Compliance frameworks
HIPAA Security Rule
The HIPAA Security Rule, codified at 45 CFR 164.302 through 164.318, sets administrative, physical, and technical safeguards for electronic PHI that is created, received, maintained, or transmitted. Its technical safeguards (164.312) cover access control, audit controls, integrity, person or entity authentication, and transmission security. Each comes with implementation specifications marked Required, such as unique user identification, or Addressable, such as automatic logoff, encryption, and mechanisms to authenticate the integrity of ePHI. An Addressable specification must be implemented if reasonable and appropriate, or an equivalent alternative documented. HHS proposed changes in January 2025, including removing most Addressable designations; as of October 2026 the proposal had not been finalized.