Skip to main content
Back to results
X-HIPAA-SECRULE Informational

Implement HIPAA Security Rule Safeguards for ePHI

Official citation: HIPAA Security Rule

Class: informational · Severity: high

Statement of the obligation — verify against source

HIPAA Security Rule

What it means

If you handle health information for a covered entity, you are a business associate and the HIPAA Security Rule binds you directly. Two things anchor it: a real, documented risk analysis, and a signed Business Associate Agreement before any ePHI changes hands.

Required by

  • 45 CFR 164 Subpart C
  • HHSARHHSAR 352.224-70
  • HITECHPub. L. 111-5
  • HIPAA45 CFR 164 Subpart C

Educational reference only — not legal advice. Consult a qualified assessor or attorney for binding compliance determinations.