What is HIPAA Security Rule, and what should an ABA practice owner know before applying it? The HIPAA Security Rule requires covered entities and business associates to protect ePHI through reasonable and appropriate administrative, physical, and technical safeguards. An ABA owner should confirm regulated-entity status, map all ePHI, assess risk, assign security responsibility, document control choices, govern business associates, and test incident and continuity procedures under the current rule.
Editorial approval scope: The team checked current source fidelity, scope boundaries, dates, arithmetic, reader usefulness, practical workflow, and general-information limitations.
The rule protects ePHI in regulated hands
The HHS Security Rule page says the rule establishes national standards for electronic protected health information created, received, used, or maintained by a covered entity or business associate.
The rule covers health plans, clearinghouses, and health care providers that conduct specified HIPAA transactions electronically, plus their business associates. It protects PHI maintained or transmitted electronically. Paper-only and verbal PHI fall outside this rule's ePHI scope, although Privacy Rule and other safeguards can still apply.
For an ABA practice, ePHI can appear in clinical records, scheduling, billing, claim attachments, email, texting, portals, recordings, spreadsheets, analytics, backups, devices, interfaces, support tools, and vendor systems. A data map should record where it comes from, why it is used, who can access it, where it moves, where it is retained, and how it is deleted.
The 2025 proposal has not replaced the current rule
HHS's history page, reviewed in March 2026, still identifies the January 2025 action as proposed. The currently effective Security Rule remains the compliance baseline. The NPRM would make implementation specifications required with limited exceptions and add detailed mandates for items such as inventories, network maps, encryption, multifactor authentication, annual audits, vulnerability scanning, and penetration testing. Those proposals can guide readiness planning while HHS completes rulemaking.
Safeguards protect confidentiality, integrity, and availability
45 CFR 164.306 requires regulated entities to ensure the confidentiality, integrity, and availability of all ePHI they create, receive, maintain, or transmit; protect against reasonably anticipated threats, hazards, and impermissible uses or disclosures; and ensure workforce compliance.
HHS's current Security Rule summary explains that the rule is scalable and technology neutral. It lets an entity choose reasonable and appropriate measures after considering size, complexity, capabilities, infrastructure, cost, and risk. That flexibility does not remove a standard.
| Rule area | Operational focus for an ABA practice |
|---|---|
| Administrative, 45 CFR 164.308 | Risk analysis and management, assigned security responsibility, workforce controls, access management, awareness, incident procedures, contingency planning, evaluation, and business-associate arrangements |
| Physical, 45 CFR 164.310 | Facility access, workstation use and security, and device or media receipt, movement, reuse, and disposal |
| Technical, 45 CFR 164.312 | Access control, audit controls, integrity, person or entity authentication, and transmission security |
| Organizational, 45 CFR 164.314 | Business-associate contracts or other arrangements and certain group-health-plan requirements |
| Policy and documentation, 45 CFR 164.316 | Written policies, updates after environmental or operational change, and required documentation retention |
Security Rule documentation described in section 164.316 must be retained for six years from creation or the date last in effect, whichever is later. That period does not automatically govern every medical record or raw operational log; map each record type to its own source.
Risk analysis covers every ePHI location
HHS risk-analysis guidance calls risk analysis foundational and ongoing. Its scope includes potential risks and vulnerabilities to all ePHI the organization creates, receives, maintains, or transmits, including vendor-held and remote data.
Risk analysis identifies and evaluates risks. Risk management under 45 CFR 164.308 requires security measures sufficient to reduce them to a reasonable and appropriate level. An inventory or risk register alone does not complete that work.
Maintain a versioned inventory of systems, data flows, devices, sites, interfaces, vendors, and workforce roles. For each, identify threats, vulnerabilities, existing safeguards, likelihood, impact, risk level, treatment, owner, due date, evidence, residual risk, and review trigger. A penetration test, questionnaire, certification, or vendor report can inform this process. None supplies a complete practice risk analysis by itself.
Update the analysis after material changes such as a new center, acquisition, telehealth model, device fleet, interface, vendor, record type, remote-work design, or security incident. Connect identified risks to a tracked risk-management decision and validation test.
Addressable does not mean optional
Every applicable Security Rule standard must be met. Some implementation specifications are required and must be implemented. For an addressable specification, the entity evaluates whether it is reasonable and appropriate in its environment.
The HHS required-versus-addressable FAQ explains the possible paths: implement the specification; document why it is unreasonable or inappropriate and use an equivalent alternative when reasonable and appropriate; or document why neither measure is reasonable and appropriate when the standard can otherwise be met. Cost is one factor, not a standalone waiver.
Under the current rule, unique user identification is required under the access-control standard. Automatic logoff and encryption are addressable under specified provisions. The practice should record the applicable standard, risk evidence, decision, configuration, test, exception, approver, and review date instead of treating a product checkbox as proof of compliance.
Business associates retain their own duties
When a vendor creates, receives, maintains, or transmits ePHI, determine whether the relationship makes it a business associate or business-associate subcontractor. If it does, the responsible regulated party must have the written contract or other arrangement required by 45 CFR 164.314 before permitting that activity. A covered entity contracts with its business associate; that business associate contracts with its qualifying subcontractor. Each remains directly responsible for its applicable Security Rule duties.
Record data scope, hosting, encryption, keys, identities, logs, backups, recovery, incident routing, subservice providers, exit controls, and validation evidence. Contract notice periods should support the practice's legal clocks. Security incidents and HIPAA breaches are classified under separate rule definitions.
A fictional control review exposes gaps
A fictional ABA practice inventories 24 systems and vendors. Twenty create, receive, maintain, or transmit ePHI; four have a source-supported no-ePHI determination. Those 20 form the risk-analysis cohort.
Seventeen of the 20 have a current owner, risk decision, control evidence, and review date, so complete control-record coverage is 17 of 20, or 85%. The three gaps remain open: an intake form lacks a data-flow owner, a messaging vendor's agreement has expired and its connection is suspended, and one backup has no completed restore test.
Six approved restore tests are due during the quarter. All six are attempted, and five meet the recovery criteria: 5 of 6, or 83.3%. One failed restore remains in the denominator and corrective-action queue. A skipped test would remain in that denominator too. These measures describe evidence coverage and test results. They do not establish overall compliance or security.
Measure control evidence and correction
Useful measures include ePHI systems with current risk decisions divided by ePHI systems in scope; required control tests passed divided by tests due; addressable specifications with current written decisions divided by specifications due; high-risk actions closed by target divided by high-risk actions due; and access removals completed by their governing deadline divided by removals due.
Report open risks by age and severity, backup and recovery results, incident response, vendor exceptions, overdue access reviews, and corrective-action validation. Define the inventory version, source, owner, test, acceptance rule, period, exclusions, numerator, and denominator before interpreting a percentage.
Related terms
Sources
- U.S. Department of Health and Human Services, The Security Rule
- U.S. Department of Health and Human Services, Summary of the HIPAA Security Rule
- U.S. Department of Health and Human Services, Guidance on Risk Analysis
- U.S. Department of Health and Human Services, Addressable and Required Implementation Specifications FAQ
- Electronic Code of Federal Regulations, 45 CFR 164.306, Security Standards General Rules
- Electronic Code of Federal Regulations, 45 CFR 164.308, Administrative Safeguards
- Electronic Code of Federal Regulations, 45 CFR 164.310, Physical Safeguards
- Electronic Code of Federal Regulations, 45 CFR 164.312, Technical Safeguards
- Electronic Code of Federal Regulations, 45 CFR 164.314, Organizational Requirements
- Electronic Code of Federal Regulations, 45 CFR 164.316, Policies, Procedures, and Documentation
- U.S. Department of Health and Human Services, HIPAA Security Rule Proposed Rule Fact Sheet
Take the next step with clarity
Whether you are finding care, growing as a clinician, or building a stronger ABA practice, Finni brings the people, tools, and support together to help you move forward.
Start or grow your ABA practice with Finni