> 45_cfr_parts_160_&_164
45 CFR Parts 160 & 164
HIPAA Security and Privacy Rules
The HIPAA Security and Privacy Rules establish federal protections for Protected Health Information (PHI) held by covered entities and business associates. The Security Rule outlines technical, physical, and administrative safeguards for electronic PHI (ePHI), including transmission encryption, access controls, audit logs, and business associate agreements (BAAs).
Scope & Applicability
Applies to Covered Entities (healthcare providers, health plans, healthcare clearinghouses) and Business Associates (software vendors, cloud providers handling ePHI).
Non-Coverage Boundaries
Does not apply to non-covered entities such as direct-to-consumer health tracking wearables that do not interface with covered clinical institutions.
Key Clauses & Control Requirements
Access Controls & Unique User Identification
Assign unique name/number for identifying and tracking user identity, emergency 'break-glass' access procedures, and automatic logoff.
Transmission Security (Encryption in Transit)
Guard against unauthorized access to ePHI that is being transmitted over an electronic communications network.
Required Regulatory & Audit Evidence Artifacts
- [✓]Signed Business Associate Agreements (BAAs) with all cloud infrastructure providers
- [✓]HIPAA Security Risk Assessment (SRA) reports
- [✓]ePHI database encryption configuration records (AES-256 at rest, TLS 1.3 in transit)
“A SaaS provider handling clinical data in the US without executed BAAs is in immediate breach. Encryption at rest and in transit is a non-negotiable architectural baseline.”
Cross-Surface Ecosystem Relationships
- HIPAA Security Rule ↗(U.S. Department of Health and Human Services)
Frequently Asked Questions
What is a Business Associate Agreement (BAA)?
A legally binding contract between a covered entity and a vendor (e.g. AWS, SaaS platform) ensuring the vendor will appropriately safeguard protected health information.
