Compliance

0 min read

The HIPAA Security Rule: A Complete Guide for 2026

Shamai Cohen

Shamai Cohen

CEO of FaxSIPit Services Inc.

The HIPAA Security Rule: A Complete Guide

In this article

Get fresh insights, bi-weekly

Stay ahead of fax compliance, security, and integration trends. Join our community of IT pros and MSPs.

The HIPAA Security Rule is the federal regulation, found at 45 CFR Part 164, Subpart C, that requires covered entities and business associates to protect electronic protected health information (ePHI) with administrative, physical, and technical safeguards. It sets the standards for keeping electronic health data confidential, accurate, and available to the people who are allowed to see it.

This guide explains what the Security Rule is, who has to follow it, the three safeguard categories it defines, the risk analysis it demands, and the 2025 update that is still only proposed as of July 2026. At FaxSIPit, we co-created HTTPS faxing in 2008 and have built HIPAA-compliant cloud fax infrastructure for healthcare, legal, and financial organizations ever since, so protecting ePHI in transit is the exact problem our platform is built to solve.

Key Takeaways

  • The Security Rule protects ePHI only. It covers protected health information in electronic form, not information on paper or spoken out loud. That paper and oral information falls under the HIPAA Privacy Rule instead.

  • There are three safeguard categories: administrative (§164.308), physical (§164.310), and technical (§164.312). Together they define what "reasonable and appropriate" security looks like.

  • Risk analysis is the foundation. A written assessment of the risks to your ePHI is where the Rule starts, and OCR data from compliance and breach investigations shows it is the standard regulated entities most often struggle with.

  • "Addressable" does not mean optional. For an addressable specification you either implement it or document why a reasonable alternative meets the same goal.

  • The 2025 proposed update is not in effect. It was published in the Federal Register on January 6, 2025, is still proposed as of July 2026, and has a final action target of July 2027. The current Security Rule remains the law you follow today.

What Is the HIPAA Security Rule?

The HIPAA Security Rule is a set of federal standards that require regulated organizations to protect electronic protected health information from threats, unauthorized access, and loss. It was published on February 20, 2003, and its full text sits at 45 CFR Part 160 and Part 164, Subparts A and C, according to the HHS Summary of the HIPAA Security Rule.

The Rule protects a specific subset of health data: ePHI, which is protected health information that an organization creates, receives, stores, or sends in electronic form. It does not apply to protected health information that is only on paper or communicated verbally. That distinction matters because it separates the Security Rule from the Privacy Rule, which covers all protected health information in any format.

The Security Rule covers ePHI only. Paper and spoken health information falls under the Privacy Rule.

The Security Rule covers ePHI only. Paper and spoken health information falls under the Privacy Rule.

The Security Rule pairs with two other core HIPAA rules. The Privacy Rule sets the standards for who may use and share health information. The Security Rule sets the standards for protecting the electronic version of it. This guide focuses on the Security Rule.

Who Must Comply With the HIPAA Security Rule?

The HIPAA Security Rule applies to two groups: covered entities and business associates. HHS refers to both together as "regulated entities."

Covered entities are health plans, health care clearinghouses, and health care providers who transmit health information electronically in connection with certain transactions. Hospitals, clinics, physician practices, and insurers are the common examples.

Business associates are the vendors and contractors that create, receive, maintain, or transmit ePHI on a covered entity's behalf. Billing companies, cloud storage providers, IT firms, and fax service providers are all business associates when they handle ePHI. The HITECH Act, enacted in 2009, applied the Security Rule's requirements directly to business associates in the same way they apply to covered entities. If your organization touches ePHI for a covered entity, the Security Rule is your obligation too.

Both groups carry the same Security Rule duty. HHS calls them regulated entities.

Both groups carry the same Security Rule duty. HHS calls them regulated entities.

What the Security Rule Protects: ePHI and the CIA Triad

The Security Rule requires regulated entities to protect the confidentiality, integrity, and availability of all ePHI they create, receive, maintain, or transmit. These three goals, often called the CIA triad, are the core of the entire Rule. §164.306(a)(1) requires you to ensure all three for every piece of ePHI you create, receive, maintain, or transmit, and §164.304 defines each one.

  • Confidentiality means ePHI is not made available or disclosed to unauthorized persons or processes.

  • Integrity means ePHI has not been altered or destroyed in an unauthorized manner.

  • Availability means ePHI is accessible and useable upon demand by an authorized person.

A control that keeps records private but lets them be quietly changed fails the integrity goal. A control that keeps data safe but locks clinicians out during an emergency fails the availability goal. The Rule expects all three at once.

The Three HIPAA Security Rule Safeguards

The Security Rule organizes its requirements into three safeguard categories: administrative, physical, and technical. Each category contains standards, and many standards contain implementation specifications that spell out how to meet them. Here is how the Rule's main sections map out.

CFR Section

Category

What It Covers

§164.306

General Rules

The baseline duty to protect the confidentiality, integrity, and availability of all ePHI.

§164.308

Administrative Safeguards

Risk analysis, security management, workforce training, contingency planning.

§164.310

Physical Safeguards

Facility access, workstation security, device and media controls.

§164.312

Technical Safeguards

Access control, audit controls, integrity, authentication, transmission security.

§164.314

Organizational Requirements

Business associate contracts and group health plan rules.

§164.316

Documentation

Written policies and procedures, retained for six years.

The full rule text for each section is available at the eCFR, Title 45, Part 164.

Administrative Safeguards (§164.308)

Administrative safeguards are the policies, procedures, and management actions that run your security program. This is the largest of the three categories. It includes the Security Management Process (which contains the required risk analysis), Assigned Security Responsibility, Workforce Security, Information Access Management, Security Awareness and Training, Security Incident Procedures, a Contingency Plan, periodic Evaluation, and business associate contracts. In practice, administrative safeguards are where most of the day-to-day work of compliance lives.

Physical Safeguards (§164.310)

Physical safeguards protect the buildings, equipment, and devices that hold ePHI. They cover Facility Access Controls, Workstation Use and Workstation Security, and Device and Media Controls. These safeguards apply to more than servers and laptops. Device and Media Controls at §164.310(d) governs the hardware and electronic media that contain ePHI, which pulls in the printers, scanners, multifunction devices, and fax machines that hold patient data in memory or on an internal drive, along with any removable media. For those devices, Disposal and Media Re-use are both required specifications: you need a documented process for wiping ePHI before a device is resold, returned at lease end, or thrown away. For the fax-specific side of this, see our guide to HIPAA fax requirements.

Technical Safeguards (§164.312)

Technical safeguards are the technology controls that protect ePHI and control who can reach it. They include Access Control, Audit Controls, Integrity, Person or Entity Authentication, and Transmission Security. Transmission Security, at §164.312(e), governs ePHI as it moves across a network, which is where encryption most often applies. For example, we encrypt every fax in transit over TLS on every FaxSIPit plan, and we record every delivery in a full audit trail. Encrypting one transport channel is one control supporting one safeguard, not compliance by itself, but it shows how a technical safeguard maps to a real capability.

Risk Analysis: The Foundation of Compliance

Risk analysis is the single most important requirement in the Security Rule. Under §164.308(a)(1), a regulated entity must perform what the Rule calls "an accurate and thorough assessment" of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of its ePHI. Every other safeguard decision flows from what that assessment finds.

The risk analysis standard at 45 CFR §164.308(a)(1). Every other safeguard decision flows from it.

The risk analysis standard at 45 CFR §164.308(a)(1). Every other safeguard decision flows from it.

It is also the requirement organizations struggle with most. According to HIPAA Journal, citing data the HHS Office for Civil Rights gathers during compliance and breach investigations, the risk analysis standard is the one many covered entities and business associates appear to struggle with. A risk analysis is not a one-time checkbox. It is an ongoing process that you repeat as your systems, threats, and workflows change. HHS and ONC publish a free Security Risk Assessment Tool built for small and medium-sized providers to work through the assessment step by step.

Required vs. Addressable: What "Addressable" Really Means

The word "addressable" causes more confusion than any other part of the Security Rule, so here is the plain answer: addressable does not mean optional. HHS states directly that the "addressable" designation does not mean that an implementation specification is optional.

For a required specification, you must implement it. For an addressable specification, you assess whether it is reasonable and appropriate for your environment. If it is, you implement it. If it is not, you may adopt an alternative measure that achieves the same purpose, and you must document why you made that choice. Encryption of stored data is a good example. It is addressable today, which means you either encrypt or you record a justified, equivalent alternative. Skipping it silently is not a lawful option.

HHS states directly that the addressable designation does not make a specification optional.

HHS states directly that the addressable designation does not make a specification optional.

The Rule is also flexible by design. Under §164.306(b)(2), a regulated entity may choose its security measures based on its size, complexity, and capabilities; its technical infrastructure; the cost of the measures; and the probability and criticality of the risks to its ePHI. A solo dental practice and a national hospital network can both comply, using very different controls. The standard is "reasonable and appropriate" for your organization, not a single fixed checklist.

How the Security Rule Fits With HIPAA's Other Rules

The Security Rule is one of several rules under HIPAA, and each one does a different job. Knowing where the Security Rule stops helps you avoid gaps.

  • The Privacy Rule sets the standards for using and disclosing all protected health information, in any format, including paper and spoken.

  • The Security Rule sets the standards for protecting the electronic subset of that information, ePHI.

  • The Breach Notification Rule sets what an organization must do after a breach of unsecured PHI, including notifying affected individuals and HHS.

A single event can involve all three. If a laptop of unencrypted patient records is stolen, the Security Rule speaks to the missing safeguards, the Privacy Rule speaks to the exposure of the information, and the Breach Notification Rule speaks to the notices you now owe. For the numbers behind these events, see our HIPAA violation statistics.

Who Enforces the HIPAA Security Rule?

The HHS Office for Civil Rights (OCR) enforces the HIPAA Security Rule. OCR investigates complaints, conducts compliance reviews, and can impose civil monetary penalties and require corrective action plans when it finds violations. State attorneys general also have authority to bring HIPAA enforcement actions.

Penalties scale with the level of culpability, from unknowing violations to willful neglect, and an inadequate risk analysis is a recurring finding in OCR investigations. The practical takeaway is simple: enforcement tends to follow the safeguards an organization skipped.

The Proposed 2025 HIPAA Security Rule Update (Not Yet in Effect)

As of July 2026, the most significant proposed overhaul of the Security Rule since it took effect is still only proposed. It is not in effect, and it is not being enforced. HHS states plainly that "while the Department is undertaking this rulemaking, the current Security Rule remains in effect."

Here is the accurate timeline. OCR issued a Notice of Proposed Rulemaking (NPRM) on December 27, 2024. It was published in the Federal Register on January 6, 2025, and the public comment period closed on March 7, 2025. According to HIPAA Journal, OCR received nearly 5,000 comments and the final rule has been pushed back, with final action now targeted for July 2027. Any source telling you these changes are required right now is wrong.

The 2025 proposed update is not in effect. The current Security Rule remains the law you follow today.

The 2025 proposed update is not in effect. The current Security Rule remains the law you follow today. Source: HHS; HIPAA Journal.

If it is finalized in something close to its current form, the proposed update would strengthen the Rule in several ways. Every item in this list is proposed, not current law, and comes from the HHS fact sheet:

  • Remove the distinction between "required" and "addressable" specifications and make nearly all of them required.

  • Require encryption of ePHI both at rest and in transit, with limited exceptions.

  • Require multi-factor authentication, with limited exceptions.

  • Require a technology asset inventory and a network map, updated at least every 12 months.

  • Require written procedures to restore critical systems and data within 72 hours.

  • Require a compliance audit at least once every 12 months.

  • Require vulnerability scanning at least every six months and penetration testing at least once every 12 months.

  • Require network segmentation.

The proposal has drawn heavy pushback. As HIPAA Journal reported, in December 2025 more than 100 hospital systems and provider associations, including major health systems and physician groups, sent a joint letter to HHS calling for the proposed update to be withdrawn and describing its provisions as "crushing and unprecedented." Whatever the final rule looks like, the point for planning today is that it is not here yet.

What the Security Rule Means for How You Send ePHI

Because the Transmission Security standard (§164.312(e)) covers ePHI as it moves across networks, the way your organization actually sends patient records sits directly under the Security Rule. Fax, email, and portals are all transmission channels, and each one has to be secured.

Fax is still the backbone of health care document exchange, which is where our work fits. We run a HIPAA-compliant cloud fax platform built to connect today's fax to tomorrow's workflows, meaning cloud fax that works with your existing fax machines and modern tools like Teams, Zoom, and Outlook. Every fax is encrypted in transit over TLS, every delivery is recorded in a full audit trail you can produce when an auditor asks for proof of transmission, faxes can be retained for up to seven years to support your retention and audit needs, and we sign a business associate agreement on every plan. To be clear about the boundary: securing one channel is one part of a much larger compliance program, not a substitute for it.

There is a forward-looking reason this matters. If the 2025 proposed update is finalized, encryption of ePHI in transit moves from addressable to required. That is the same last-mile transport encryption we already apply to every fax, on every plan, today.

Frequently Asked Questions

What are the three HIPAA Security Rule safeguards?

The three HIPAA Security Rule safeguards are administrative safeguards (§164.308), physical safeguards (§164.310), and technical safeguards (§164.312). Administrative safeguards are the policies and management actions that run a security program, physical safeguards protect facilities and devices, and technical safeguards are the technology controls that protect ePHI and control access to it.

What is the difference between the HIPAA Privacy Rule and the Security Rule?

The HIPAA Privacy Rule governs all protected health information in any format, including paper and spoken, and sets the standards for using and disclosing it. The HIPAA Security Rule governs only electronic protected health information (ePHI) and sets the administrative, physical, and technical safeguards used to protect it. The Privacy Rule is about who can access and share information; the Security Rule is about protecting the electronic form of it.

Are the 2026 HIPAA Security Rule changes in effect?

No. The proposed 2025 update to the HIPAA Security Rule is not in effect as of July 2026. It was published in the Federal Register on January 6, 2025, remains a proposed rule, and has a final action target of July 2027. HHS has confirmed that the current Security Rule remains in effect while the rulemaking continues, so organizations should keep complying with the existing Rule.

Does the HIPAA Security Rule require encryption?

Encryption is currently an addressable specification, not a flat requirement. That means a regulated entity must either encrypt ePHI or document why a reasonable, equivalent alternative meets the same goal. The 2025 proposed update would change this by making encryption of ePHI at rest and in transit required, with limited exceptions, but that change is not yet in effect.

What are the five HIPAA rules?

The five HIPAA rules are the Privacy Rule, the Security Rule, the Breach Notification Rule, the Enforcement Rule, and the Omnibus Rule. The Security Rule is the one that sets the safeguards for protecting electronic protected health information.

The Bottom Line

The HIPAA Security Rule requires covered entities and business associates to protect electronic protected health information through administrative, physical, and technical safeguards, built on top of a genuine risk analysis. It is flexible enough for a solo practice and a hospital system to comply in different ways, but the core duty is the same: keep ePHI confidential, accurate, and available.

The most important thing to get right in 2026 is what has and has not changed. The 2025 proposed update is a significant rewrite, but it is still proposed, still unenforced, and now targeted for July 2027. Keep meeting the current Rule today, and watch the rulemaking rather than acting as if it is already law.

We built FaxSIPit as HIPAA-compliant cloud fax for regulated healthcare, legal, and financial organizations. For sites that want to keep their existing machines, our SecureFax-ATA devices also connect them to that encrypted cloud without a rip-and-replace. If your patient records still move by fax, see how we handle HIPAA-compliant fax so that channel stays encrypted, provable, and audit-ready.

Sources

  1. HHS: Summary of the HIPAA Security Rule

  2. HHS: The Security Rule

  3. HHS: HIPAA Security Rule NPRM Fact Sheet

  4. HIPAA Journal: HIPAA Security Rule Update Postponed

  5. HIPAA Journal: The HIPAA Security Rule

  6. HIPAA Journal: Hospitals and Provider Associations Call for Withdrawal of the HIPAA Security Rule Update

  7. eCFR: Title 45, Part 164

Follow FaxSIPit on LinkedIn for more fax insights and news

Follow FaxSIPit on LinkedIn for more fax insights and news

Follow FaxSIPit on LinkedIn for more fax insights and news

Shamai Cohen

Shamai Cohen

Shamai Cohen is the CEO of FaxSIPit Services Inc., a cloud fax infrastructure company headquartered in Vancouver, Canada. With a background in economics and over a decade at FaxSIPit — from project coordinator to chief executive — Shamai leads the company's mission to deliver compliance, continuity, and confidence in fax solutions for regulated industries. Under his leadership, FaxSIPit serves 300+ channel partners across 40+ countries and continues to expand its direct enterprise offering for healthcare, legal, and financial organizations.

Follow FaxSIPit on LinkedIn for more fax insights and news

Stay informed on fax trends, compliance updates, and smart solutions for modern workflows—follow us on LinkedIn.

Follow FaxSIPit on LinkedIn for more fax insights and news

Stay informed on fax trends, compliance updates, and smart solutions for modern workflows—follow us on LinkedIn.

Follow FaxSIPit on LinkedIn for more fax insights and news

Stay informed on fax trends, compliance updates, and smart solutions for modern workflows—follow us on LinkedIn.

Follow FaxSIPit on LinkedIn for more fax insights and news

Stay informed on fax trends, compliance updates, and smart solutions for modern workflows—follow us on LinkedIn.