Skip to content
Oluma Cyber Security Awareness
Law · Health Information

HIPAA Security Rule

The U.S. law that turns “protect patient data” into a legal duty — and the Security Rule that spells out how to guard every byte of electronic health information.

1996 · Rule 20053 Safeguard TypesePHI scope2025 NPRM pending
01 The Problem

Your most private records, one keystroke away

As health records went digital, a person’s most sensitive information — diagnoses, medications, mental-health history — could be copied, shared, or leaked with a single keystroke. And there was no federal floor requiring anyone to protect it.

A hospital, an insurer, and a billing vendor could each handle the same patient’s data with wildly different care. Patients had no guarantee their records were safe anywhere in the chain.

03 The Story Behind It

From privacy promise to enforced duty

1996
HIPAA becomes law
Set national standards for the privacy and portability of health information.
2003–05
Privacy & Security Rules take effect
The Security Rule established the required safeguards for electronic PHI specifically.
2009 · HITECH
Teeth and breach notification
The HITECH Act added breach-notification duties, stronger penalties, and extended the rules directly to “business associates” — the vendors who touch ePHI.
2025 · proposed
The biggest overhaul in 20 years
A January 2025 proposed rule would sharply strengthen the Security Rule. It is still proposed — not yet law — with final action pushed to roughly 2027. The current rule remains fully in force.
04 How It Works

Three safeguards, one mandatory risk analysis

The Security Rule sorts its protections into three families of safeguards — and the whole thing rests on a risk analysis that’s the single most-cited deficiency in federal investigations. Skip it, and nothing else you do is defensible.

AdministrativePhysicalTechnical+ Risk Analysis

Administrative safeguards cover policies, training, and access management; Physical cover facilities and devices; Technical cover encryption, access controls, and audit logs. Today each specification is either “required” or “addressable” (flexible where justified).

Who it binds
Covered entities
Healthcare providers, health plans, and clearinghouses that handle protected health information.
Who it reaches
Business associates
Any vendor — including much of health-tech and SaaS — that touches ePHI, bound through a Business Associate Agreement.
Who enforces it
HHS Office for Civil Rights
OCR investigates breaches and complaints, runs audits, and levies penalties — with risk analysis and access control the usual sore spots.
Current rule vs. the 2025 proposal

The proposed update would remove the “addressable” category (making most safeguards mandatory) and add explicit MFA, encryption, asset inventories, network segmentation, and annual audits. It is not yet law — plan for it, but comply with the current rule today.

06 Who Uses It

The whole healthcare data chain

🩺
Providers & plans
Hospitals, clinics, insurers, and clearinghouses — the covered entities at the core of the rule.
🧑‍💻
Business associates
Health-tech, billing, cloud, and SaaS vendors bound the moment they touch ePHI.
⚖️
HHS / OCR
The federal enforcer that investigates, audits, and penalizes across the entire chain.

Because HIPAA is a legal floor rather than a full playbook, organizations lean on crosswalks to operationalize it.

maps to NIST 800-66NIST CSFHITRUSTISO 27001
07 Career Relevance

The heart of healthcare GRC

Healthcare is one of the largest, most-breached sectors there is — which makes HIPAA fluency a durable career. The skills are practical and in constant demand: risk analyses, BAAs, breach response, and OCR readiness.

Healthcare GRC
Risk & compliance
Run the risk analysis, close gaps, and keep a program defensible against audit.
Privacy officer
Data & disclosure
Own how PHI is used, shared, and protected across the organization and its vendors.
Incident & vendor lead
Breach & third parties
Manage breach notification and the Business Associate Agreements that extend the rule down the supply chain.

And with a major overhaul on the horizon, professionals who understand both today’s rule and the proposed one are especially valuable.

09 Final Takeaway

HIPAA makes protecting health data the law. The Security Rule decides whether you actually did.

Its whole logic flows from one honest question — what could go wrong with this data, and have we reasonably guarded against it? Do the risk analysis well, and the three safeguards fall into place. Skip it, and no amount of technology will save you when OCR comes knocking.