Skip to main content
Patient Protect circular logo mark in purple and white used for site navigationPatient Protect

Regulatory reference

HIPAA, by citation.

Look up what a provision of the Security, Privacy or Breach Notification Rule actually covers, and where to go next to work on it. Provisions the proposed Security Rule would change are flagged as proposed — the rule currently in effect is the one described here.

54 provisions·3 rules·13 NPRM changes flagged·Updated September 2026

Why this page exists

You cannot evaluate a compliance platform without seeing what it actually covers.

Every HIPAA compliance vendor says they “cover the Security Rule.” That claim is easy to make and impossible to verify — unless the vendor shows you exactly which provisions their platform addresses and how. Most do not. They give you a feature list and expect you to trust that it maps to the regulation. That is not transparency. That is marketing.

This page is the opposite. Below is a provision-by-provision cross-reference between the HIPAA Security Rule, Breach Notification Rule, and Privacy Rule and the Patient Protect platform. Every citation comes from 45 CFR Part 164. Every platform mapping points to a named module, not a vague bullet point. Where the 2026 NPRM changes a provision from addressable to required, it is flagged — so you can see which controls your practice will need before enforcement, not after.

If you are evaluating compliance platforms, ask every vendor for this level of specificity. If they cannot provide it, that tells you something.

New to these provisions? The free HIPAA Fundamentals and Security Rule training modules cover the vocabulary and safeguards framework this map assumes.

This map is an index, not the regulation. The text itself is published on eCFR: Security Rule, Subpart C; Privacy Rule, Subpart E; Breach Notification Rule, Subpart D. For the Privacy Rule read as a practice would use it rather than as it is written, see the Privacy Rule guide.

3

Rules covered

Security · Breach · Privacy

13

Regulatory sections

Security, Privacy, Breach

54

Provisions indexed

Not a count of HIPAA requirements

13

NPRM changes

Addressable → required

22

Modules involved

Covering every provision

45 CFR Part 164

HIPAA Security Rule

Administrative, physical, and technical safeguards for electronic protected health information. The 2026 NPRM eliminates 'addressable' designations — all safeguards become required.

Where to go next

Reading the rule is the first step.

Most of what you have just read is addressed to your organization rather than to any vendor. The risk assessment is where a practice usually starts, and it is free.

Free · No account required

How to read the rule.

The four things people most often get wrong about HIPAA’s structure, and one about the proposed Security Rule.

What does it mean for a HIPAA provision to be 'addressable' vs 'required'?

Under the current Security Rule, 'required' implementation specifications must be implemented as written; 'addressable' specifications can be implemented as written, replaced with an equivalent measure documented in writing, or — if neither is reasonable — addressed via a documented analysis explaining why. The January 2025 NPRM would eliminate the 'addressable' designation and make all current addressable specifications required, subject to specific limited exceptions. The NPRM has not been finalized and the current Security Rule remains in effect.

How many CFR provisions does HIPAA contain?

Patient Protect's regulation map tracks 54 provisions across the HIPAA Security Rule (45 CFR §164.302–§164.318), Breach Notification Rule (§164.400–§164.414), and Privacy Rule (45 CFR Part 164, Subpart E). Of these, 13 are flagged as changing if the January 2025 NPRM is finalized.

What's the difference between the Security Rule and the Privacy Rule?

The Privacy Rule governs how protected health information (PHI) may be used and disclosed by covered entities and business associates. The Security Rule governs the administrative, physical, and technical safeguards required to protect electronic PHI (ePHI) specifically. Both apply concurrently — Privacy says what you can share; Security says how you protect what you keep.

Does this map mean Patient Protect satisfies these provisions?

No, and the distinction matters. This map is a navigation aid: it tells you what a citation covers and where to go next to work on it. Whether an obligation is discharged is a different question — most of the Security Rule is addressed to your organization, not to a vendor, and no subscription answers it on your behalf. For that analysis, provision by provision, see what Patient Protect handles automatically and what remains yours.

When does the 2026 HIPAA Security Rule take effect?

The Security Rule NPRM (Notice of Proposed Rulemaking) was published on January 6, 2025 at 90 FR 898. No final rule has been issued and the current Security Rule remains in effect and fully enforceable. HHS's Unified Agenda currently places the proposal (RIN 0945-AA22) in Long-Term Actions with July 2027 listed as an agency planning estimate for possible final action — not a binding deadline. If finalized, the proposal would (subject to limited exceptions) require encryption of ePHI at rest and in transit, multi-factor authentication, technology asset inventory and network map review on defined cadence, vulnerability scanning and penetration testing, annual compliance audit, network segmentation, written documentation, and the capability to restore certain relevant electronic information systems and data within 72 hours. The 72-hour concept is a restoration/recovery obligation — it is not a new HHS breach reporting deadline. Breach notification is unchanged: individual notice without unreasonable delay and no later than 60 calendar days after discovery (§164.404(b)), and notice to HHS contemporaneously with it where 500 or more individuals are involved (§164.408(b)).