Skip to main content
—
Framework library
Framework module · hipaa-security-rule

HIPAA Security Rule

The federal safeguards standard for electronic protected health information, binding on covered entities and their business associates.

45 CFR Part 164 Subparts A and C · HHS Office for Civil Rights

Standing today
Onboardable
5 evidence lanes · 65 control units

00Answer

from the registry record
What is HIPAA Security Rule?
The federal safeguards standard for electronic protected health information, binding on covered entities and their business associates.
Who does HIPAA Security Rule apply to?
HIPAA Security Rule applies to healthcare, US, per HHS Office for Civil Rights.
What is the current version of HIPAA Security Rule?
The current edition is 45 CFR Part 164 Subparts A and C, issued by HHS Office for Civil Rights. Source: https://www.hhs.gov/hipaa/for-professionals/security/index.html.
What does an assessment under HIPAA Security Rule require?
65 control units are on record (65 requirements — 22 standards and 43 implementation specifications (Required or Addressable) — with the regulation's own citations and verbatim text, parsed from eCFR point-in-time XML. Federal regulation is not subject to copyright, so the text is the rule's own, not a paraphrase.), organized into 5 control families: Administrative safeguards, Physical safeguards, Technical safeguards, Organizational requirements, Policies, procedures and documentation.

01Standing

Onboardable

A project opens into evidence lanes with a real control set behind them; collection is demonstrative until a test plan runs against a real target.

Blueprint with 5 evidence lanes and a control set; no registered test plans yet. A project opens into real lanes; collection is demonstrative until a READY plan or a release path exists.

Engagement
HIPAA Security Rule readiness
Control set
65 requirements — 22 standards and 43 implementation specifications (Required or Addressable) — with the regulation's own citations and verbatim text, parsed from eCFR point-in-time XML. Federal regulation is not subject to copyright, so the text is the rule's own, not a paraphrase.
Native identifiers
Regulation citations, e.g. 164.308(a)(1)(ii)(A) for an implementation specification and 164.312(b) for a standard.
Evidence lanes
  1. 01§ 164.308 — Administrative safeguardsrisk analysis and risk management plan · sanction policy and information system activity review records · workforce clearance, authorization and termination records · access authorization and modification records · security awareness training completion · incident response procedure and incident log · contingency, backup and disaster recovery plans with test results · periodic technical and non-technical evaluation · business associate agreements
  2. 02§ 164.310 — Physical safeguardsfacility security plan and access control records · workstation use and security standards · media disposal and re-use records · hardware and media movement accountability
  3. 03§ 164.312 — Technical safeguardsunique user identification and emergency access configuration · automatic logoff and encryption settings · audit log configuration and review records · integrity controls for ePHI · authentication configuration (MFA, identity provider) · transmission encryption configuration
  4. 04§ 164.314 — Organizational requirementsexecuted business associate and subcontractor agreements · group health plan document provisions, where applicable
  5. 05§ 164.316 — Policies, procedures and documentationsecurity policies and procedures with version history · documentation retention and availability records · periodic review and update records

02Registry record

checked 2026-09-23
Registry status
Beta · catalog on diskParsed catalog: a source-pinned control or requirement catalog for this regime exists in the repo. `catalogPath` is non-null and `controlCount` is real. This does not mean tenant workflows are activated or that an assurance outcome has been earned.
Control units
6565 requirements — 22 standards and 43 implementation specifications (Required or Addressable) — with the regulation's own citations and verbatim text, parsed from eCFR point-in-time XML. Federal regulation is not subject to copyright, so the text is the rule's own, not a paraphrase.
Control families
Administrative safeguards · Physical safeguards · Technical safeguards · Organizational requirements · Policies, procedures and documentation
Applies to
healthcare · US
Verification
Primary — the issuing body's own page was read and states this version. checked 2026-09-23
Pending change
OCR's January 2025 proposal (RIN 0945-AA22) is not final, so the existing Security Rule remains in force. HHS's Unified Agenda lists July 2027 as an anticipated final-action date, not a guaranteed effective date.Expected: July 2027 (anticipated final action in the HHS Unified Agenda)

03Version ledger

1 edition
45 CFR Part 164 Subparts A and CCurrent editiondate not published

06Related frameworks

scored from registry facts
  1. Also applies to healthcare · A licensed cybersecurity and risk-management framework used across healthcare and other sectors. HITRUST offers scoped assessment and certification programs through its authorized processes; registry tracking claims no certification.

  2. HIPAA Breach Notification Rule45 CFR §§ 164.400–414

    Also applies to healthcare · What a covered entity or business associate must tell individuals, the media, and HHS after a breach of unsecured protected health information, and how fast.

  3. SOC 22017 TSC (revised points of focus, 2022)

    Same framework family · Independent assurance over how a service organization handles customer data. Type 1 and Type 2 are two report options over the same criteria, not two standards.

  4. HIPAA Privacy Rule45 CFR Part 160 and Part 164 Subparts A and E

    Also applies to healthcare · The federal rule governing permitted uses and disclosures of protected health information, minimum-necessary practices, notices, and individual privacy rights for covered entities and business associates.

HIPAA Security Rule | ControlFrame