The HIPAA Security Rule sets the safeguards that must protect electronic protected health information. It is the part of HIPAA that lands on engineering.
The short answer
The HIPAA Security Rule requires covered entities and business associates to protect the confidentiality, integrity and availability of ePHI through administrative, physical and technical safeguards. It is deliberately technology-neutral: it tells you what outcome to achieve, not which product to buy. Every requirement is either “required” or “addressable”, and the difference is widely misread.
Unlike the Privacy Rule, the Security Rule applies only to ePHI. Paper records sit outside it entirely.
On this page
The three safeguard families
Required versus addressable
Each standard contains implementation specifications tagged one way or the other. This is the most misunderstood mechanic in the rule.
| Tag | What it actually means |
|---|---|
| Required | Implement it. No discretion |
| Addressable | Assess whether it is reasonable and appropriate for you. If yes, implement it. If not, document why and put an equivalent alternative in place |
Addressable does not mean optional
Encryption of ePHI is addressable. Skipping it without a documented analysis and an equivalent alternative is a violation, and unencrypted devices are behind a large share of reported breaches. In practice, encrypt and move on.
Risk analysis is the foundation
An accurate and thorough risk analysis is a required specification under the administrative safeguards, and everything else depends on it. It identifies where ePHI lives, what threatens it, how likely each threat is, and what you will do about it. Every addressable decision has to trace back to it.
It is not a one-off document. The rule expects it to be reviewed and updated as systems, vendors and the organisation change.
Where organisations fail
| Failure | Why it recurs in enforcement |
|---|---|
| No risk analysis, or one covering only part of the estate | The single most cited Security Rule finding |
| Unencrypted laptops and portable media | Addressable was read as optional |
| Access not removed when staff leave | Offboarding is a process gap, not a technical one |
| Audit logs collected but never reviewed | The rule requires review, not just collection |
| No contingency plan or untested backups | Availability is part of the rule, and ransomware tests it |
How Osto implements the Security Rule
Most of the technical family is infrastructure work, and Osto runs it directly: unique identification, authentication and MFA, encryption at rest and in transit, audit controls with correlation and review, device control, cloud posture and vulnerability testing. Security awareness training and policy generation cover parts of the administrative family, and evidence maps to HIPAA alongside SOC 2 and ISO 27001.
Free security assessment
The Security Rule, deployed rather than documented
Osto runs authentication, encryption, audit controls, endpoint and cloud posture, and maps evidence to every safeguard.
Get a free security assessment Book a platform walkthroughRisk analysis supported · Controls that run · One platform, everything
Frequently asked questions
What is the HIPAA Security Rule?
The standard requiring covered entities and business associates to protect electronic PHI through administrative, physical and technical safeguards, preserving its confidentiality, integrity and availability.
What does addressable mean in the Security Rule?
That you must assess whether the specification is reasonable and appropriate for your environment. If it is, implement it. If not, document the reasoning and implement an equivalent alternative. It does not mean you can ignore it.
Is encryption required under HIPAA?
Encryption is addressable rather than required. In practice it is the expected control, and unencrypted ePHI features in a large share of reported breaches and resulting penalties.
Does the Security Rule apply to paper records?
No. It applies only to electronic PHI. Paper and spoken PHI are covered by the Privacy Rule, which applies to all forms.
Can you be HIPAA certified?
No. There is no official HIPAA certification. Organisations demonstrate compliance through a documented risk analysis, implemented safeguards, and independent assessments such as a SOC 2 report.

