Compliance Framework Alignment
HIPAA Security Rule — 45 CFR Part 164 Subpart C Administrative safeguards — 45 CFR §164.308 Physical safeguards — 45 CFR §164.310 Technical safeguards — 45 CFR §164.312 Documentation — 45 CFR §164.316 This document is a configurable template to help organisations structure a HIPAA Security Rule programme. It is not legal or compliance advice, and it does not itself establish compliance. Citations reflect 45 CFR Part 164 Subpart C as amended by the 2013 Omnibus Rule (78 FR 5566). Where relevant, it flags the OCR Notice of Proposed Rulemaking published 6 January 2025 (90 FR 898); until any final rule takes effect the current Security Rule governs. Review with qualified counsel and a security professional before adoption.
ACME HEALTH INC HIPAA SECURITY RULE POLICY
Regulated role covered entity
Effective Date [Effective Date]
Next Review [Review Date]
Security Official Dana Ruiz
Framework 45 CFR Part 164 Subpart C (§164.302–164.318) 1. Purpose and Scope
This policy establishes how Acme Health Inc (the "Organisation"), acting as a covered entity, protects the confidentiality, integrity, and availability of all electronic protected health information ("ePHI") that it creates, receives, maintains, or transmits, in accordance with the HIPAA Security Rule at 45 CFR Part 164 Subpart C. It applies to every member of the workforce — employees, contractors, volunteers, and trainees — and to all information systems, applications, networks, devices, and physical locations that store, process, or move ePHI, whether owned by the Organisation or by a third party acting on its behalf. It complements, and does not replace, the Organisation's obligations under the HIPAA Privacy Rule (45 CFR Part 164 Subpart E) and the Breach Notification Rule (Subpart D).
2. General Requirements and the Flexible Approach
Under 45 CFR §164.306(a), the Organisation will ensure the confidentiality, integrity, and availability of all ePHI it handles; protect against reasonably anticipated threats and hazards; protect against reasonably anticipated impermissible uses or disclosures; and ensure workforce compliance. Consistent with the flexibility principle in §164.306(b), the Organisation selects reasonable and appropriate security measures having regard to its size, complexity, and capabilities; its technical infrastructure; the cost of measures; and the probability and criticality of potential risks to ePHI. Each standard in Subpart C carries one or more implementation specifications marked "Required" or "Addressable" (§164.306(d)). Required specifications must be implemented. For an Addressable specification the Organisation will assess whether it is reasonable and appropriate and then implement it, adopt an equivalent alternative measure, or, where neither is reasonable and appropriate, document that determination and the rationale. Note that the OCR NPRM of 6 January 2025 (90 FR 898) proposes to remove the Required/Addressable distinction and make most specifications mandatory; the Organisation monitors this rulemaking and will realign upon any final rule.
3. Assigned Security Responsibility
In satisfaction of 45 CFR §164.308(a)(2) (Required), the Organisation designates a single Security Official who is responsible for developing, implementing, and maintaining this policy and the security measures it describes. The current Security Official is Dana Ruiz (security@acmehealth.example ). Where the Privacy and Security roles are held by different individuals, the Privacy Officer is Privacy Officer (name, if separate) , and both officials coordinate on incidents, workforce sanctions, and business associate arrangements. The Security Official reports security posture and material risks to senior management on a regular cadence.
4. Security Management Process — Risk Analysis and Risk Management
Under the Security Management Process standard (45 CFR §164.308(a)(1)), the Organisation implements the following required specifications. Risk Analysis (§164.308(a)(1)(ii)(A), Required): the Organisation conducts an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of all ePHI, covering every system and location where ePHI resides. The most recent risk analysis was completed on [not yet recorded] and is repeated periodically and whenever significant changes occur. Risk Management (§164.308(a)(1)(ii)(B), Required): the Organisation implements security measures sufficient to reduce identified risks and vulnerabilities to a reasonable and appropriate level in line with §164.306(a). Sanction Policy (§164.308(a)(1)(ii)(C), Required): workforce members who fail to comply with security policies are subject to graduated disciplinary action. Information System Activity Review (§164.308(a)(1)(ii)(D), Required): the Organisation regularly reviews records of information system activity, including audit logs, access reports, and security incident tracking reports.
5. Workforce Security, Access Management, Awareness, and Incidents
Workforce Security (45 CFR §164.308(a)(3)) ensures that only appropriately authorised workforce members can access ePHI, through authorisation and/or supervision (Addressable), workforce clearance procedures (Addressable), and termination procedures that revoke access promptly on separation (Addressable). Information Access Management (§164.308(a)(4)) governs authorising access to ePHI consistent with the Privacy Rule's minimum-necessary principle, including access authorisation, and access establishment and modification (both Addressable); where the Organisation is a clearinghouse within a larger entity, isolation of clearinghouse functions is Required. Security Awareness and Training (§164.308(a)(5)) provides periodic security reminders, protection from malicious software, log-in monitoring, and password management (all Addressable) to the entire workforce, including management. Security Incident Procedures (§164.308(a)(6)) require the Organisation to identify and respond to suspected or known security incidents, mitigate their harmful effects, and document incidents and outcomes (Response and Reporting, Required).
6. Contingency Planning and Evaluation
The Contingency Plan standard (45 CFR §164.308(a)(7)) requires policies and procedures for responding to emergencies or other occurrences — such as fire, vandalism, system failure, or natural disaster — that damage systems containing ePHI. It comprises a Data Backup Plan (Required), a Disaster Recovery Plan (Required), and an Emergency Mode Operation Plan (Required) to sustain critical processes while operating in emergency mode, together with Testing and Revision Procedures and Applications and Data Criticality Analysis (both Addressable). The Evaluation standard (§164.308(a)(8), Required) obliges the Organisation to perform periodic technical and non-technical evaluations — initially against the Security Rule standards and thereafter in response to environmental or operational changes affecting the security of ePHI — to confirm that this policy continues to meet the requirements of Subpart C.
7. Business Associate Contracts and Other Arrangements
Under 45 CFR §164.308(b)(1) the Organisation permits a business associate to create, receive, maintain, or transmit ePHI on its behalf only where it has obtained satisfactory written assurances, through a compliant business associate agreement, that the business associate will appropriately safeguard the information (Written Contract or Other Arrangement, §164.308(b)(3), Required). Since the 2013 Omnibus Rule (78 FR 5566) business associates and their subcontractors are directly liable for compliance with the applicable Security Rule provisions. The Organisation maintains an inventory of business associates, tracks agreement status, and, where it is itself a business associate, flows equivalent obligations down to any subcontractor.
8. Physical Safeguards — Facility and Workstations
Facility Access Controls (45 CFR §164.310(a)(1)) limit physical access to electronic information systems and the facilities in which they are housed while ensuring properly authorised access is allowed, through Contingency Operations, a Facility Security Plan, Access Control and Validation Procedures, and Maintenance Records (all Addressable). Workstation Use (§164.310(b), Required) specifies the proper functions to be performed at workstations that access ePHI, the manner of performance, and the physical attributes of their surroundings. Workstation Security (§164.310(c), Required) implements physical safeguards for all such workstations to restrict access to authorised users. The Organisation positions screens away from public view, enforces clear-desk and lock-on-leave practices, and controls access to server rooms and wiring closets.
9. Physical Safeguards — Device and Media Controls
Device and Media Controls (45 CFR §164.310(d)(1)) govern the receipt and removal of hardware and electronic media that contain ePHI into, out of, and within a facility. The Organisation implements Disposal (Required) and Media Re-use (Required) so that ePHI is rendered irretrievable before disposal or reissue of any device or medium, and adopts Accountability (Addressable) — maintaining a record of the movement of hardware and media and the person responsible — and Data Backup and Storage (Addressable) — creating a retrievable, exact copy of ePHI before equipment is moved. Portable devices and removable media that hold ePHI are encrypted to AES-256 at rest; TLS 1.2+ in transit .
10. Technical Safeguards — Access Control and Audit Controls
Access Control (45 CFR §164.312(a)(1)) permits access to ePHI only to authorised persons or software. The Organisation implements Unique User Identification (§164.312(a)(2)(i), Required) and Emergency Access Procedure (§164.312(a)(2)(ii), Required), and addresses Automatic Logoff (§164.312(a)(2)(iii)) and Encryption and Decryption (§164.312(a)(2)(iv)), both Addressable. As an addressable measure the Organisation encrypts ePHI at rest using AES-256 at rest; TLS 1.2+ in transit . Audit Controls (§164.312(b), Required) require hardware, software, and/or procedural mechanisms that record and examine activity in information systems containing or using ePHI; the Organisation retains and periodically reviews these logs. The Organisation notes that the OCR NPRM of 6 January 2025 proposes to make encryption of ePHI and multi-factor authentication mandatory, subject to limited exceptions, and is aligning its roadmap accordingly.
11. Technical Safeguards — Integrity, Authentication, and Transmission Security
Integrity (45 CFR §164.312(c)(1)) protects ePHI from improper alteration or destruction; the Organisation addresses the Mechanism to Authenticate ePHI (§164.312(c)(2), Addressable) using checksums, hashing, or equivalent controls. Person or Entity Authentication (§164.312(d), Required) verifies that a person or entity seeking access is the one claimed, through strong credentials and, where reasonable and appropriate, multi-factor authentication. Transmission Security (§164.312(e)(1)) guards against unauthorised access to ePHI transmitted over an electronic network; the Organisation implements Integrity Controls (§164.312(e)(2)(i), Addressable) and Encryption (§164.312(e)(2)(ii), Addressable). As an addressable measure the Organisation encrypts ePHI in transit using AES-256 at rest; TLS 1.2+ in transit .
12. Summary of Safeguard Families
The table below summarises the principal standards of the Security Rule addressed by this policy and the marking of their implementation specifications. "R" denotes a Required specification and "A" an Addressable one; several standards contain a mix of both.
Safeguard family Key standard (45 CFR) Representative specifications R / A Administrative §164.308(a)(1) Security Management Process Risk Analysis; Risk Management; Sanction Policy; Activity Review R Administrative §164.308(a)(5) Security Awareness & Training Reminders; anti-malware; log-in monitoring; passwords A Administrative §164.308(a)(7) Contingency Plan Data backup; disaster recovery; emergency mode R + A Physical §164.310(a)(1) Facility Access Controls Facility security plan; access validation; maintenance records A Physical §164.310(d)(1) Device & Media Controls Disposal; media re-use; accountability; data backup R + A Technical §164.312(a)(1) Access Control Unique user ID; emergency access; auto logoff; encryption R + A Technical §164.312(b) Audit Controls Record and examine information system activity R Technical §164.312(e)(1) Transmission Security Integrity controls; encryption in transit A
13. Documentation, Retention, and Availability
In accordance with 45 CFR §164.316, the Organisation maintains this policy and its supporting procedures in written (which may be electronic) form, together with a written record of any action, activity, or assessment required to be documented under Subpart C. Under the Time Limit specification (§164.316(b)(2)(i)) documentation is retained for six years from the date of its creation or the date when it was last in effect, whichever is later. Under Availability (§164.316(b)(2)(ii)) documentation is made available to those persons responsible for implementing the procedures to which it pertains, and under Updates (§164.316(b)(2)(iii)) it is reviewed periodically and updated in response to environmental or operational changes affecting the security of ePHI. This policy will next be reviewed on [Review Date].
14. Enforcement, Breach Interaction, and Governing Law
This policy is enforced through the sanction process at §164.308(a)(1)(ii)(C); violations may result in disciplinary action up to and including termination, and, for third parties, contractual and legal remedies. A security incident involving unsecured ePHI is additionally evaluated under the Breach Notification Rule (45 CFR Part 164 Subpart D). This policy is governed by the HIPAA Security Rule and the enforcement provisions of 45 CFR Part 160, together with any more stringent or applicable law of California that is not preempted under 45 CFR §160.203. The Organisation cooperates with the HHS Office for Civil Rights in any compliance review or investigation.
Approved by
Policy owner / approver (name)
______________________
Security Official
Dana Ruiz
______________________