risk Analysis Administrative safeguards cover policies, training, and access management; Physical cover facilities and devices; Technical cover encryption, access controls, and audit logs. Today each specification is either “required” or “addressable” (flexible where justified). Who it bindsCovered entitiesHealthcare providers, health plans, and clearinghouses that handle protected health information. Who it reachesBusiness associatesAny vendor — including much of health-tech and SaaS — that touches ePHI, bound through a Business Associate Agreement. Who enforces itHHS Office for Civil RightsOCR investigates breaches and complaints, runs audits, and levies penalties — with risk analysis and access control the usual sore spots. Current rule vs. the 2025 proposalThe proposed update would remove the “addressable” category (making most safeguards mandatory) and add explicit MFA, encryption, asset inventories, network segmentation, and annual audits. It is not yet law — plan for it, but comply with the current rule today. 05 Real-World Example A regional clinic builds a defensible program A mid-sized clinic can’t buy its way to compliance with one product — but it can build a program that would survive an OCR investigation, starting from an honest look at its own risks. Their Security Rule foundationAssess first, then safeguard Run a real, documented risk analysis of every ePHI system Encrypt laptops and ePHI at rest and in transit Give each user a unique login and turn on audit logs Sign Business Associate Agreements with every vendor Train staff and keep the evidence to prove it None of it is exotic — but together it’s the difference between a program that holds up under scrutiny and one that collapses at the first question. 06 Who Uses It The whole healthcare data chain 🩺Providers & plansHospitals, clinics, insurers, and clearinghouses — the covered entities at the core of the rule. 🧑💻Business associatesHealth-tech, billing, cloud, and SaaS vendors bound the moment they touch ePHI. ⚖️HHS / OCRThe federal enforcer that investigates, audits, and penalizes across the entire chain. Because HIPAA is a legal floor rather than a full playbook, organizations lean on crosswalks to operationalize it. maps to NIST 800-66NIST CSFHITRUSTISO 27001 07 Career Relevance The heart of healthcare GRC Healthcare is one of the largest, most-breached sectors there is — which makes HIPAA fluency a durable career. The skills are practical and in constant demand: risk analyses, BAAs, breach response, and OCR readiness. Healthcare GRCRisk & complianceRun the risk analysis, close gaps, and keep a program defensible against audit. Privacy officerData & disclosureOwn how PHI is used, shared, and protected across the organization and its vendors. Incident & vendor leadBreach & third partiesManage breach notification and the Business Associate Agreements that extend the rule down the supply chain. And with a major overhaul on the horizon, professionals who understand both today’s rule and the proposed one are especially valuable. 08 Strengths & Challenges Honest trade-offs ✦ Strengths A legal floor with real, enforced penalties Flexible and scalable to any size of organization Technology-neutral — it ages well Risk analysis forces you to know your own gaps Extends down the vendor chain via BAAs ⚠ Challenges “Addressable” specs create genuine ambiguity Risk analyses are often done poorly or skipped Enforcement can feel uneven The pending overhaul adds planning uncertainty A floor, not a complete security program 09 Final Takeaway HIPAA makes protecting health data the law. The Security Rule decides whether you actually did.Its whole logic flows from one honest question — what could go wrong with this data, and have we reasonably guarded against it? Do the risk analysis well, and the three safeguards fall into place. Skip it, and no amount of technology will save you when OCR comes knocking.