HIPAA & privacy
What does the HIPAA Security Rule apply to?
Short answer
The HIPAA Security Rule applies to electronic protected health information (ePHI) that a covered entity or a business associate creates, receives, maintains or transmits. It does not cover PHI that only ever exists on paper or in speech, which the Privacy Rule governs instead. The rule sits in subpart C of 45 CFR Part 164, and §164.306(c) applies its standards to all of your ePHI rather than a subset you choose.
The short version: electronic PHI
If a question asks what the Security Rule applies to and offers you PHI, ePHI, paper records and spoken disclosures, the answer is ePHI. §164.306(a) states the general requirements in those terms: ensure the confidentiality, integrity and availability of all electronic PHI you create, receive, maintain or transmit, protect against reasonably anticipated threats to it, protect against uses or disclosures the Privacy Rule does not permit, and ensure your workforce complies.
Who it binds
Covered entities and business associates both. A covered entity is a health plan, a health care clearinghouse, or a health care provider that transmits health information electronically in connection with a covered transaction. A business associate is an organization that handles PHI on a covered entity’s behalf. Business associates have been directly liable for the Security Rule since the 2013 Omnibus Rule implemented the HITECH Act, so a vendor cannot treat the rule as its customer’s problem.
What is in scope
Every system that touches ePHI: servers and databases, laptops and phones, backups and archives, removable media, email, logs that contain clinical detail, and the cloud services you run all of it on. §164.306(c) is explicit that the standards apply with respect to all electronic PHI, so scope follows the data. Subcontractors that handle ePHI for you are covered by the business associate provisions at §164.308(b) and §164.314(a).
What the Security Rule does not reach
Paper charts, faxes printed and filed, and conversations between clinicians are PHI, and the Privacy Rule applies to them, but the Security Rule does not. Health data outside HIPAA altogether is a separate question: a consumer wellness app with no provider or plan involved is usually not covered, though the FTC’s Health Breach Notification Rule and state privacy law may apply. Employment records an employer holds in its role as employer are excluded from PHI by definition.
What it requires once it applies
Subpart C is organized into administrative safeguards (§164.308), physical safeguards (§164.310), technical safeguards (§164.312), organizational requirements (§164.314) and policies, procedures and documentation (§164.316), all governed by the general rules in §164.306. Each standard carries implementation specifications marked Required or Addressable. Addressable does not mean optional: §164.306(d)(3) requires you to assess whether the specification is reasonable and appropriate, then implement it, implement an equivalent measure, or document why neither fits.
Where Keel fits
Keel models 45 CFR Part 164 at leaf level, so each Required and Addressable specification in subpart C is its own scored row, with the regulation’s own label on it. What Keel scores and what it deliberately leaves out is written down on the HIPAA scope page rather than implied by the readiness number.
FAQ
-
Does the Security Rule apply to paper records?
- No. The Security Rule covers electronic PHI. Paper and oral PHI are governed by the Privacy Rule, which still requires reasonable administrative, technical and physical safeguards for them.
-
Does it apply to business associates?
- Yes, directly. Since the 2013 Omnibus Rule, a business associate must comply with the Security Rule itself, not only through its contract.
-
Is ePHI the same as PHI?
- ePHI is the electronic subset of PHI. PHI is protected health information in any form; ePHI is PHI created, stored or transmitted electronically.
-
Does encryption satisfy the Security Rule?
- No. Encryption is an addressable specification in two places (§164.312(a)(2)(iv) for data at rest and §164.312(e)(2)(ii) in transit), and the rule has many other standards. Encryption does matter for breach reporting: PHI secured to HHS guidance is not unsecured PHI, so a breach of it does not trigger the notification duties.
-
Which part of the CFR is the Security Rule?
- Subpart C of 45 CFR Part 164, which runs from §164.302 through §164.318, alongside the definitions in 45 CFR Part 160.
Next step
Get audit-ready with Keel
The AI-native GRC platform for SMBs: one control-and-evidence graph across SOC 2, ISO 27001, HIPAA, PCI DSS, NIST CSF, and more. Start free, no credit card.