{"id":855,"date":"2026-08-17T05:44:53","date_gmt":"2026-08-17T05:44:53","guid":{"rendered":"https:\/\/www.osto.one\/resources\/?p=855"},"modified":"2026-08-17T05:44:53","modified_gmt":"2026-08-17T05:44:53","slug":"technical-safeguards","status":"publish","type":"post","link":"https:\/\/www.osto.one\/resources\/glossary\/technical-safeguards\/","title":{"rendered":"Technical Safeguards"},"content":{"rendered":"\n<!-- =========================================================================\n     OSTO GLOSSARY: TECHNICAL SAFEGUARDS\n     Shared glossary design system. Paste into one Custom HTML block. No H1.\n     ========================================================================= -->\n\n<style>\n.og{\n  --navy:#1c267a; --text:#0f1538; --muted:#0f1538; --light:#0f1538;\n  --border:#e7e9f2; --divider:#eceef5; --white:#ffffff;\n\n  --peri-50:#f4f5fd;  --peri-100:#e9ecfa; --peri-200:#cfd5f2; --peri-700:#4a52a8;\n  --sage-50:#f2f8f5;  --sage-100:#e3f0e9; --sage-200:#c3ddce; --sage-700:#3a6f5d;\n  --apri-50:#fdf6f0;  --apri-100:#fbe9dc; --apri-200:#f2cdb2; --apri-700:#a2603a;\n  --plum-50:#f8f3f9;  --plum-100:#f0e6f3; --plum-200:#dcc6e2; --plum-700:#6b4576;\n  --sky-50:#f1f7fb;   --sky-100:#e2eff7;  --sky-200:#bfd9e9;  --sky-700:#2f6a89;\n\n  --shadow:0 6px 22px rgba(15,21,56,.05);\n  --font:'Inter',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif;\n  font-family:var(--font); font-size:17px; line-height:1.75; color:var(--text);\n}\n.og p{margin:0 0 22px}\n.og h2{font-family:var(--font);font-size:clamp(25px,3vw,31px);font-weight:700;line-height:1.25;letter-spacing:-.5px;color:var(--navy);margin:52px 0 8px;scroll-margin-top:92px}\n.og h2::after{content:\"\";display:block;width:46px;height:5px;border-radius:3px;margin:12px 0 18px;background:var(--peri-200)}\n.og h2.c-sage::after{background:var(--sage-200)}\n.og h2.c-apri::after{background:var(--apri-200)}\n.og h2.c-plum::after{background:var(--plum-200)}\n.og h2.c-sky::after{background:var(--sky-200)}\n.og ul,.og ol{padding-left:22px;margin:0 0 24px}\n.og li{margin-bottom:9px}\n.og strong{font-weight:600}\n\n.og .dek{font-size:20px;line-height:1.6;color:var(--muted);margin:0 0 18px}\n.og .tags{margin:0 0 30px;padding:0;list-style:none;display:flex;flex-wrap:wrap;gap:8px}\n.og .tags li{margin:0}\n.og .tag{display:inline-block;font-size:12px;font-weight:600;letter-spacing:.7px;text-transform:uppercase;padding:6px 13px;border-radius:20px}\n.og .t-peri{background:var(--peri-100);color:var(--peri-700)}\n.og .t-sage{background:var(--sage-100);color:var(--sage-700)}\n\n.og .short{background:linear-gradient(135deg,var(--peri-100) 0%,var(--sage-100) 100%);border-radius:22px;padding:28px 32px;margin:0 0 30px}\n.og .short .k{font-size:13px;font-weight:700;letter-spacing:1.4px;text-transform:uppercase;color:var(--peri-700);margin:0 0 10px}\n.og .short p{font-size:19px;line-height:1.65;margin:0;color:var(--text)}\n\n.og .toc{background:var(--peri-50);border-radius:20px;padding:24px 28px;margin:0 0 34px}\n.og .toc .k{font-size:12px;font-weight:700;letter-spacing:1.3px;text-transform:uppercase;color:var(--peri-700);margin:0 0 12px}\n.og .toc ol{margin:0;padding-left:20px;columns:2;column-gap:34px}\n.og .toc li{margin-bottom:8px;break-inside:avoid;font-size:16px}\n.og .toc a{color:var(--navy);text-decoration:none;border-bottom:1px solid rgba(28,38,122,.22)}\n\n.og .callout{border-radius:4px;padding:24px 28px;margin:0 0 30px;background:var(--white);border:2px solid var(--navy)}\n.og .callout .k{font-weight:700;font-size:17px;margin:0 0 8px;color:var(--navy)}\n.og .callout p:last-child{margin-bottom:0}\n.og .callout.c-plum{background:var(--plum-50);border:none;border-radius:20px}\n.og .callout.c-plum .k{color:var(--plum-700)}\n\n.og figure{margin:0 0 30px}\n.og .sx{overflow-x:auto;-webkit-overflow-scrolling:touch;border-radius:20px;background:var(--white);box-shadow:var(--shadow)}\n.og .sx svg{display:block;width:100%;height:auto;min-width:600px}\n.og figcaption{font-size:14px;line-height:1.6;color:var(--muted);margin-top:12px}\n.og .swipe{display:none}\n\n.og table{width:100%;border-collapse:collapse;margin:0 0 28px;font-size:15px;background:var(--white);border-radius:18px;overflow:hidden;box-shadow:var(--shadow)}\n.og th{text-align:left;padding:14px 16px;font-weight:700;font-size:12.5px;letter-spacing:.8px;text-transform:uppercase}\n.og td{border-bottom:1px solid var(--divider);padding:13px 16px;vertical-align:top;line-height:1.6}\n.og tr:last-child td{border-bottom:none}\n.og .h-peri th{background:var(--peri-100);color:var(--peri-700)}\n.og .h-sage th{background:var(--sage-100);color:var(--sage-700)}\n.og .h-plum th{background:var(--plum-100);color:var(--plum-700)}\n\n.og .trio{display:grid;grid-template-columns:repeat(3,1fr);gap:14px;margin:0 0 28px}\n.og .tcard{border-radius:18px;padding:20px 22px}\n.og .tcard .n{font-size:16px;font-weight:700;margin:0 0 4px}\n.og .tcard .g{font-size:13px;font-weight:600;margin:0 0 10px;opacity:.8}\n.og .tcard p{font-size:14px;line-height:1.55;margin:0;color:var(--muted)}\n.og .tcard.a{background:var(--sky-50)}   .og .tcard.a .n,.og .tcard.a .g{color:var(--sky-700)}\n.og .tcard.b{background:var(--sage-50)}  .og .tcard.b .n,.og .tcard.b .g{color:var(--sage-700)}\n.og .tcard.c{background:var(--plum-50)}  .og .tcard.c .n,.og .tcard.c .g{color:var(--plum-700)}\n\n.og .pill{display:inline-block;font-size:11px;font-weight:700;letter-spacing:.8px;text-transform:uppercase;padding:5px 11px;border-radius:20px;white-space:nowrap}\n.og .p-req{background:var(--plum-200);color:#4d2f57}\n.og .p-exp{background:var(--sky-100);color:var(--sky-700)}\n.og .p-imp{background:#eef0f4;color:var(--muted)}\n.og .p-ask{background:var(--apri-100);color:var(--apri-700)}\n\n.og details{background:var(--white);border-radius:14px;margin:0 0 10px;box-shadow:0 2px 10px rgba(15,21,56,.04)}\n.og summary{cursor:pointer;padding:16px 20px;font-weight:600;font-size:17px;color:var(--navy);list-style:none;display:flex;justify-content:space-between;gap:16px;align-items:flex-start}\n.og summary::-webkit-details-marker{display:none}\n.og summary::after{content:\"+\";font-size:22px;line-height:1;color:var(--peri-700);flex:0 0 auto}\n.og details[open] summary::after{content:\"\\2013\"}\n.og details p{padding:0 20px 18px;margin:0;font-size:16px;line-height:1.7}\n\n.og .related{font-size:15px;color:var(--muted);border-top:1px solid var(--divider);padding-top:22px;margin-top:40px}\n\n@media(max-width:700px){\n  .og{font-size:16px}\n  .og .dek{font-size:18px}\n  .og .short p{font-size:17px}\n  .og .short,.og .toc,.og .callout{padding:22px 20px}\n  .og .toc ol{columns:1}\n  .og .trio{grid-template-columns:1fr}\n  .og .swipe{display:inline;font-weight:600;color:var(--peri-700)}\n  .og table{font-size:14px}\n  .og th,.og td{padding:11px 12px}\n}\n<\/style>\n\n<div class=\"og\">\n\n<p class=\"dek\">Technical safeguards are the five HIPAA Security Rule standards that govern the systems holding electronic protected health information.<\/p>\n\n<ul class=\"tags\">\n  <li><span class=\"tag t-peri\">Glossary<\/span><\/li>\n  <li><span class=\"tag t-sage\">HIPAA<\/span><\/li>\n<\/ul>\n\n<div class=\"short\">\n  <p class=\"k\">The short answer<\/p>\n  <p>Technical safeguards are access control, audit controls, integrity, person or entity authentication, and transmission security. They cover who can reach ePHI, what gets recorded when they do, whether the data can be altered undetected, how identity is proven, and how data is protected in motion. The rule states outcomes rather than technologies.<\/p>\n<\/div>\n\n<p>For an engineering team this is the most familiar family. Most of it is ordinary practice, documented properly and evidenced.<\/p>\n\n<div class=\"toc\">\n  <p class=\"k\">On this page<\/p>\n  <ol>\n    <li><a href=\"#five\">The five standards<\/a><\/li>\n    <li><a href=\"#access\">Access control in detail<\/a><\/li>\n    <li><a href=\"#audit\">Audit controls<\/a><\/li>\n    <li><a href=\"#transmission\">Transmission security<\/a><\/li>\n    <li><a href=\"#osto\">How Osto implements them<\/a><\/li>\n    <li><a href=\"#faq\">FAQ<\/a><\/li>\n  <\/ol>\n<\/div>\n\n<h2 id=\"five\">The five standards<\/h2>\n\n<figure>\n<div class=\"sx\">\n<svg viewBox=\"0 0 760 250\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" role=\"img\" aria-label=\"The five technical safeguard standards: access control, audit controls, integrity, authentication and transmission security.\">\n  <text x=\"20\" y=\"26\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" letter-spacing=\"1.2\" fill=\"#0f1538\">FIVE STANDARDS, R = REQUIRED, A = ADDRESSABLE<\/text>\n\n  <rect x=\"12\" y=\"42\" width=\"238\" height=\"76\" rx=\"14\" fill=\"#e9ecfa\"\/>\n  <text x=\"131\" y=\"68\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" font-weight=\"700\" fill=\"#4a52a8\">Access control<\/text>\n  <text x=\"131\" y=\"88\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10.5\" fill=\"#0f1538\">Unique user ID (R), emergency access (R)<\/text>\n  <text x=\"131\" y=\"105\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10.5\" fill=\"#0f1538\">Auto logoff (A), encryption (A)<\/text>\n\n  <rect x=\"261\" y=\"42\" width=\"238\" height=\"76\" rx=\"14\" fill=\"#e3f0e9\"\/>\n  <text x=\"380\" y=\"68\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" font-weight=\"700\" fill=\"#3a6f5d\">Audit controls<\/text>\n  <text x=\"380\" y=\"88\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10.5\" fill=\"#0f1538\">Record and examine activity in<\/text>\n  <text x=\"380\" y=\"105\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10.5\" fill=\"#0f1538\">systems holding ePHI (R)<\/text>\n\n  <rect x=\"510\" y=\"42\" width=\"238\" height=\"76\" rx=\"14\" fill=\"#fbe9dc\"\/>\n  <text x=\"629\" y=\"68\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" font-weight=\"700\" fill=\"#a2603a\">Integrity<\/text>\n  <text x=\"629\" y=\"88\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10.5\" fill=\"#0f1538\">Protect ePHI from improper<\/text>\n  <text x=\"629\" y=\"105\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10.5\" fill=\"#0f1538\">alteration or destruction (A)<\/text>\n\n  <rect x=\"136\" y=\"132\" width=\"238\" height=\"76\" rx=\"14\" fill=\"#f0e6f3\"\/>\n  <text x=\"255\" y=\"158\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" font-weight=\"700\" fill=\"#6b4576\">Authentication<\/text>\n  <text x=\"255\" y=\"178\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10.5\" fill=\"#0f1538\">Verify the person or entity is<\/text>\n  <text x=\"255\" y=\"195\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10.5\" fill=\"#0f1538\">who they claim to be (R)<\/text>\n\n  <rect x=\"386\" y=\"132\" width=\"238\" height=\"76\" rx=\"14\" fill=\"#1c267a\"\/>\n  <text x=\"505\" y=\"158\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" font-weight=\"700\" fill=\"#ffffff\">Transmission security<\/text>\n  <text x=\"505\" y=\"178\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10.5\" fill=\"#b9c1e6\">Integrity controls (A),<\/text>\n  <text x=\"505\" y=\"195\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10.5\" fill=\"#b9c1e6\">encryption in transit (A)<\/text>\n\n  <text x=\"380\" y=\"236\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" fill=\"#0f1538\">Addressable still requires a documented decision and an equivalent alternative if you decline.<\/text>\n<\/svg>\n<\/div>\n<figcaption><span class=\"swipe\">Swipe to see the full diagram. <\/span>Encryption appears twice, at rest and in transit, and is addressable in both places.<\/figcaption>\n<\/figure>\n\n<h2 id=\"access\" class=\"c-sage\">Access control in detail<\/h2>\n\n<table class=\"h-sage\">\n  <thead>\n    <tr><th>Specification<\/th><th>What it means<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td><strong>Unique user identification<\/strong> (required)<\/td><td>Every person has their own account. Shared logins break the audit trail and are a standing violation<\/td><\/tr>\n    <tr><td><strong>Emergency access procedure<\/strong> (required)<\/td><td>A documented way to reach ePHI during an outage or crisis, with the use logged<\/td><\/tr>\n    <tr><td><strong>Automatic logoff<\/strong> (addressable)<\/td><td>Sessions terminate after inactivity<\/td><\/tr>\n    <tr><td><strong>Encryption and decryption<\/strong> (addressable)<\/td><td><a href=\"https:\/\/www.osto.one\/resources\/glossary\/encryption-at-rest-and-in-transit\/\">Encryption at rest<\/a>, or a documented equivalent<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<div class=\"callout\">\n  <p class=\"k\">Shared accounts are the quiet failure<\/p>\n  <p>A single admin login used by three engineers defeats unique identification and audit controls at once. When an investigator asks who accessed a record, &#8220;the ops account&#8221; is not an answer.<\/p>\n<\/div>\n\n<h2 id=\"audit\" class=\"c-apri\">Audit controls<\/h2>\n\n<p>Required, with no addressable escape. You need hardware, software or procedural mechanisms that record and examine activity in systems containing ePHI. Two halves matter: recording, and examining. Logs written to a bucket nobody opens satisfy half a requirement.<\/p>\n\n<p>Retention is not fixed by the Security Rule itself, though HIPAA documentation requirements run to six years and most organisations align log retention with that.<\/p>\n\n<h2 id=\"transmission\" class=\"c-plum\">Transmission security<\/h2>\n\n<div class=\"trio\">\n  <div class=\"tcard a\">\n    <p class=\"n\">Integrity controls<\/p>\n    <p>Detect whether ePHI was altered in transit. TLS provides this as part of the protocol.<\/p>\n  <\/div>\n  <div class=\"tcard b\">\n    <p class=\"n\">Encryption<\/p>\n    <p>Addressable, but expected. Modern TLS on every path carrying ePHI, internal ones included.<\/p>\n  <\/div>\n  <div class=\"tcard c\">\n    <p class=\"n\">Internal traffic counts<\/p>\n    <p>Service-to-service calls inside a VPC still transmit ePHI and are frequently overlooked.<\/p>\n  <\/div>\n<\/div>\n\n<h2 id=\"osto\">How Osto implements them<\/h2>\n\n<p>Four of the five standards are infrastructure Osto runs directly. <a href=\"https:\/\/www.osto.one\/resources\/glossary\/mfa\/\">Identity, unique accounts, MFA and session control<\/a> cover access control and authentication. <a href=\"https:\/\/www.osto.one\/resources\/glossary\/siem\/\">SIEM with cross-module correlation<\/a> covers audit controls including the review half, not just collection. <a href=\"https:\/\/www.osto.one\/resources\/glossary\/encryption-at-rest-and-in-transit\/\">Encryption<\/a> and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/ztna\/\">ZTNA<\/a> cover transmission security, and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/cspm\/\">cloud posture<\/a> flags a storage bucket or database that drifts out of policy.<\/p>\n\n<!-- ============ CTA ============ -->\n<div style=\"background:linear-gradient(135deg,#1c267a 0%,#3f4796 48%,#6b4576 100%);border-radius:22px;padding:38px 34px;margin:40px 0 12px;box-shadow:0 10px 26px rgba(28,38,122,.2);text-align:center;\">\n  <p style=\"display:inline-block;background:rgba(255,255,255,.16);color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:11px;font-weight:700;letter-spacing:1.2px;text-transform:uppercase;padding:6px 14px;border-radius:20px;margin:0 0 16px;\">Free security assessment<\/p>\n  <p style=\"color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:26px;line-height:1.3;font-weight:700;letter-spacing:-.4px;margin:0 0 12px;\">Four of five standards, running out of the box<\/p>\n  <p style=\"color:#cfd3ea;font-family:'Inter',-apple-system,sans-serif;font-size:16px;line-height:1.65;margin:0 auto 26px;max-width:520px;\">Unique identity and MFA, audit controls with real review, encryption and transmission security in one integrated stack.<\/p>\n  <a href=\"https:\/\/osto.one\/contact\/\" style=\"display:inline-block;background:#ffffff;color:#1c267a;font-family:&#039;Inter&#039;,-apple-system,sans-serif;font-weight:700;font-size:16px;text-decoration:none;border-bottom:none;padding:14px 30px;border-radius:12px;margin:0 6px 10px;\" target=\"_blank\" rel=\"noopener\"><span style=\"color:#1c267a;\">Get a free security assessment<\/span><\/a>\n  <a href=\"https:\/\/osto.one\/book-demo\/\" style=\"display:inline-block;background:transparent;color:#ffffff;font-family:&#039;Inter&#039;,-apple-system,sans-serif;font-weight:600;font-size:16px;text-decoration:none;border:1.5px solid rgba(255,255,255,.5);border-radius:12px;padding:13px 28px;margin:0 6px 10px;\" target=\"_blank\" rel=\"noopener\"><span style=\"color:#ffffff;\">Book a platform walkthrough<\/span><\/a>\n  <p style=\"color:#b3b8d8;font-family:'Inter',-apple-system,sans-serif;font-size:13px;margin:14px 0 0;\">Access, logging, encryption &middot; Cloud posture &middot; One platform, everything<\/p>\n<\/div>\n\n\n<h2 id=\"faq\">Frequently asked questions<\/h2>\n\n<details>\n  <summary>What are technical safeguards under HIPAA?<\/summary>\n  <p>The five Security Rule standards governing systems that hold ePHI: access control, audit controls, integrity, person or entity authentication, and transmission security.<\/p>\n<\/details>\n\n<details>\n  <summary>Is MFA required under HIPAA?<\/summary>\n  <p>The rule requires authentication but does not name multi-factor specifically. In practice MFA is the expected implementation, and regulators and cyber insurers treat its absence as a significant weakness.<\/p>\n<\/details>\n\n<details>\n  <summary>Are audit logs required?<\/summary>\n  <p>Yes. Audit controls is a required standard with no addressable alternative. You must both record activity in systems containing ePHI and examine those records, not merely retain them.<\/p>\n<\/details>\n\n<details>\n  <summary>Does HIPAA require encryption in transit?<\/summary>\n  <p>It is addressable rather than required, meaning you must implement it or document why an equivalent alternative is reasonable. Given TLS is standard practice, declining it is very hard to justify.<\/p>\n<\/details>\n\n<details>\n  <summary>Are shared accounts allowed?<\/summary>\n  <p>No. Unique user identification is a required specification. Shared credentials break both access control and the audit trail, and are a common enforcement finding.<\/p>\n<\/details>\n\n<p class=\"related\"><strong>Related glossary terms:<\/strong> HIPAA Security Rule &middot; Administrative Safeguards &middot; Physical Safeguards &middot; ePHI &middot; MFA &middot; Encryption at Rest and in Transit<\/p>\n\n<\/div>\n\n","protected":false},"excerpt":{"rendered":"<p>Technical safeguards are the five HIPAA Security Rule standards that govern the systems holding electronic protected health information. Glossary HIPAA\u2026<\/p>\n","protected":false},"author":8,"featured_media":856,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[180],"tags":[344,343],"class_list":["post-855","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-glossary","tag-access-control-hipaa","tag-technical-safeguards"],"_links":{"self":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/855","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/comments?post=855"}],"version-history":[{"count":1,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/855\/revisions"}],"predecessor-version":[{"id":857,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/855\/revisions\/857"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media\/856"}],"wp:attachment":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media?parent=855"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/categories?post=855"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/tags?post=855"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}