HIPAA Security Rule Requirements: Complete Technical Safeguards Guide

The HIPAA Security Rule governs electronic protected health information (ePHI) specifically, and it is built around three categories of safeguards: administrative, physical, and technical. What trips most organizations up is not the list of controls but the structure. Every standard is either required or addressable, and addressable does not mean optional. Understanding that distinction is the key to reading the Security Rule correctly.

The three safeguard categories

Technical safeguards in detail

Access control means unique user identification, emergency access procedures, automatic logoff, and encryption or decryption of ePHI. Audit controls require mechanisms to record and examine system activity. Integrity controls protect ePHI from improper alteration or destruction. Person-or-entity authentication verifies that users are who they claim to be, increasingly through multi-factor authentication. Transmission security protects ePHI moving across networks, typically through TLS and end-to-end encryption.

Required vs. addressable

Required specifications must be implemented as written. Addressable specifications must be assessed: you implement them, implement an equivalent alternative, or document a reasonable justification for doing neither. Addressable is frequently misread as ignore — a mistake OCR routinely cites in enforcement actions. Our HIPAA access control best practices guide walks through one of the most-cited technical standards in depth.

It all starts with the risk analysis

Every Security Rule obligation flows from one required administrative safeguard: the Security Risk Analysis under 45 CFR § 164.308(a)(1)(ii)(A). The SRA identifies where ePHI exists and the risks to it, and it is the document that tells you which addressable items you can justify and which you cannot.

The 2026 update would reshape this

In December 2024, HHS published an NPRM proposing significant Security Rule changes. It is not final and would carry a 240-day compliance window once published. Most notably, it proposes removing the addressable category — making specifications like encryption and MFA effectively mandatory — and adding requirements such as asset inventories, network segmentation, and regular technical testing.

How Medcurity helps

Medcurity maps your environment against every Security Rule standard, separates required from addressable, and documents your justification for each addressable decision so you have defensible evidence if OCR ever asks. The platform is $499/year (about $42/month); larger organizations can request a quote. Use our HIPAA compliance checklist alongside it to track implementation.

Frequently Asked Questions

Does the Security Rule cover paper records?

No. The Security Rule applies only to ePHI. Paper PHI is covered by the HIPAA Privacy Rule. The two rules work together but address different media.

What is the difference between required and addressable?

Required specifications must be implemented exactly as written. Addressable specifications must be implemented, replaced with an equivalent measure, or formally justified as unnecessary — never simply skipped.

Is multi-factor authentication required today?

Not explicitly under the current rule, but it falls under the authentication standard and is widely expected. The 2026 NPRM would make MFA an explicit requirement for most systems.

How do we prove we meet the Security Rule?

With documentation: a current Security Risk Analysis, written policies, evidence of implemented controls, and records of your addressable decisions. OCR investigations are essentially documentation tests.