Skip to main content
Patient Protect circular logo mark in purple and white used for site navigationPatient Protect
HIPAA Training

Module 03 · Free · 5:30

HIPAA Security Rule

The Security Rule, mandatory risk assessment, Security Officer designation, secure networks, BAAs, MFA, encryption, secure device use (registered devices, screen time-outs, password rotation), and staff-training cadence.

The Security Rule establishes national standards to protect electronic Protected Health Information. Where the Privacy Rule covers all forms of patient information, the Security Rule applies specifically to ePHI — through administrative, physical, and technical safeguards designed to ensure confidentiality, integrity, and availability. This module covers the required risk assessment, the officer designation, and the specific technical and operational practices every practice must have in place.

Regulatory anchors

  • 45 CFR §164.306
  • 45 CFR §164.308(a)(1)(ii)(A)
  • 45 CFR §164.308(a)(2)
  • 45 CFR §164.308(a)(5)
  • 45 CFR §164.308(b)
  • 45 CFR §164.312
  • 45 CFR §164.312(a)(2)(iv)

Hosted on the Patient Protect YouTube channel

HIPAA Security Rule: How to Protect Patient Data in Your Practice

Learning objectives

What the workforce should be able to do after this module.

  • Define and understand the HIPAA Security Rule
  • Learn how to implement security measures to protect ePHI
  • Understand the importance of risk assessments and the assigned security-officer role
  • Identify best practices to maintain compliance and prevent breaches

Assessment: 5 knowledge-check questions per module, 80% passing standard.

Module outline

Section-by-section walkthrough.

  1. 01

    What the Security Rule is

    As defined by HHS, the Security Rule establishes national standards to protect ePHI through administrative, physical, and technical safeguards. Its aim is to ensure the confidentiality, integrity, and availability of patient data. Unlike the Privacy Rule — which applies to all forms of patient information — the Security Rule applies only to electronic data.

  2. 02

    Risk Assessment — required

    Completion of a risk assessment is required under HIPAA. It identifies potential vulnerabilities in how the practice stores, accesses, and transmits ePHI. Every subsequent safeguard decision flows from the results of this assessment.

  3. 03

    Assigning a Security Officer

    Each practice must designate a Security Officer responsible for overseeing the implementation and enforcement of security policies, ensuring safeguards are in place, and maintaining compliance across the organization.

  4. 04

    Secure networks and Business Associate Agreements

    The practice must use secure, protected networks whenever accessing or transmitting ePHI. Any vendor or third party that handles ePHI must have a signed Business Associate Agreement in place, ensuring the vendor is also bound by HIPAA obligations.

  5. 05

    MFA and encryption

    Multi-Factor Authentication (MFA) adds a verification layer beyond the password before granting access to systems containing ePHI. Encryption converts ePHI into unreadable data during transmission and storage, protecting against breach even when a device is lost or a network is intercepted.

  6. 06

    Secure use of office technology

    All devices used to access ePHI must be properly secured and monitored. That includes registering devices in a centralized system, enabling screen time-outs to prevent unauthorized viewing, and requiring frequent password updates. Access to ePHI should also be role-based — staff only have access to the information necessary for their job duties.

  7. 07

    Staff training — cadence and onboarding

    Ongoing staff training is essential. Training should be conducted annually or whenever significant policy changes are made — whichever comes first. All new hires must complete HIPAA training as part of their onboarding so they understand security protocols from day one.

  8. 08

    The three safeguard categories

    The Security Rule is built on three main safeguard categories — administrative, physical, and technical. Every step in this module supports at least one of these categories and, together, they create a secure environment for ePHI.

Sample knowledge check

A representative question from this module.

Sample question · 5 per module in the live series

An office is signing up for a new cloud EHR vendor that will store ePHI. According to the Security Rule requirements covered in this module, which of the following MUST the practice have in place before using the vendor?

  1. A.Only a workforce training refresher on the new system.
  2. B.A signed Business Associate Agreement (BAA) with the vendor.
  3. C.A written acceptable-use policy signed by all staff.
  4. D.Notification to affected patients that a new vendor is being used.
Show explanation

Correct answer: B. Any vendor or third party that handles ePHI must have a signed Business Associate Agreement in place, ensuring the vendor is also bound by HIPAA obligations. This is one of the specific implementation requirements covered in the Security Rule module.

Module 03 of the HIPAA Foundations series

Every learner. Every module. One office price.

When you are ready to train the whole practice, the complete 19-module HIPAA Foundations series unlocks for up to 25 personnel at $39/office/month — with per-learner assessment scores, verifiable Certificates of Completion, and workforce-wide tracking.

Free tools stay free — no account needed. The 14-day platform trial asks for a card for identity verification; no charge before day 14, cancel any time.