Module 03 · Free · 5:30
HIPAA Security Rule
The Security Rule, mandatory risk assessment, Security Officer designation, secure networks, BAAs, MFA, encryption, secure device use (registered devices, screen time-outs, password rotation), and staff-training cadence.
The Security Rule establishes national standards to protect electronic Protected Health Information. Where the Privacy Rule covers all forms of patient information, the Security Rule applies specifically to ePHI — through administrative, physical, and technical safeguards designed to ensure confidentiality, integrity, and availability. This module covers the required risk assessment, the officer designation, and the specific technical and operational practices every practice must have in place.
Regulatory anchors
- 45 CFR §164.306
- 45 CFR §164.308(a)(1)(ii)(A)
- 45 CFR §164.308(a)(2)
- 45 CFR §164.308(a)(5)
- 45 CFR §164.308(b)
- 45 CFR §164.312
- 45 CFR §164.312(a)(2)(iv)
Hosted on the Patient Protect YouTube channel
HIPAA Security Rule: How to Protect Patient Data in Your Practice
Learning objectives
What the workforce should be able to do after this module.
- Define and understand the HIPAA Security Rule
- Learn how to implement security measures to protect ePHI
- Understand the importance of risk assessments and the assigned security-officer role
- Identify best practices to maintain compliance and prevent breaches
Assessment: 5 knowledge-check questions per module, 80% passing standard.
Module outline
Section-by-section walkthrough.
01
What the Security Rule is
As defined by HHS, the Security Rule establishes national standards to protect ePHI through administrative, physical, and technical safeguards. Its aim is to ensure the confidentiality, integrity, and availability of patient data. Unlike the Privacy Rule — which applies to all forms of patient information — the Security Rule applies only to electronic data.
02
Risk Assessment — required
Completion of a risk assessment is required under HIPAA. It identifies potential vulnerabilities in how the practice stores, accesses, and transmits ePHI. Every subsequent safeguard decision flows from the results of this assessment.
03
Assigning a Security Officer
Each practice must designate a Security Officer responsible for overseeing the implementation and enforcement of security policies, ensuring safeguards are in place, and maintaining compliance across the organization.
04
Secure networks and Business Associate Agreements
The practice must use secure, protected networks whenever accessing or transmitting ePHI. Any vendor or third party that handles ePHI must have a signed Business Associate Agreement in place, ensuring the vendor is also bound by HIPAA obligations.
05
MFA and encryption
Multi-Factor Authentication (MFA) adds a verification layer beyond the password before granting access to systems containing ePHI. Encryption converts ePHI into unreadable data during transmission and storage, protecting against breach even when a device is lost or a network is intercepted.
06
Secure use of office technology
All devices used to access ePHI must be properly secured and monitored. That includes registering devices in a centralized system, enabling screen time-outs to prevent unauthorized viewing, and requiring frequent password updates. Access to ePHI should also be role-based — staff only have access to the information necessary for their job duties.
07
Staff training — cadence and onboarding
Ongoing staff training is essential. Training should be conducted annually or whenever significant policy changes are made — whichever comes first. All new hires must complete HIPAA training as part of their onboarding so they understand security protocols from day one.
08
The three safeguard categories
The Security Rule is built on three main safeguard categories — administrative, physical, and technical. Every step in this module supports at least one of these categories and, together, they create a secure environment for ePHI.
Sample knowledge check
A representative question from this module.
Sample question · 5 per module in the live series
An office is signing up for a new cloud EHR vendor that will store ePHI. According to the Security Rule requirements covered in this module, which of the following MUST the practice have in place before using the vendor?
- A.Only a workforce training refresher on the new system.
- B.A signed Business Associate Agreement (BAA) with the vendor.
- C.A written acceptable-use policy signed by all staff.
- D.Notification to affected patients that a new vendor is being used.
Show explanation
Correct answer: B. Any vendor or third party that handles ePHI must have a signed Business Associate Agreement in place, ensuring the vendor is also bound by HIPAA obligations. This is one of the specific implementation requirements covered in the Security Rule module.
Module 03 of the HIPAA Foundations series
Every learner. Every module. One office price.
When you are ready to train the whole practice, the complete 19-module HIPAA Foundations series unlocks for up to 25 personnel at $39/office/month — with per-learner assessment scores, verifiable Certificates of Completion, and workforce-wide tracking.
Free tools stay free — no account needed. The 14-day platform trial asks for a card for identity verification; no charge before day 14, cancel any time.
