{"@context":"https://schema.org","@type":"Article","headline":"HIPAA Security Rule","description":"Learn how ABA practices scope ePHI, assess security risk, implement administrative, physical, and technical safeguards, govern vendors, and test controls.","url":"https://finnihealth.com/resources/glossary/hipaa-security-rule","datePublished":"2026-08-14T00:00:00.000Z","dateModified":"2026-08-14T00:00:00.000Z","author":{"@type":"Organization","name":"Finni Health Editorial Team"},"publisher":{"@type":"Organization","name":"Finni Health","url":"https://www.finnihealth.com"},"isPartOf":{"@type":"CollectionPage","name":"ABA and Practice Operations Glossary","url":"https://www.finnihealth.com/resources/glossary"},"breadcrumb":{"@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Resources","item":"https://www.finnihealth.com/resources"},{"@type":"ListItem","position":2,"name":"Glossary","item":"https://www.finnihealth.com/resources/glossary"},{"@type":"ListItem","position":3,"name":"HIPAA Security Rule","item":"https://finnihealth.com/resources/glossary/hipaa-security-rule"}]}}
Glossary term

HIPAA Security Rule

Learn how ABA practices scope ePHI, assess security risk, implement administrative, physical, and technical safeguards, govern vendors, and test controls.

7
min read
Updated
August 13, 2026
Sources checked
August 13, 2026
ยท View sources
Also called

HIPAA security standards Security Rule

What is HIPAA Security Rule, and what should an ABA practice owner know before applying it? The HIPAA Security Rule requires covered entities and business associates to protect ePHI through reasonable and appropriate administrative, physical, and technical safeguards. An ABA owner should confirm regulated-entity status, map all ePHI, assess risk, assign security responsibility, document control choices, govern business associates, and test incident and continuity procedures under the current rule.

Editorial approval scope: The team checked current source fidelity, scope boundaries, dates, arithmetic, reader usefulness, practical workflow, and general-information limitations.

The rule protects ePHI in regulated hands

The HHS Security Rule page says the rule establishes national standards for electronic protected health information created, received, used, or maintained by a covered entity or business associate.

The rule covers health plans, clearinghouses, and health care providers that conduct specified HIPAA transactions electronically, plus their business associates. It protects PHI maintained or transmitted electronically. Paper-only and verbal PHI fall outside this rule's ePHI scope, although Privacy Rule and other safeguards can still apply.

For an ABA practice, ePHI can appear in clinical records, scheduling, billing, claim attachments, email, texting, portals, recordings, spreadsheets, analytics, backups, devices, interfaces, support tools, and vendor systems. A data map should record where it comes from, why it is used, who can access it, where it moves, where it is retained, and how it is deleted.

The 2025 proposal has not replaced the current rule

HHS's history page, reviewed in March 2026, still identifies the January 2025 action as proposed. The currently effective Security Rule remains the compliance baseline. The NPRM would make implementation specifications required with limited exceptions and add detailed mandates for items such as inventories, network maps, encryption, multifactor authentication, annual audits, vulnerability scanning, and penetration testing. Those proposals can guide readiness planning while HHS completes rulemaking.

Safeguards protect confidentiality, integrity, and availability

45 CFR 164.306 requires regulated entities to ensure the confidentiality, integrity, and availability of all ePHI they create, receive, maintain, or transmit; protect against reasonably anticipated threats, hazards, and impermissible uses or disclosures; and ensure workforce compliance.

HHS's current Security Rule summary explains that the rule is scalable and technology neutral. It lets an entity choose reasonable and appropriate measures after considering size, complexity, capabilities, infrastructure, cost, and risk. That flexibility does not remove a standard.

Rule areaOperational focus for an ABA practice
Administrative, 45 CFR 164.308Risk analysis and management, assigned security responsibility, workforce controls, access management, awareness, incident procedures, contingency planning, evaluation, and business-associate arrangements
Physical, 45 CFR 164.310Facility access, workstation use and security, and device or media receipt, movement, reuse, and disposal
Technical, 45 CFR 164.312Access control, audit controls, integrity, person or entity authentication, and transmission security
Organizational, 45 CFR 164.314Business-associate contracts or other arrangements and certain group-health-plan requirements
Policy and documentation, 45 CFR 164.316Written policies, updates after environmental or operational change, and required documentation retention

Security Rule documentation described in section 164.316 must be retained for six years from creation or the date last in effect, whichever is later. That period does not automatically govern every medical record or raw operational log; map each record type to its own source.

Risk analysis covers every ePHI location

HHS risk-analysis guidance calls risk analysis foundational and ongoing. Its scope includes potential risks and vulnerabilities to all ePHI the organization creates, receives, maintains, or transmits, including vendor-held and remote data.

Risk analysis identifies and evaluates risks. Risk management under 45 CFR 164.308 requires security measures sufficient to reduce them to a reasonable and appropriate level. An inventory or risk register alone does not complete that work.

Maintain a versioned inventory of systems, data flows, devices, sites, interfaces, vendors, and workforce roles. For each, identify threats, vulnerabilities, existing safeguards, likelihood, impact, risk level, treatment, owner, due date, evidence, residual risk, and review trigger. A penetration test, questionnaire, certification, or vendor report can inform this process. None supplies a complete practice risk analysis by itself.

Update the analysis after material changes such as a new center, acquisition, telehealth model, device fleet, interface, vendor, record type, remote-work design, or security incident. Connect identified risks to a tracked risk-management decision and validation test.

Addressable does not mean optional

Every applicable Security Rule standard must be met. Some implementation specifications are required and must be implemented. For an addressable specification, the entity evaluates whether it is reasonable and appropriate in its environment.

The HHS required-versus-addressable FAQ explains the possible paths: implement the specification; document why it is unreasonable or inappropriate and use an equivalent alternative when reasonable and appropriate; or document why neither measure is reasonable and appropriate when the standard can otherwise be met. Cost is one factor, not a standalone waiver.

Under the current rule, unique user identification is required under the access-control standard. Automatic logoff and encryption are addressable under specified provisions. The practice should record the applicable standard, risk evidence, decision, configuration, test, exception, approver, and review date instead of treating a product checkbox as proof of compliance.

Business associates retain their own duties

When a vendor creates, receives, maintains, or transmits ePHI, determine whether the relationship makes it a business associate or business-associate subcontractor. If it does, the responsible regulated party must have the written contract or other arrangement required by 45 CFR 164.314 before permitting that activity. A covered entity contracts with its business associate; that business associate contracts with its qualifying subcontractor. Each remains directly responsible for its applicable Security Rule duties.

Record data scope, hosting, encryption, keys, identities, logs, backups, recovery, incident routing, subservice providers, exit controls, and validation evidence. Contract notice periods should support the practice's legal clocks. Security incidents and HIPAA breaches are classified under separate rule definitions.

A fictional control review exposes gaps

A fictional ABA practice inventories 24 systems and vendors. Twenty create, receive, maintain, or transmit ePHI; four have a source-supported no-ePHI determination. Those 20 form the risk-analysis cohort.

Seventeen of the 20 have a current owner, risk decision, control evidence, and review date, so complete control-record coverage is 17 of 20, or 85%. The three gaps remain open: an intake form lacks a data-flow owner, a messaging vendor's agreement has expired and its connection is suspended, and one backup has no completed restore test.

Six approved restore tests are due during the quarter. All six are attempted, and five meet the recovery criteria: 5 of 6, or 83.3%. One failed restore remains in the denominator and corrective-action queue. A skipped test would remain in that denominator too. These measures describe evidence coverage and test results. They do not establish overall compliance or security.

Measure control evidence and correction

Useful measures include ePHI systems with current risk decisions divided by ePHI systems in scope; required control tests passed divided by tests due; addressable specifications with current written decisions divided by specifications due; high-risk actions closed by target divided by high-risk actions due; and access removals completed by their governing deadline divided by removals due.

Report open risks by age and severity, backup and recovery results, incident response, vendor exceptions, overdue access reviews, and corrective-action validation. Define the inventory version, source, owner, test, acceptance rule, period, exclusions, numerator, and denominator before interpreting a percentage.

Related terms

Sources

Beyond the glossary

Take the next step with clarity

Whether you are finding care, growing as a clinician, or building a stronger ABA practice, Finni brings the people, tools, and support together to help you move forward.

Start or grow your ABA practice with Finni