HIPAA Security Rule¶
The HIPAA Security Rule sets administrative and technical safeguards for electronic protected health information (ePHI).
About this standard
The HIPAA Security Rule (45 CFR Part 164, Subpart C) sets safeguards for electronic protected health information (ePHI). 'Required' specifications must be implemented; 'addressable' ones must be implemented when reasonable, or the alternative documented.
Official sources: 45 CFR 164.308 Administrative safeguards (eCFR) · 45 CFR 164.312 Technical safeguards (eCFR) · HHS Security Rule guidance
Trimtab checks 10 of this standard's requirements with technical evidence. Requirements about policies, training, and physical security need their own evidence and are not listed here.
164.308 · Administrative Safeguards¶
164.308(a)(1)(ii)(B)¶
Risk management
In plain terms: Find your security weak spots and fix them, starting with the ones most likely to cause harm.
Required. Implement security measures sufficient to reduce risks and vulnerabilities to a reasonable and appropriate level.
Proven by: PAT-001, PAT-003, M365-011
164.308(a)(5)(ii)(B)¶
Protection from malicious software
In plain terms: Have antivirus in place and a way to notice and report malware.
Addressable. Procedures for guarding against, detecting, and reporting malicious software.
164.308(a)(5)(ii)(C)¶
Log-in monitoring
In plain terms: Watch for failed or suspicious sign-ins and act on them.
Addressable. Procedures for monitoring log-in attempts and reporting discrepancies.
164.308(a)(5)(ii)(D)¶
Password management
In plain terms: Set rules for strong passwords and protect them.
Addressable. Procedures for creating, changing, and safeguarding passwords.
Proven by: ACC-005, ACC-006, ACC-007
164.312 · Technical Safeguards¶
164.312(a)(1)¶
Access control
In plain terms: Only people and programs that have been given permission should be able to reach patient data.
Standard. Implement technical policies and procedures for electronic information systems that maintain ePHI to allow access only to those persons or software programs that have been granted access rights.
Proven by: ACC-001, ACC-002, ACC-009, M365-005, M365-006, M365-008, M365-009, M365-010
164.312(a)(2)(iii)¶
Automatic logoff
In plain terms: Lock or sign out unattended sessions automatically after a set time.
Addressable. Implement electronic procedures that terminate an electronic session after a predetermined time of inactivity.
Proven by: SES-001
164.312(a)(2)(iv)¶
Encryption and decryption
In plain terms: Encrypt patient data so it is unreadable if a device or file falls into the wrong hands.
Addressable. Implement a mechanism to encrypt and decrypt ePHI.
Proven by: ENC-001
164.312(b)¶
Audit controls
In plain terms: Keep records of who accessed and changed systems holding patient data, and review them.
Standard. Implement hardware, software, and/or procedural mechanisms that record and examine activity in information systems that contain or use ePHI.
Proven by: AUD-001, AUD-002, AUD-003, EXO-001, EXO-002
164.312(d)¶
Person or entity authentication
In plain terms: Make sure people are who they say they are before they get in, and protect the credentials that prove it.
Standard. Implement procedures to verify that a person or entity seeking access to ePHI is the one claimed.
Proven by: HRD-009, M365-001, M365-002, M365-003, M365-004, EXO-005, EXO-006
164.312(e)(1)¶
Transmission security
In plain terms: Protect patient data while it travels across a network, for example with encryption and firewalls.
Standard. Implement technical security measures to guard against unauthorized access to ePHI that is being transmitted over an electronic communications network.
Proven by: FW-001, SES-003, M365-009, EXO-003, EXO-004, EXO-007, EXO-008