{"id":842,"date":"2026-08-17T05:10:04","date_gmt":"2026-08-17T05:10:04","guid":{"rendered":"https:\/\/www.osto.one\/resources\/?p=842"},"modified":"2026-08-17T05:10:04","modified_gmt":"2026-08-17T05:10:04","slug":"hipaa-security-rule-safeguards-that-matter","status":"publish","type":"post","link":"https:\/\/www.osto.one\/resources\/glossary\/hipaa-security-rule-safeguards-that-matter\/","title":{"rendered":"HIPAA Security Rule: Safeguards That Matter"},"content":{"rendered":"\n<!-- =========================================================================\n     OSTO GLOSSARY: HIPAA SECURITY RULE\n     Shared glossary design system. Paste into one Custom HTML block. No H1.\n     ========================================================================= -->\n\n<style>\n.og{\n  --navy:#1c267a; --text:#0f1538; --muted:#0f1538; --light:#0f1538;\n  --border:#e7e9f2; --divider:#eceef5; --white:#ffffff;\n\n  --peri-50:#f4f5fd;  --peri-100:#e9ecfa; --peri-200:#cfd5f2; --peri-700:#4a52a8;\n  --sage-50:#f2f8f5;  --sage-100:#e3f0e9; --sage-200:#c3ddce; --sage-700:#3a6f5d;\n  --apri-50:#fdf6f0;  --apri-100:#fbe9dc; --apri-200:#f2cdb2; --apri-700:#a2603a;\n  --plum-50:#f8f3f9;  --plum-100:#f0e6f3; --plum-200:#dcc6e2; --plum-700:#6b4576;\n  --sky-50:#f1f7fb;   --sky-100:#e2eff7;  --sky-200:#bfd9e9;  --sky-700:#2f6a89;\n\n  --shadow:0 6px 22px rgba(15,21,56,.05);\n  --font:'Inter',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif;\n  font-family:var(--font); font-size:17px; line-height:1.75; color:var(--text);\n}\n.og p{margin:0 0 22px}\n.og h2{font-family:var(--font);font-size:clamp(25px,3vw,31px);font-weight:700;line-height:1.25;letter-spacing:-.5px;color:var(--navy);margin:52px 0 8px;scroll-margin-top:92px}\n.og h2::after{content:\"\";display:block;width:46px;height:5px;border-radius:3px;margin:12px 0 18px;background:var(--peri-200)}\n.og h2.c-sage::after{background:var(--sage-200)}\n.og h2.c-apri::after{background:var(--apri-200)}\n.og h2.c-plum::after{background:var(--plum-200)}\n.og h2.c-sky::after{background:var(--sky-200)}\n.og ul,.og ol{padding-left:22px;margin:0 0 24px}\n.og li{margin-bottom:9px}\n.og strong{font-weight:600}\n\n.og .dek{font-size:20px;line-height:1.6;color:var(--muted);margin:0 0 18px}\n.og .tags{margin:0 0 30px;padding:0;list-style:none;display:flex;flex-wrap:wrap;gap:8px}\n.og .tags li{margin:0}\n.og .tag{display:inline-block;font-size:12px;font-weight:600;letter-spacing:.7px;text-transform:uppercase;padding:6px 13px;border-radius:20px}\n.og .t-peri{background:var(--peri-100);color:var(--peri-700)}\n.og .t-sage{background:var(--sage-100);color:var(--sage-700)}\n\n.og .short{background:linear-gradient(135deg,var(--peri-100) 0%,var(--sage-100) 100%);border-radius:22px;padding:28px 32px;margin:0 0 30px}\n.og .short .k{font-size:13px;font-weight:700;letter-spacing:1.4px;text-transform:uppercase;color:var(--peri-700);margin:0 0 10px}\n.og .short p{font-size:19px;line-height:1.65;margin:0;color:var(--text)}\n\n.og .toc{background:var(--peri-50);border-radius:20px;padding:24px 28px;margin:0 0 34px}\n.og .toc .k{font-size:12px;font-weight:700;letter-spacing:1.3px;text-transform:uppercase;color:var(--peri-700);margin:0 0 12px}\n.og .toc ol{margin:0;padding-left:20px;columns:2;column-gap:34px}\n.og .toc li{margin-bottom:8px;break-inside:avoid;font-size:16px}\n.og .toc a{color:var(--navy);text-decoration:none;border-bottom:1px solid rgba(28,38,122,.22)}\n\n.og .callout{border-radius:4px;padding:24px 28px;margin:0 0 30px;background:var(--white);border:2px solid var(--navy)}\n.og .callout .k{font-weight:700;font-size:17px;margin:0 0 8px;color:var(--navy)}\n.og .callout p:last-child{margin-bottom:0}\n.og .callout.c-plum{background:var(--plum-50);border:none;border-radius:20px}\n.og .callout.c-plum .k{color:var(--plum-700)}\n\n.og figure{margin:0 0 30px}\n.og .sx{overflow-x:auto;-webkit-overflow-scrolling:touch;border-radius:20px;background:var(--white);box-shadow:var(--shadow)}\n.og .sx svg{display:block;width:100%;height:auto;min-width:600px}\n.og figcaption{font-size:14px;line-height:1.6;color:var(--muted);margin-top:12px}\n.og .swipe{display:none}\n\n.og table{width:100%;border-collapse:collapse;margin:0 0 28px;font-size:15px;background:var(--white);border-radius:18px;overflow:hidden;box-shadow:var(--shadow)}\n.og th{text-align:left;padding:14px 16px;font-weight:700;font-size:12.5px;letter-spacing:.8px;text-transform:uppercase}\n.og td{border-bottom:1px solid var(--divider);padding:13px 16px;vertical-align:top;line-height:1.6}\n.og tr:last-child td{border-bottom:none}\n.og .h-peri th{background:var(--peri-100);color:var(--peri-700)}\n.og .h-sage th{background:var(--sage-100);color:var(--sage-700)}\n.og .h-plum th{background:var(--plum-100);color:var(--plum-700)}\n\n.og .trio{display:grid;grid-template-columns:repeat(3,1fr);gap:14px;margin:0 0 28px}\n.og .tcard{border-radius:18px;padding:20px 22px}\n.og .tcard .n{font-size:16px;font-weight:700;margin:0 0 4px}\n.og .tcard .g{font-size:13px;font-weight:600;margin:0 0 10px;opacity:.8}\n.og .tcard p{font-size:14px;line-height:1.55;margin:0;color:var(--muted)}\n.og .tcard.a{background:var(--sky-50)}   .og .tcard.a .n,.og .tcard.a .g{color:var(--sky-700)}\n.og .tcard.b{background:var(--sage-50)}  .og .tcard.b .n,.og .tcard.b .g{color:var(--sage-700)}\n.og .tcard.c{background:var(--plum-50)}  .og .tcard.c .n,.og .tcard.c .g{color:var(--plum-700)}\n\n.og .pill{display:inline-block;font-size:11px;font-weight:700;letter-spacing:.8px;text-transform:uppercase;padding:5px 11px;border-radius:20px;white-space:nowrap}\n.og .p-req{background:var(--plum-200);color:#4d2f57}\n.og .p-exp{background:var(--sky-100);color:var(--sky-700)}\n.og .p-imp{background:#eef0f4;color:var(--muted)}\n.og .p-ask{background:var(--apri-100);color:var(--apri-700)}\n\n.og details{background:var(--white);border-radius:14px;margin:0 0 10px;box-shadow:0 2px 10px rgba(15,21,56,.04)}\n.og summary{cursor:pointer;padding:16px 20px;font-weight:600;font-size:17px;color:var(--navy);list-style:none;display:flex;justify-content:space-between;gap:16px;align-items:flex-start}\n.og summary::-webkit-details-marker{display:none}\n.og summary::after{content:\"+\";font-size:22px;line-height:1;color:var(--peri-700);flex:0 0 auto}\n.og details[open] summary::after{content:\"\\2013\"}\n.og details p{padding:0 20px 18px;margin:0;font-size:16px;line-height:1.7}\n\n.og .related{font-size:15px;color:var(--muted);border-top:1px solid var(--divider);padding-top:22px;margin-top:40px}\n\n@media(max-width:700px){\n  .og{font-size:16px}\n  .og .dek{font-size:18px}\n  .og .short p{font-size:17px}\n  .og .short,.og .toc,.og .callout{padding:22px 20px}\n  .og .toc ol{columns:1}\n  .og .trio{grid-template-columns:1fr}\n  .og .swipe{display:inline;font-weight:600;color:var(--peri-700)}\n  .og table{font-size:14px}\n  .og th,.og td{padding:11px 12px}\n}\n<\/style>\n\n<div class=\"og\">\n\n<p class=\"dek\">The HIPAA Security Rule sets the safeguards that must protect electronic protected health information. It is the part of HIPAA that lands on engineering.<\/p>\n\n<ul class=\"tags\">\n  <li><span class=\"tag t-peri\">Glossary<\/span><\/li>\n  <li><span class=\"tag t-sage\">HIPAA<\/span><\/li>\n<\/ul>\n\n<div class=\"short\">\n  <p class=\"k\">The short answer<\/p>\n  <p>The HIPAA Security Rule requires covered entities and business associates to protect the confidentiality, integrity and availability of ePHI through administrative, physical and technical safeguards. It is deliberately technology-neutral: it tells you what outcome to achieve, not which product to buy. Every requirement is either &#8220;required&#8221; or &#8220;addressable&#8221;, and the difference is widely misread.<\/p>\n<\/div>\n\n<p>Unlike the <a href=\"https:\/\/www.osto.one\/resources\/glossary\/hipaa-privacy-rule\/\">Privacy Rule<\/a>, the Security Rule applies only to <a href=\"https:\/\/www.osto.one\/resources\/glossary\/ephi\/\">ePHI<\/a>. Paper records sit outside it entirely.<\/p>\n\n<div class=\"toc\">\n  <p class=\"k\">On this page<\/p>\n  <ol>\n    <li><a href=\"#three\">The three safeguard families<\/a><\/li>\n    <li><a href=\"#addressable\">Required versus addressable<\/a><\/li>\n    <li><a href=\"#risk\">Risk analysis is the foundation<\/a><\/li>\n    <li><a href=\"#fails\">Where organisations fail<\/a><\/li>\n    <li><a href=\"#osto\">How Osto implements the Security Rule<\/a><\/li>\n    <li><a href=\"#faq\">FAQ<\/a><\/li>\n  <\/ol>\n<\/div>\n\n<h2 id=\"three\">The three safeguard families<\/h2>\n\n<figure>\n<div class=\"sx\">\n<svg viewBox=\"0 0 760 220\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" role=\"img\" aria-label=\"Administrative, physical and technical safeguards together protect the confidentiality, integrity and availability of ePHI.\">\n  <rect x=\"12\" y=\"36\" width=\"238\" height=\"118\" rx=\"16\" fill=\"#e9ecfa\"\/>\n  <text x=\"131\" y=\"66\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"13.5\" font-weight=\"700\" fill=\"#4a52a8\">Administrative<\/text>\n  <text x=\"131\" y=\"90\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#0f1538\">Risk analysis, workforce<\/text>\n  <text x=\"131\" y=\"108\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#0f1538\">security, training,<\/text>\n  <text x=\"131\" y=\"126\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#0f1538\">contingency planning<\/text>\n  <text x=\"131\" y=\"146\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" font-weight=\"700\" fill=\"#4a52a8\">9 standards<\/text>\n\n  <rect x=\"261\" y=\"36\" width=\"238\" height=\"118\" rx=\"16\" fill=\"#e3f0e9\"\/>\n  <text x=\"380\" y=\"66\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"13.5\" font-weight=\"700\" fill=\"#3a6f5d\">Physical<\/text>\n  <text x=\"380\" y=\"90\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#0f1538\">Facility access,<\/text>\n  <text x=\"380\" y=\"108\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#0f1538\">workstation use,<\/text>\n  <text x=\"380\" y=\"126\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#0f1538\">device and media controls<\/text>\n  <text x=\"380\" y=\"146\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" font-weight=\"700\" fill=\"#3a6f5d\">4 standards<\/text>\n\n  <rect x=\"510\" y=\"36\" width=\"238\" height=\"118\" rx=\"16\" fill=\"#1c267a\"\/>\n  <text x=\"629\" y=\"66\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"13.5\" font-weight=\"700\" fill=\"#ffffff\">Technical<\/text>\n  <text x=\"629\" y=\"90\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#b9c1e6\">Access control, audit<\/text>\n  <text x=\"629\" y=\"108\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#b9c1e6\">controls, integrity,<\/text>\n  <text x=\"629\" y=\"126\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#b9c1e6\">authentication, transmission<\/text>\n  <text x=\"629\" y=\"146\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" font-weight=\"700\" fill=\"#b9c1e6\">5 standards<\/text>\n\n  <rect x=\"12\" y=\"172\" width=\"736\" height=\"34\" rx=\"11\" fill=\"#f4f5fd\"\/>\n  <text x=\"380\" y=\"194\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" font-weight=\"700\" fill=\"#4a52a8\">All three protect the same thing: confidentiality, integrity and availability of ePHI<\/text>\n<\/svg>\n<\/div>\n<figcaption><span class=\"swipe\">Swipe to see the full diagram. <\/span>Administrative is the largest family, and the one small teams underinvest in.<\/figcaption>\n<\/figure>\n\n<h2 id=\"addressable\" class=\"c-sage\">Required versus addressable<\/h2>\n\n<p>Each standard contains implementation specifications tagged one way or the other. This is the most misunderstood mechanic in the rule.<\/p>\n\n<table class=\"h-sage\">\n  <thead>\n    <tr><th>Tag<\/th><th>What it actually means<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td><strong>Required<\/strong><\/td><td>Implement it. No discretion<\/td><\/tr>\n    <tr><td><strong>Addressable<\/strong><\/td><td>Assess whether it is reasonable and appropriate for you. If yes, implement it. If not, document why and put an equivalent alternative in place<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<div class=\"callout\">\n  <p class=\"k\">Addressable does not mean optional<\/p>\n  <p>Encryption of ePHI is addressable. Skipping it without a documented analysis and an equivalent alternative is a violation, and unencrypted devices are behind a large share of reported breaches. In practice, encrypt and move on.<\/p>\n<\/div>\n\n<h2 id=\"risk\" class=\"c-apri\">Risk analysis is the foundation<\/h2>\n\n<p>An accurate and thorough <a href=\"https:\/\/www.osto.one\/resources\/glossary\/information-security-risk-assessment\/\">risk analysis<\/a> is a required specification under the administrative safeguards, and everything else depends on it. It identifies where ePHI lives, what threatens it, how likely each threat is, and what you will do about it. Every addressable decision has to trace back to it.<\/p>\n\n<p>It is not a one-off document. The rule expects it to be reviewed and updated as systems, vendors and the organisation change.<\/p>\n\n<h2 id=\"fails\" class=\"c-plum\">Where organisations fail<\/h2>\n\n<table class=\"h-peri\">\n  <thead>\n    <tr><th>Failure<\/th><th>Why it recurs in enforcement<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>No risk analysis, or one covering only part of the estate<\/td><td>The single most cited Security Rule finding<\/td><\/tr>\n    <tr><td>Unencrypted laptops and portable media<\/td><td>Addressable was read as optional<\/td><\/tr>\n    <tr><td>Access not removed when staff leave<\/td><td>Offboarding is a process gap, not a technical one<\/td><\/tr>\n    <tr><td>Audit logs collected but never reviewed<\/td><td>The rule requires review, not just collection<\/td><\/tr>\n    <tr><td>No contingency plan or untested backups<\/td><td>Availability is part of the rule, and ransomware tests it<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<h2 id=\"osto\">How Osto implements the Security Rule<\/h2>\n\n<p>Most of the technical family is infrastructure work, and Osto runs it directly: <a href=\"https:\/\/www.osto.one\/resources\/glossary\/mfa\/\">unique identification, authentication and MFA<\/a>, <a href=\"https:\/\/www.osto.one\/resources\/glossary\/encryption-at-rest-and-in-transit\/\">encryption at rest and in transit<\/a>, <a href=\"https:\/\/www.osto.one\/resources\/glossary\/siem\/\">audit controls with correlation and review<\/a>, <a href=\"https:\/\/www.osto.one\/resources\/glossary\/mdm\/\">device control<\/a>, <a href=\"https:\/\/www.osto.one\/resources\/glossary\/cspm\/\">cloud posture<\/a> and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/vapt\/\">vulnerability testing<\/a>. Security awareness training and policy generation cover parts of the administrative family, and evidence maps to HIPAA alongside <a href=\"https:\/\/www.osto.one\/resources\/glossary\/soc-2\/\">SOC 2<\/a> and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/iso-27001\/\">ISO 27001<\/a>.<\/p>\n\n<!-- ============ CTA ============ -->\n<div style=\"background:linear-gradient(135deg,#1c267a 0%,#3f4796 48%,#6b4576 100%);border-radius:22px;padding:38px 34px;margin:40px 0 12px;box-shadow:0 10px 26px rgba(28,38,122,.2);text-align:center;\">\n  <p style=\"display:inline-block;background:rgba(255,255,255,.16);color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:11px;font-weight:700;letter-spacing:1.2px;text-transform:uppercase;padding:6px 14px;border-radius:20px;margin:0 0 16px;\">Free security assessment<\/p>\n  <p style=\"color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:26px;line-height:1.3;font-weight:700;letter-spacing:-.4px;margin:0 0 12px;\">The Security Rule, deployed rather than documented<\/p>\n  <p style=\"color:#cfd3ea;font-family:'Inter',-apple-system,sans-serif;font-size:16px;line-height:1.65;margin:0 auto 26px;max-width:520px;\">Osto runs authentication, encryption, audit controls, endpoint and cloud posture, and maps evidence to every safeguard.<\/p>\n  <a href=\"https:\/\/osto.one\/contact\/\" style=\"display:inline-block;background:#ffffff;color:#1c267a;font-family:&#039;Inter&#039;,-apple-system,sans-serif;font-weight:700;font-size:16px;text-decoration:none;border-bottom:none;padding:14px 30px;border-radius:12px;margin:0 6px 10px;\" target=\"_blank\" rel=\"noopener\"><span style=\"color:#1c267a;\">Get a free security assessment<\/span><\/a>\n  <a href=\"https:\/\/osto.one\/book-demo\/\" style=\"display:inline-block;background:transparent;color:#ffffff;font-family:&#039;Inter&#039;,-apple-system,sans-serif;font-weight:600;font-size:16px;text-decoration:none;border:1.5px solid rgba(255,255,255,.5);border-radius:12px;padding:13px 28px;margin:0 6px 10px;\" target=\"_blank\" rel=\"noopener\"><span style=\"color:#ffffff;\">Book a platform walkthrough<\/span><\/a>\n  <p style=\"color:#b3b8d8;font-family:'Inter',-apple-system,sans-serif;font-size:13px;margin:14px 0 0;\">Risk analysis supported &middot; Controls that run &middot; One platform, everything<\/p>\n<\/div>\n\n\n<h2 id=\"faq\">Frequently asked questions<\/h2>\n\n<details>\n  <summary>What is the HIPAA Security Rule?<\/summary>\n  <p>The standard requiring covered entities and business associates to protect electronic PHI through administrative, physical and technical safeguards, preserving its confidentiality, integrity and availability.<\/p>\n<\/details>\n\n<details>\n  <summary>What does addressable mean in the Security Rule?<\/summary>\n  <p>That you must assess whether the specification is reasonable and appropriate for your environment. If it is, implement it. If not, document the reasoning and implement an equivalent alternative. It does not mean you can ignore it.<\/p>\n<\/details>\n\n<details>\n  <summary>Is encryption required under HIPAA?<\/summary>\n  <p>Encryption is addressable rather than required. In practice it is the expected control, and unencrypted ePHI features in a large share of reported breaches and resulting penalties.<\/p>\n<\/details>\n\n<details>\n  <summary>Does the Security Rule apply to paper records?<\/summary>\n  <p>No. It applies only to electronic PHI. Paper and spoken PHI are covered by the Privacy Rule, which applies to all forms.<\/p>\n<\/details>\n\n<details>\n  <summary>Can you be HIPAA certified?<\/summary>\n  <p>No. There is no official HIPAA certification. Organisations demonstrate compliance through a documented risk analysis, implemented safeguards, and independent assessments such as a SOC 2 report.<\/p>\n<\/details>\n\n<p class=\"related\"><strong>Related glossary terms:<\/strong> Administrative Safeguards &middot; Physical Safeguards &middot; Technical Safeguards &middot; ePHI &middot; HIPAA Privacy Rule &middot; Risk Assessment<\/p>\n\n<\/div>\n\n","protected":false},"excerpt":{"rendered":"<p>The HIPAA Security Rule sets the safeguards that must protect electronic protected health information. It is the part of HIPAA\u2026<\/p>\n","protected":false},"author":8,"featured_media":843,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[180],"tags":[336,308,335],"class_list":["post-842","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-glossary","tag-addressable-vs-required","tag-hipaa-security-rule","tag-security-rule-safeguards"],"_links":{"self":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/842","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/comments?post=842"}],"version-history":[{"count":1,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/842\/revisions"}],"predecessor-version":[{"id":844,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/842\/revisions\/844"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media\/843"}],"wp:attachment":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media?parent=842"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/categories?post=842"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/tags?post=842"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}