The Security Rule in plain English

Every section of the Security Rule, 164.302 through 164.316, translated line by line into language you will actually read, with the same structure as the official text and nothing legally lost.

Last verified: 2026-07-12

This is a plain-language translation of the HIPAA Security Rule, keeping the same section headings and outline structure as the official text with simplified wording. It is a study aid, not the law itself; for the exact binding language, use the linked eCFR text, which is the authority everywhere this page and the regulation could be read differently.

Two flags before anything else. Required means you must do it. Addressable does NOT mean optional; it means assess it, then either do it, do an equivalent, or document why it is not reasonable for you. The full explanation lives here.

164.306 Security standards: general rules

(a) What you must accomplish. Every covered entity and business associate must do four things:

“Addressable does NOT mean optional; it means assess it, then either do it, do an equivalent, or document why it is not reasonable for you.”

  1. Ensure the confidentiality, integrity, and availability of all the ePHI it creates, receives, maintains, or transmits;
  2. Protect against reasonably anticipated threats or hazards to that information’s security or integrity;
  3. Protect against reasonably anticipated uses or disclosures that the Privacy Rule does not permit; and
  4. Ensure its workforce complies with this rule.

(b) Flexibility of approach.

  1. You may use any security measures that let you reasonably and appropriately implement the standards. The rule names no products and mandates no technologies.
  2. In deciding what is reasonable and appropriate, you must take into account: (i) your size, complexity, and capabilities; (ii) your technical infrastructure, hardware, and software security capabilities; (iii) the costs of security measures; and (iv) the probability and criticality of the potential risks to your ePHI.

(c) Standards. You must comply with the standards in this rule with respect to all the ePHI you handle.

(d) Implementation specifications. Each specification under a standard is labelled required or addressable.

  1. Required: implement it.
  2. Addressable: (i) assess whether the specification is a reasonable and appropriate safeguard in your environment, judged by how much it would contribute to protecting your ePHI; then (ii) either implement it, or, if it is not reasonable and appropriate for you, document why not and implement an equivalent alternative measure if one is reasonable and appropriate.

(e) Maintenance. Security is not a one-time event. You must review your security measures and modify them as needed to keep protection of ePHI reasonable and appropriate, and update your documentation to match.

164.308 Administrative safeguards

(a)(1) Security management process (Standard). Put policies and procedures in place to prevent, detect, contain, and fix security violations. Its implementation specifications:

  • Risk analysis (Required). Thoroughly and accurately assess the risks and vulnerabilities to the confidentiality, integrity, and availability of the ePHI you hold.
  • Risk management (Required). Put in security measures that reduce those risks to a reasonable, appropriate level.
  • Sanction policy (Required). Discipline workforce members who do not follow your security policies and procedures.
  • Information system activity review (Required). Regularly review records of system activity: audit logs, access reports, and incident tracking reports.

(a)(2) Assigned security responsibility (Standard). Name one security official responsible for developing and running these policies and procedures.

(a)(3) Workforce security (Standard). Have policies and procedures so the right workforce members get appropriate access to ePHI, and those who should not have access cannot get it.

  • Authorization and/or supervision (Addressable). Procedures to authorize and supervise workforce members who work with ePHI or in places where it can be reached.
  • Workforce clearance procedure (Addressable). Procedures to confirm each workforce member’s access is appropriate for their role.
  • Termination procedures (Addressable). Procedures to cut off ePHI access when someone leaves or changes roles.

(a)(4) Information access management (Standard). Have policies and procedures for authorizing access to ePHI, consistent with the Privacy Rule.

  • Isolating health care clearinghouse functions (Required). If a clearinghouse is part of a larger organization, wall off its ePHI from the rest of the organization.
  • Access authorization (Addressable). Policies for granting access, for example to a workstation, transaction, program, or process.
  • Access establishment and modification (Addressable). Policies to set up, document, review, and change each user’s access rights.

(a)(5) Security awareness and training (Standard). Run a security awareness and training program for the whole workforce, including management.

  • Security reminders (Addressable). Periodic security updates.
  • Protection from malicious software (Addressable). Procedures to guard against, detect, and report malware.
  • Log-in monitoring (Addressable). Procedures to watch log-in attempts and report anything off.
  • Password management (Addressable). Procedures to create, change, and safeguard passwords.

(a)(6) Security incident procedures (Standard). Have policies and procedures to handle security incidents.

  • Response and reporting (Required). Identify and respond to suspected or known incidents, limit the harm as much as practicable, and document the incidents and their outcomes.

(a)(7) Contingency plan (Standard). Have policies and procedures for emergencies (fire, vandalism, system failure, natural disaster) that damage systems holding ePHI.

  • Data backup plan (Required). Procedures to create and keep retrievable exact copies of ePHI.
  • Disaster recovery plan (Required). Procedures to restore any lost data.
  • Emergency mode operation plan (Required). Procedures to keep critical business processes running, while protecting ePHI, during an emergency.
  • Testing and revision procedures (Addressable). Periodically test and update your contingency plans.
  • Applications and data criticality analysis (Addressable). Assess how critical specific applications and data are to your operations.

(a)(8) Evaluation (Standard). Periodically evaluate, technically and nontechnically, whether your security measures still meet this rule, especially after environmental or operational changes.

(b) Business associate contracts and other arrangements. You may let a business associate create, receive, maintain, or transmit ePHI on your behalf only if you get satisfactory assurances, per 164.314(a), that it will safeguard the information. A business associate must get the same assurances from its subcontractors. Written contract or other arrangement (Required): put those assurances in a written contract or arrangement that meets 164.314(a).

164.310 Physical safeguards

(a)(1) Facility access controls (Standard). Limit physical access to your systems and the facilities that house them, while still allowing properly authorized access.

  • Contingency operations (Addressable). Procedures allowing facility access to support data restoration during an emergency, under your disaster recovery and emergency mode plans.
  • Facility security plan (Addressable). Policies to protect the facility and its equipment from unauthorized access, tampering, and theft.
  • Access control and validation procedures (Addressable). Procedures to control and verify people’s facility access by role, including visitor control and access to software programs for testing and revision.
  • Maintenance records (Addressable). Document repairs and modifications to security-related physical parts of the facility: hardware, walls, doors, locks.

(b) Workstation use (Standard). Have policies specifying what functions are performed at a workstation, how they are performed, and the physical surroundings of any workstation or class of workstation that can access ePHI.

(c) Workstation security (Standard). Put physical safeguards on all workstations that access ePHI so only authorized users can use them.

(d)(1) Device and media controls (Standard). Have policies governing how hardware and electronic media holding ePHI move into, out of, and within your facility.

  • Disposal (Required). Policies for the final disposition of ePHI and the hardware or media it is stored on.
  • Media re-use (Required). Procedures to remove ePHI from media before the media are reused.
  • Accountability (Addressable). Keep a record of the movements of hardware and media and the person responsible for them.
  • Data backup and storage (Addressable). Create a retrievable exact copy of ePHI before moving equipment, when needed.

164.312 Technical safeguards

(a)(1) Access control (Standard). Use technical policies and procedures so only the persons or software programs granted rights under 164.308(a)(4) can reach systems holding ePHI.

  • Unique user identification (Required). Give each user a unique name and/or number for identifying and tracking their identity.
  • Emergency access procedure (Required). Procedures for obtaining necessary ePHI during an emergency.
  • Automatic logoff (Addressable). Electronic procedures that end a session after a set period of inactivity.
  • Encryption and decryption (Addressable). A mechanism to encrypt and decrypt ePHI.

(b) Audit controls (Standard). Use hardware, software, and/or procedural mechanisms that record and examine activity in systems that contain or use ePHI.

(c)(1) Integrity (Standard). Have policies and procedures to protect ePHI from improper alteration or destruction.

  • Mechanism to authenticate ePHI (Addressable). Electronic ways to confirm ePHI has not been altered or destroyed in an unauthorized manner.

(d) Person or entity authentication (Standard). Have procedures to verify that a person or entity seeking access to ePHI is who they claim to be.

(e)(1) Transmission security (Standard). Use technical security measures to guard ePHI against unauthorized access while it travels over an electronic communications network.

  • Integrity controls (Addressable). Measures to ensure transmitted ePHI is not improperly modified without detection until disposed of.
  • Encryption (Addressable). A mechanism to encrypt ePHI whenever deemed appropriate.

164.314 Organizational requirements

(a) Business associate contracts or other arrangements (Standard). The contract required by 164.308(b)(3) must meet the applicable requirements below (all Required):

  • Business associate contracts. The contract must require the business associate to: (A) comply with this rule’s applicable requirements; (B) ensure any subcontractors that handle its ePHI agree, through a compliant contract, to the same requirements; and (C) report to the covered entity any security incident it becomes aware of, including breaches of unsecured PHI per 164.410.
  • Other arrangements. A covered entity is compliant if it has another arrangement that meets 164.504(e)(3), which covers certain government and legally mandated situations.
  • Subcontractor contracts. The same requirements apply between a business associate and its subcontractor as between a covered entity and its business associate.

(b) Requirements for group health plans (Standard). Unless the only ePHI shared with a plan sponsor is the limited kind allowed by 164.504(f)(1)(ii) or (iii), or is authorized under 164.508, a group health plan must make its plan documents require the sponsor to reasonably safeguard the ePHI: implement reasonable administrative, physical, and technical safeguards; back the required separation between plan and employer with security measures; make its agents agree to the same; and report security incidents to the plan (all Required).

164.316 Policies, procedures, and documentation

(a) Policies and procedures (Standard). Implement reasonable and appropriate policies and procedures to comply with this rule, taking the 164.306(b)(2) factors into account. This never excuses violating another requirement. You may change your policies and procedures at any time, as long as you document the changes and implement them properly.

(b)(1) Documentation (Standard). Keep your policies and procedures in written form, which may be electronic; and whenever this rule requires an action, activity, or assessment to be documented, keep a written or electronic record of it.

  • Time limit (Required). Keep that documentation for 6 years from when it was created or when it was last in effect, whichever is later.
  • Availability (Required). Make the documentation available to the people responsible for carrying out the procedures it covers.
  • Updates (Required). Review the documentation periodically and update it as needed in response to environmental or operational changes affecting the security of your ePHI.

The short version

  • This is the full Security Rule, 164.306 through 164.316, translated section by section with the legal meaning preserved.
  • 164.306 is the engine: four duties, four flexibility factors, and the definition of required versus addressable.
  • The eCFR text linked in the sources is the authority anywhere this translation could be read differently.
  • Documentation requirements at 164.316 apply to everything: written, retained six years, reviewed and updated.

This article is educational information about the HIPAA regulations, not legal advice. It describes what the rules say; it does not tell you what to do about your specific situation, and reading it does not create an attorney-client or consultant-client relationship. Regulations change, and enforcement positions change with them. For advice on your clinic, talk to a qualified professional.

Sources

Read it here. Run it for real.

This page makes the rule readable. WiseUpHIPAA makes it operational: every requirement below mapped to your clinic's actual state, honestly, including the parts that are not done yet.