HIPAA Security Rule Checklist: Administrative, Physical, and Technical Safeguards
The HIPAA Security Rule organizes its requirements into three safeguard categories and divides each specification as either Required or Addressable. This checklist maps every standard so your compliance team knows precisely what must be implemented and what must be assessed and documented.
Before You Start
Understanding Required Versus Addressable Specifications
Before reviewing the checklist, one distinction is critical to understand. When HHS designates a specification as Required, it must be implemented exactly as stated — no alternative analysis is permitted. When a specification is designated Addressable, the covered entity must assess whether the specification is reasonable and appropriate given its size, complexity, and capabilities. If it is, implementation is required. If an alternative measure accomplishes the same purpose more effectively for that specific organization, the alternative may be implemented — but the analysis and the rationale must be documented. “Addressable” does not mean optional; it means implementation decisions must be justified in writing.
This distinction drives a significant share of OCR enforcement findings. Organizations that treat addressable specifications as unconditional opt-outs, without conducting and documenting the required assessment, are not compliant. The complete HIPAA compliance framework and its relationship to your risk assessment program determine which addressable specifications are reasonable for your environment.
45 CFR §164.308
Administrative Safeguards
Administrative safeguards are the policies, procedures, and management practices governing the selection, development, implementation, and maintenance of security measures that protect ePHI.
| Standard | Implementation Specification | Type |
|---|---|---|
| Security Management Process | Risk Analysis | Required |
| Security Management Process | Risk Management | Required |
| Security Management Process | Sanction Policy | Required |
| Security Management Process | Information System Activity Review | Required |
| Assigned Security Responsibility | Designate a Security Official | Required |
| Workforce Security | Authorization and Supervision | Addressable |
| Workforce Security | Workforce Clearance Procedure | Addressable |
| Workforce Security | Termination Procedures | Addressable |
| Information Access Management | Isolating Healthcare Clearinghouse Functions | Required |
| Information Access Management | Access Authorization | Addressable |
| Information Access Management | Access Establishment and Modification | Addressable |
| Security Awareness and Training | Security Reminders | Addressable |
| Security Awareness and Training | Protection from Malicious Software | Addressable |
| Security Awareness and Training | Log-in Monitoring | Addressable |
| Security Awareness and Training | Password Management | Addressable |
| Security Incident Procedures | Response and Reporting | Required |
| Contingency Plan | Data Backup Plan | Required |
| Contingency Plan | Disaster Recovery Plan | Required |
| Contingency Plan | Emergency Mode Operation Plan | Required |
| Contingency Plan | Testing and Revision Procedures | Addressable |
| Contingency Plan | Applications and Data Criticality Analysis | Addressable |
| Evaluation | Periodic Technical and Non-Technical Evaluation | Required |
| Business Associate Contracts | Written Contract or Other Arrangement | Required |
45 CFR §164.310
Physical Safeguards
Physical safeguards govern the physical measures, policies, and procedures your organization uses to protect electronic information systems and the facilities and equipment that house them from natural and environmental hazards and unauthorized intrusion.
| Standard | Implementation Specification | Type |
|---|---|---|
| Facility Access Controls | Contingency Operations | Addressable |
| Facility Access Controls | Facility Security Plan | Addressable |
| Facility Access Controls | Access Control and Validation Procedures | Addressable |
| Facility Access Controls | Maintenance Records | Addressable |
| Workstation Use | Workstation Use Policy | Required |
| Workstation Security | Physical Safeguards for Workstations | Required |
| Device and Media Controls | Disposal | Required |
| Device and Media Controls | Media Re-use | Required |
| Device and Media Controls | Accountability | Addressable |
| Device and Media Controls | Data Backup and Storage | Addressable |
45 CFR §164.312
Technical Safeguards
Technical safeguards are the technology and the policy and procedures for its use that protect ePHI and control access to it. These are the controls most directly visible in security audits and breach investigations.
| Standard | Implementation Specification | Type |
|---|---|---|
| Access Control | Unique User Identification | Required |
| Access Control | Emergency Access Procedure | Required |
| Access Control | Automatic Logoff | Addressable |
| Access Control | Encryption and Decryption | Addressable |
| Audit Controls | Hardware, Software, and Procedural Mechanisms for Recording and Examining Activity | Required |
| Integrity | Mechanism to Authenticate ePHI | Addressable |
| Person or Entity Authentication | Authentication Mechanisms | Required |
| Transmission Security | Encryption of ePHI in Transit | Addressable |
| Transmission Security | Integrity Controls | Addressable |
45 CFR §164.314
Organizational Requirements
This section governs the contractual requirements between covered entities and business associates, including the mandatory elements of a Business Associate Agreement. If your organization shares ePHI with vendors, cloud providers, billing processors, or any other third party, written contracts are Required — not Addressable.
45 CFR §164.316
Policies, Procedures, and Documentation
All implemented safeguards must be supported by written policies and procedures. Documentation must be retained for six years from the date of creation or the date it was last in effect, whichever is later. This documentation retention requirement is frequently overlooked and directly relevant to how OCR evaluates the penalty tier applicable when a violation is identified.
Beyond the Checklist
Turning the Checklist Into a Continuous Program
A checklist confirms point-in-time status. Sustained compliance requires continuous monitoring, periodic evaluation, and rapid response when new threats emerge. Armorstack’s 100+ technical experts operate at the intersection of the three safeguard categories — providing the technical audit and monitoring depth of our SENTRY Managed Detection and Response program, the physical access control assessments of our CITADEL practice, and the advisory governance structures of our VERITY vCISO offering.
The result is a Security Rule compliance program that does not go stale between annual reviews. Your risk assessment drives prioritization, your breach notification readiness is tested proactively, and your readiness for the 2025 proposed updates is built in from the start.
877-890-5508 · [email protected]
FAQ
Frequently Asked Questions
What is the difference between Required and Addressable specifications in the HIPAA Security Rule?
Required specifications must be implemented exactly as stated with no alternative. Addressable specifications require a documented assessment of whether the specification is reasonable and appropriate for the organization. If it is, it must be implemented. If an equivalent alternative better serves the same security objective for that specific organization, the alternative may be used — but the analysis and rationale must be documented in writing. Addressable does not mean optional.
What are the three categories of HIPAA Security Rule safeguards?
The HIPAA Security Rule organizes all requirements into Administrative Safeguards (45 CFR §164.308), Physical Safeguards (45 CFR §164.310), and Technical Safeguards (45 CFR §164.312). Administrative safeguards govern policies and workforce management. Physical safeguards govern facility access and device controls. Technical safeguards govern access control, audit logging, authentication, and transmission security.
How long must HIPAA Security Rule documentation be retained?
Under 45 CFR §164.316(b)(2), written policies, procedures, actions, activities, and assessments required by the Security Rule must be retained for six years from the date of creation or the date they were last in effect, whichever is later. This retention requirement applies to risk assessments, risk management plans, training records, and all policy documents.
Does the HIPAA Security Rule require encryption?
Encryption is an Addressable specification under both the Access Control standard (encryption and decryption of ePHI at rest) and the Transmission Security standard (encryption of ePHI in transit). This means each covered entity must document whether encryption is reasonable and appropriate for its environment. In practice, OCR consistently treats unencrypted ePHI on portable devices and unencrypted transmissions as high-risk findings. The proposed 2025 Security Rule update would elevate encryption requirements significantly.
Keep Reading
Related Resources
HIPAA Compliance
The full HIPAA compliance pillar page.
HIPAA Risk Assessment
What the required risk analysis actually covers.
HIPAA Breach Notification
Timelines and obligations under the Breach Notification Rule.
Compliance Frameworks Hub
Every regulatory framework Armorstack covers.
CMMC Compliance
The defense-industrial-base compliance framework.
Start a 90-Day Proof
Establish your compliance baseline with no long-term commitment.