HIPAA Security Rule Checklist: Administrative, Physical, and Technical Safeguards

VERITY — HIPAA Compliance

HIPAA Security Rule Checklist: Administrative, Physical, and Technical Safeguards

The HIPAA Security Rule organizes its requirements into three safeguard categories and divides each specification as either Required or Addressable. This checklist maps every standard so your compliance team knows precisely what must be implemented and what must be assessed and documented.

Before You Start

Understanding Required Versus Addressable Specifications

Before reviewing the checklist, one distinction is critical to understand. When HHS designates a specification as Required, it must be implemented exactly as stated — no alternative analysis is permitted. When a specification is designated Addressable, the covered entity must assess whether the specification is reasonable and appropriate given its size, complexity, and capabilities. If it is, implementation is required. If an alternative measure accomplishes the same purpose more effectively for that specific organization, the alternative may be implemented — but the analysis and the rationale must be documented. “Addressable” does not mean optional; it means implementation decisions must be justified in writing.

This distinction drives a significant share of OCR enforcement findings. Organizations that treat addressable specifications as unconditional opt-outs, without conducting and documenting the required assessment, are not compliant. The complete HIPAA compliance framework and its relationship to your risk assessment program determine which addressable specifications are reasonable for your environment.

45 CFR §164.308

Administrative Safeguards

Administrative safeguards are the policies, procedures, and management practices governing the selection, development, implementation, and maintenance of security measures that protect ePHI.

StandardImplementation SpecificationType
Security Management ProcessRisk AnalysisRequired
Security Management ProcessRisk ManagementRequired
Security Management ProcessSanction PolicyRequired
Security Management ProcessInformation System Activity ReviewRequired
Assigned Security ResponsibilityDesignate a Security OfficialRequired
Workforce SecurityAuthorization and SupervisionAddressable
Workforce SecurityWorkforce Clearance ProcedureAddressable
Workforce SecurityTermination ProceduresAddressable
Information Access ManagementIsolating Healthcare Clearinghouse FunctionsRequired
Information Access ManagementAccess AuthorizationAddressable
Information Access ManagementAccess Establishment and ModificationAddressable
Security Awareness and TrainingSecurity RemindersAddressable
Security Awareness and TrainingProtection from Malicious SoftwareAddressable
Security Awareness and TrainingLog-in MonitoringAddressable
Security Awareness and TrainingPassword ManagementAddressable
Security Incident ProceduresResponse and ReportingRequired
Contingency PlanData Backup PlanRequired
Contingency PlanDisaster Recovery PlanRequired
Contingency PlanEmergency Mode Operation PlanRequired
Contingency PlanTesting and Revision ProceduresAddressable
Contingency PlanApplications and Data Criticality AnalysisAddressable
EvaluationPeriodic Technical and Non-Technical EvaluationRequired
Business Associate ContractsWritten Contract or Other ArrangementRequired

45 CFR §164.310

Physical Safeguards

Physical safeguards govern the physical measures, policies, and procedures your organization uses to protect electronic information systems and the facilities and equipment that house them from natural and environmental hazards and unauthorized intrusion.

StandardImplementation SpecificationType
Facility Access ControlsContingency OperationsAddressable
Facility Access ControlsFacility Security PlanAddressable
Facility Access ControlsAccess Control and Validation ProceduresAddressable
Facility Access ControlsMaintenance RecordsAddressable
Workstation UseWorkstation Use PolicyRequired
Workstation SecurityPhysical Safeguards for WorkstationsRequired
Device and Media ControlsDisposalRequired
Device and Media ControlsMedia Re-useRequired
Device and Media ControlsAccountabilityAddressable
Device and Media ControlsData Backup and StorageAddressable

45 CFR §164.312

Technical Safeguards

Technical safeguards are the technology and the policy and procedures for its use that protect ePHI and control access to it. These are the controls most directly visible in security audits and breach investigations.

StandardImplementation SpecificationType
Access ControlUnique User IdentificationRequired
Access ControlEmergency Access ProcedureRequired
Access ControlAutomatic LogoffAddressable
Access ControlEncryption and DecryptionAddressable
Audit ControlsHardware, Software, and Procedural Mechanisms for Recording and Examining ActivityRequired
IntegrityMechanism to Authenticate ePHIAddressable
Person or Entity AuthenticationAuthentication MechanismsRequired
Transmission SecurityEncryption of ePHI in TransitAddressable
Transmission SecurityIntegrity ControlsAddressable

45 CFR §164.314

Organizational Requirements

This section governs the contractual requirements between covered entities and business associates, including the mandatory elements of a Business Associate Agreement. If your organization shares ePHI with vendors, cloud providers, billing processors, or any other third party, written contracts are Required — not Addressable.

45 CFR §164.316

Policies, Procedures, and Documentation

All implemented safeguards must be supported by written policies and procedures. Documentation must be retained for six years from the date of creation or the date it was last in effect, whichever is later. This documentation retention requirement is frequently overlooked and directly relevant to how OCR evaluates the penalty tier applicable when a violation is identified.

Beyond the Checklist

Turning the Checklist Into a Continuous Program

A checklist confirms point-in-time status. Sustained compliance requires continuous monitoring, periodic evaluation, and rapid response when new threats emerge. Armorstack’s 100+ technical experts operate at the intersection of the three safeguard categories — providing the technical audit and monitoring depth of our SENTRY Managed Detection and Response program, the physical access control assessments of our CITADEL practice, and the advisory governance structures of our VERITY vCISO offering.

The result is a Security Rule compliance program that does not go stale between annual reviews. Your risk assessment drives prioritization, your breach notification readiness is tested proactively, and your readiness for the 2025 proposed updates is built in from the start.

FAQ

Frequently Asked Questions

What is the difference between Required and Addressable specifications in the HIPAA Security Rule?

Required specifications must be implemented exactly as stated with no alternative. Addressable specifications require a documented assessment of whether the specification is reasonable and appropriate for the organization. If it is, it must be implemented. If an equivalent alternative better serves the same security objective for that specific organization, the alternative may be used — but the analysis and rationale must be documented in writing. Addressable does not mean optional.

What are the three categories of HIPAA Security Rule safeguards?

The HIPAA Security Rule organizes all requirements into Administrative Safeguards (45 CFR §164.308), Physical Safeguards (45 CFR §164.310), and Technical Safeguards (45 CFR §164.312). Administrative safeguards govern policies and workforce management. Physical safeguards govern facility access and device controls. Technical safeguards govern access control, audit logging, authentication, and transmission security.

How long must HIPAA Security Rule documentation be retained?

Under 45 CFR §164.316(b)(2), written policies, procedures, actions, activities, and assessments required by the Security Rule must be retained for six years from the date of creation or the date they were last in effect, whichever is later. This retention requirement applies to risk assessments, risk management plans, training records, and all policy documents.

Does the HIPAA Security Rule require encryption?

Encryption is an Addressable specification under both the Access Control standard (encryption and decryption of ePHI at rest) and the Transmission Security standard (encryption of ePHI in transit). This means each covered entity must document whether encryption is reasonable and appropriate for its environment. In practice, OCR consistently treats unencrypted ePHI on portable devices and unencrypted transmissions as high-risk findings. The proposed 2025 Security Rule update would elevate encryption requirements significantly.