Skip to main content

> 45_cfr_parts_160_&_164

45 CFR Parts 160 & 164

HIPAA Security and Privacy Rules

SPEC // INSPECT: 45 CFR Parts 160 & 164REVIEWED: 2026-09-16
CATEGORYPrivacy & Data Protection
JURISDICTIONUNITED_STATES
REGULATORY AUTHORITYU.S. Department of Health and Human Services (HHS / OCR)
LIFECYCLE STATUSCURRENT
EXECUTIVE BRIEF SPECIFICATION PDFDISTRIBUTION LOCKED
Fail-Closed Distribution Policy: Download control is visibly disabled until Cloudflare R2 CDN upload and remote SHA-256 verification complete.
[AI // ARCHITECTURAL SUMMARY]

The HIPAA Security and Privacy Rules establish federal protections for Protected Health Information (PHI) held by covered entities and business associates. The Security Rule outlines technical, physical, and administrative safeguards for electronic PHI (ePHI), including transmission encryption, access controls, audit logs, and business associate agreements (BAAs).

Scope & Applicability

Applies to Covered Entities (healthcare providers, health plans, healthcare clearinghouses) and Business Associates (software vendors, cloud providers handling ePHI).

Non-Coverage Boundaries

Does not apply to non-covered entities such as direct-to-consumer health tracking wearables that do not interface with covered clinical institutions.

Key Clauses & Control Requirements

sec-164-312-a

Access Controls & Unique User Identification

Assign unique name/number for identifying and tracking user identity, emergency 'break-glass' access procedures, and automatic logoff.

sec-164-312-e

Transmission Security (Encryption in Transit)

Guard against unauthorized access to ePHI that is being transmitted over an electronic communications network.

[AUDIT // VERIFIABLE EVIDENCE CHECKLIST]

Required Regulatory & Audit Evidence Artifacts

  • [✓]Signed Business Associate Agreements (BAAs) with all cloud infrastructure providers
  • [✓]HIPAA Security Risk Assessment (SRA) reports
  • [✓]ePHI database encryption configuration records (AES-256 at rest, TLS 1.3 in transit)
[LEADERSHIP TAKEAWAY // CTO & VP OF ENGINEERING DIRECTIVE]
A SaaS provider handling clinical data in the US without executed BAAs is in immediate breach. Encryption at rest and in transit is a non-negotiable architectural baseline.
PRIMARY SOURCES & AUTHORITY

Frequently Asked Questions

What is a Business Associate Agreement (BAA)?

A legally binding contract between a covered entity and a vendor (e.g. AWS, SaaS platform) ensuring the vendor will appropriately safeguard protected health information.