Skip to content
HIPAA · USA · Healthcare

HIPAA Security Rule Checklist

Interactive checklist for HIPAA Security Rule safeguards protecting electronic Protected Health Information (ePHI). Required for covered entities and business associates. Covers 28 controls across the Security Rule’s three safeguard categories (§164.308 Administrative, §164.310 Physical, §164.312 Technical) plus HITECH breach notification — not a substitute for full Privacy Rule or Enforcement Rule compliance review.

§164.308

Admin Safeguards

§164.310

Physical Safeguards

§164.312

Technical Safeguards

60 days

Breach Notification

0%0/28 controls implemented
Administrative Safeguards: 0/11
Physical Safeguards: 0/5
Technical Safeguards: 0/7
Breach Notification (HITECH): 0/5

Frequently Asked Questions

What does the HIPAA Security Rule cover?

Administrative, physical and technical safeguards required to protect the confidentiality, integrity and availability of electronic Protected Health Information (ePHI).

Who must comply with HIPAA's Security Rule?

Covered entities (health plans, healthcare clearinghouses, most healthcare providers) and their business associates that create, receive, maintain or transmit ePHI.

What's the difference between "required" and "addressable" HIPAA specifications?

Required specifications must be implemented as stated; addressable specifications must be implemented if reasonable and appropriate, or an equivalent alternative measure documented and justified if not.

Does HIPAA mandate encryption?

Encryption of ePHI at rest and in transit is an addressable specification, not an absolute requirement — but if it isn't implemented, the covered entity must document why and what compensating control is used instead.