Where the technical safeguards fit
The HIPAA Security Rule protects electronic protected health information (ePHI) with three kinds of safeguards: administrative, physical, and technical. This guide covers the technical ones, the part IT is directly responsible for.
Some specifications are required. Others are addressable, which means you must implement them if they're reasonable and appropriate for your practice, or document why you chose an equivalent alternative. In practice, for a small office, most addressable items should simply be done.
HHS proposed changes to the Security Rule in January 2025 that would make more of these safeguards, including encryption and multi-factor authentication, explicitly required. Check the current status of that rule with your compliance advisor.
1. Access control
Only the right people should be able to reach ePHI.
- Give every person their own login. No shared front-desk accounts. (Required)
- Have a documented way to get into systems in an emergency. (Required)
- Lock screens automatically after a few minutes of inactivity. (Addressable)
- Encrypt laptops and workstations that store or access ePHI. (Addressable)
- Remove access the same day someone leaves.
2. Audit controls
You need a way to record and review activity in systems that contain ePHI. (Required)
- Turn on sign-in and activity logging in your EHR, email, and file storage
- Keep logs long enough to investigate an incident
- Have someone actually review alerts, such as sign-ins from unusual locations
3. Integrity
Protect ePHI from being altered or destroyed improperly.
- Limit who can edit or delete records
- Keep backups that can't be changed by ransomware, and test restoring them
- Use endpoint protection that detects tampering and malicious software
4. Person or entity authentication
Confirm that people are who they say they are before they get access. (Required)
- Turn on multi-factor authentication for email, the EHR, remote access, and any cloud portal with patient data
- Ban shared and reused passwords; use a business password manager
5. Transmission security
Protect ePHI while it moves over a network.
- Use encrypted email or a secure portal to send patient information
- Require encrypted connections (VPN or secure remote access) for working from home
- Separate guest Wi-Fi from the network your workstations use
What technology can't do for you
HIPAA compliance also requires a documented risk analysis, written policies, workforce training, business associate agreements, and breach procedures. An IT provider can implement and document the technical safeguards and give you evidence for your program. No vendor can make a practice “HIPAA compliant” on its own, and you should be wary of any that claims to.