Skip to main content
Compliance & Legal

Recognized Security Practices

Also known as: RSPs, Recognized cybersecurity practices

Recognized security practices are NIST, HHS 405(d), and other legally recognized cybersecurity methods that HHS must consider in certain HIPAA fine and audit decisions.

Recognized security practices are cybersecurity standards and methods that HHS must weigh in certain HIPAA enforcement decisions. A 2021 amendment to the HITECH Act created the term. It applies to covered entities and business associates alike. Using them is voluntary, but proof that they were in use can count in an entity's favor.

What counts as a recognized security practice

Under 42 U.S.C. § 17941(b)(1), the term covers practices from three sources:

  • NIST. Practices developed under section 2(c)(15) of the NIST Act (15 U.S.C. § 272(c)(15)). The NIST Cybersecurity Framework is a common example.
  • HHS 405(d). Approaches set out under section 405(d) of the Cybersecurity Act of 2015 (6 U.S.C. § 1533(d)). That program publishes Health Industry Cybersecurity Practices (HICP).
  • Other programs. Cybersecurity programs developed, recognized, or set out in regulations under other federal laws.

Each covered entity or business associate decides which recognized security practices apply to it. That choice must be consistent with the HIPAA Security Rule.

How recognized security practices affect HIPAA enforcement

HHS must consider whether an entity has adequately shown recognized security practices were in place for at least the previous 12 months (§ 17941(a)). Within HHS, the Office for Civil Rights (OCR) enforces the Security Rule. Practices shown to be in place may:

  • Mitigate civil fines under 42 U.S.C. § 1320d-5.
  • Lead to the early, favorable end of an HHS audit.
  • Reduce the remedies, such as a corrective action plan, in an agreement that resolves a potential Security Rule violation.

The statute says "may," so none of these outcomes is guaranteed. Our guide to HIPAA violation fines and penalties sets out the penalty tiers and amounts these practices may help reduce.

What "in place" means, and how to show it

In an April 2022 request for information, HHS read "in place" to mean the same as "implemented" in the Security Rule. Documenting that a practice was adopted is not enough. HHS said it must be "actively and consistently in use" over the period. The statute does not say what event starts the 12-month look-back. Whatever event starts it, a framework adopted today cannot show it was in use over the past year.

Start with a risk analysis, then map each chosen practice to the systems that hold ePHI. Our HIPAA risk analysis guide covers the nine elements OCR looks for. Keep dated proof, such as access reviews, patch records, backup tests, and training logs. These are examples, not a list HHS has promised to accept.

A hosting vendor's records cover only the systems it runs. A signed contract alone does not show that a control was used.

What recognized security practices do not do

  • They are not a safe harbor. The text of Public Law 116-321 never uses the phrase "safe harbor," and it grants no immunity.
  • They do not replace the Security Rule. The law does not limit HHS's power to enforce that rule or override any duty under it (§ 17941(b)(4)).
  • Skipping them creates no liability under this law. Nor does the law let HHS raise fines or expand audits because an entity lacks them (§ 17941(b)(2) and (b)(3)).
  • They are not the de-identification Safe Harbor. The Safe Harbor method for de-identification is a separate Privacy Rule concept.

Where recognized security practices meet the HIPAA Security Rule

The Security Rule text never uses the phrase. Under 45 CFR § 164.306(b)(1), entities may use any measures that reasonably and appropriately implement its standards. A framework can help with these parts:

  • 45 CFR § 164.308(a)(1)(ii)(A) and (B). Risk analysis and risk management are both required. A framework organizes that work but does not replace it.
  • 45 CFR § 164.316(b)(1) and (b)(2)(i). Both are required. Written policies, procedures, and records of required actions and assessments must be kept for six years. The clock runs from creation or the date last in effect, whichever is later.

Addressable does not mean optional, framework or not. Under 45 CFR § 164.306(d)(3), you first assess whether an addressable specification is reasonable and appropriate. If it is, you implement it. If not, you document why and use an equivalent measure if reasonable and appropriate.

Changes under discussion

S. 3315, the Health Care Cybersecurity and Resiliency Act of 2026, passed the Senate on September 30, 2026. As of October 9, 2026, it is not law, and the House has not voted on it. If enacted, it would give HHS one year to write rules on which recognized security practices count and how fully they must be in place. Those rules would also say what entities must submit. The bill would also add "investments" to the definition. Our guide to what S. 3315 would mean for HIPAA covers the full bill. HHS's separate Security Rule proposal is not final either, as our new HIPAA Security Rule tracker explains.

Sources: 42 U.S.C. § 17941, 15 U.S.C. § 272, and 6 U.S.C. § 1533 at law.cornell.edu; 45 CFR § 164.306, § 164.308, and § 164.316; the HHS request for information, 87 FR 19833 (April 6, 2022); the HHS 405(d) HICP page; and the Senate-passed text of S. 3315.

Share this definition with your team

View link to copy manually

Stay current on HIPAA hosting

Practical guidance on compliance, hosting and the rules that actually apply to your practice.