HIPAA Security Rule: The Compliance Manager's Field Guide
A plain-language walkthrough of the Administrative, Physical, and Technical Safeguard requirements — what each specification requires, how auditors evidence it, and the findings that appear most often in OCR investigations.
Why most HIPAA failures are process failures, not technology failures.
The HIPAA Security Rule is not primarily a technology requirement — it is an administrative discipline. Of the 45 implementation specifications across Administrative, Physical, and Technical Safeguards, only a handful require specific technology. The rest require documented policies, trained workforces, evidence of ongoing review, and risk-based decision making.
This guide covers each safeguard category in practical terms: what the specification requires, what "addressable" really means (it does not mean optional), and what auditors and OCR investigators look for when they arrive.
Administrative Safeguards
Security Management Process
Implement policies to prevent, detect, and correct security violations. Conduct a formal risk analysis and risk management program.
Workforce Training & Management
All workforce members must receive security awareness training. Document training records and refresh at least annually.
Contingency Plan
Establish data backup, disaster recovery, and emergency mode operation plans. Test and update them regularly.
Evaluation
Periodically assess your security policies and procedures in response to environmental or operational changes.
Physical Safeguards
Facility Access Controls
Implement policies to limit physical access to systems containing ePHI while allowing authorized access.
Workstation Use
Specify the functions each workstation performs and the manner in which those functions are performed.
Device & Media Controls
Implement procedures for the final disposition of ePHI on hardware and electronic media before reuse or disposal.
Technical Safeguards
Access Control
Implement technical policies that allow only authorized persons to access ePHI. Unique user IDs, emergency access procedures, automatic logoff.
Audit Controls
Implement hardware, software, and procedural mechanisms that record and examine activity in systems that contain ePHI.
Integrity Controls
Protect ePHI from improper alteration or destruction. Implement electronic mechanisms to corroborate data has not been altered.
Transmission Security
Guard against unauthorized access to ePHI transmitted over electronic networks. Encryption is addressable — document your decision.
The six findings that appear in the majority of OCR investigations.
No documented risk analysis
Missing or stale workforce training records
BAAs not executed with all business associates
Lack of audit log review process
No encryption on portable devices
Contingency plan never tested
"Addressable" does not mean optional. It means you must assess whether the specification is reasonable and appropriate for your organisation. If you decide not to implement it, you must document why and implement an equivalent alternative measure — or document why no alternative is needed. Auditors will ask for this documentation.
Stop tracking compliance
in spreadsheets.
Protexa maps every HIPAA specification to your live controls, automates evidence collection, and surfaces gaps before auditors do.