HIPAA Security Rule Checklist
Interactive checklist for HIPAA Security Rule safeguards protecting electronic Protected Health Information (ePHI). Required for covered entities and business associates. Covers 28 controls across the Security Rule’s three safeguard categories (§164.308 Administrative, §164.310 Physical, §164.312 Technical) plus HITECH breach notification — not a substitute for full Privacy Rule or Enforcement Rule compliance review.
§164.308
Admin Safeguards
§164.310
Physical Safeguards
§164.312
Technical Safeguards
60 days
Breach Notification
Related Compliance Frameworks
International ISMS standard — 93 controls across 4 themes. Widely recognised globally.
6-function framework (GOVERN, IDENTIFY, PROTECT, DETECT, RESPOND, RECOVER) for any organisation size.
18 prioritised controls in 3 implementation groups. Practical cyber hygiene baseline.
12 requirements for entities handling payment card data. Mandatory for merchants and service providers.
Trust Service Criteria audit covering Security, Availability, Confidentiality, Integrity and Privacy.
India mandatory incident reporting: 6-hour reporting window, 180-day log retention, NTP sync.
Reserve Bank of India Master Directions covering cyber risk, SOC requirements and incident reporting.
Frequently Asked Questions
What does the HIPAA Security Rule cover?
Administrative, physical and technical safeguards required to protect the confidentiality, integrity and availability of electronic Protected Health Information (ePHI).
Who must comply with HIPAA's Security Rule?
Covered entities (health plans, healthcare clearinghouses, most healthcare providers) and their business associates that create, receive, maintain or transmit ePHI.
What's the difference between "required" and "addressable" HIPAA specifications?
Required specifications must be implemented as stated; addressable specifications must be implemented if reasonable and appropriate, or an equivalent alternative measure documented and justified if not.
Does HIPAA mandate encryption?
Encryption of ePHI at rest and in transit is an addressable specification, not an absolute requirement — but if it isn't implemented, the covered entity must document why and what compensating control is used instead.