← Back to Resources

HIPAA Security Rule: The Compliance Manager's Field Guide

A plain-language walkthrough of the Administrative, Physical, and Technical Safeguard requirements — what each specification requires, how auditors evidence it, and the findings that appear most often in OCR investigations.

Why most HIPAA failures are process failures, not technology failures.

The HIPAA Security Rule is not primarily a technology requirement — it is an administrative discipline. Of the 45 implementation specifications across Administrative, Physical, and Technical Safeguards, only a handful require specific technology. The rest require documented policies, trained workforces, evidence of ongoing review, and risk-based decision making.

This guide covers each safeguard category in practical terms: what the specification requires, what "addressable" really means (it does not mean optional), and what auditors and OCR investigators look for when they arrive.

Administrative Safeguards

§164.308

Security Management Process

Implement policies to prevent, detect, and correct security violations. Conduct a formal risk analysis and risk management program.

Required

Workforce Training & Management

All workforce members must receive security awareness training. Document training records and refresh at least annually.

Required

Contingency Plan

Establish data backup, disaster recovery, and emergency mode operation plans. Test and update them regularly.

Required

Evaluation

Periodically assess your security policies and procedures in response to environmental or operational changes.

Required

Physical Safeguards

§164.310

Facility Access Controls

Implement policies to limit physical access to systems containing ePHI while allowing authorized access.

Required

Workstation Use

Specify the functions each workstation performs and the manner in which those functions are performed.

Required

Device & Media Controls

Implement procedures for the final disposition of ePHI on hardware and electronic media before reuse or disposal.

Required

Technical Safeguards

§164.312

Access Control

Implement technical policies that allow only authorized persons to access ePHI. Unique user IDs, emergency access procedures, automatic logoff.

Required

Audit Controls

Implement hardware, software, and procedural mechanisms that record and examine activity in systems that contain ePHI.

Required

Integrity Controls

Protect ePHI from improper alteration or destruction. Implement electronic mechanisms to corroborate data has not been altered.

Addressable

Transmission Security

Guard against unauthorized access to ePHI transmitted over electronic networks. Encryption is addressable — document your decision.

Addressable

The six findings that appear in the majority of OCR investigations.

Very CommonCritical

No documented risk analysis

CommonHigh

Missing or stale workforce training records

CommonHigh

BAAs not executed with all business associates

CommonHigh

Lack of audit log review process

CommonMedium

No encryption on portable devices

ModerateMedium

Contingency plan never tested

A Note on "Addressable"

"Addressable" does not mean optional. It means you must assess whether the specification is reasonable and appropriate for your organisation. If you decide not to implement it, you must document why and implement an equivalent alternative measure — or document why no alternative is needed. Auditors will ask for this documentation.

Stop tracking compliance
in spreadsheets.

Protexa maps every HIPAA specification to your live controls, automates evidence collection, and surfaces gaps before auditors do.

See It in Action← Back to Resources