Skip to main content
Compliance & Legal

HIPAA Security Rule

Also known as: Security Rule

The HIPAA rule that sets administrative, physical, and technical safeguards for ePHI.

The HIPAA Security Rule sets the standards for protecting electronic protected health information (ePHI). It organizes protections into three categories: administrative safeguards (policies, training, risk analysis), physical safeguards (facility and device controls), and technical safeguards (encryption, access controls, audit logging, automatic logoff).

For a plain-language breakdown of each layer, see HIPAA safeguards explained.

Share this definition with your team

View link to copy manually

Stay current on HIPAA hosting

Practical guidance on compliance, hosting and the rules that actually apply to your practice.