HIPAA Cybersecurity Requirements
HIPAA does not prescribe one specific cybersecurity product stack. It requires covered entities and business associates to implement reasonable and appropriate safeguards to protect electronic protected health information.
HIPAA in plain English
If your organization creates, receives, maintains, or transmits electronic protected health information (ePHI), HIPAA requires administrative, physical, and technical safeguards designed to protect the confidentiality, integrity, and availability of that information.
This page provides general educational information and is not legal advice. HIPAA obligations depend on the organization's role, systems, risks, and specific circumstances. Verify current HHS, OCR, and eCFR requirements before finalizing decisions.
HIPAA is risk-based, not product-based
HIPAA does not say 'Buy Product X' or 'Install Tool Y and you are compliant.' The Security Rule requires organizations to assess risk and implement safeguards that are reasonable and appropriate for their environment.
Two healthcare organizations may need different technical implementations depending on their size, complexity, capabilities, infrastructure, cost, and the probability and criticality of potential risks. These factors are drawn from the Security Rule's flexibility language, so verify current HHS guidance.
This is why a checklist of products is not a HIPAA program. A defensible approach starts with understanding risk and then selecting safeguards that fit the organization.
HIPAA compliance is a risk-management program, not a software bundle.
What is ePHI?
Electronic protected health information (ePHI) is individually identifiable health information transmitted by or maintained in electronic form. It includes any health information that can be linked to an individual and is created, received, maintained, or transmitted in electronic format.
ePHI may exist in places such as:
The first step in HIPAA cybersecurity is knowing where ePHI actually exists and how it moves through the organization.
The three HIPAA Security Rule safeguard categories
The Security Rule organizes safeguards into administrative, physical, and technical categories. Use current HHS terminology when documenting your program.
Administrative Safeguards
- Risk analysis
- Risk management
- Workforce security
- Information access management
- Security awareness and training
- Security incident procedures
- Contingency planning
- Evaluation
- Business associate considerations
Physical Safeguards
- Facility access controls
- Workstation use
- Workstation security
- Device and media controls
Technical Safeguards
- Access control
- Audit controls
- Integrity
- Authentication
- Transmission security
The risk analysis requirement
HIPAA requires an accurate and thorough assessment of potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI.
A risk analysis should consider:
A risk analysis is not the same thing as a vulnerability scan. A scan can be one input, but a HIPAA risk analysis is broader and considers people, processes, and the business context around the technology.
You cannot manage HIPAA security risk if you do not know where the ePHI is or how it is exposed.
Required vs. addressable
HIPAA Security Rule implementation specifications may be categorized as required or addressable. This distinction matters and is often misunderstood.
Addressable does not mean optional. An organization must assess whether the specification is reasonable and appropriate for its environment. If it is not implemented as written, the organization must consider and document an appropriate alternative where the rule requires it.
Use current HHS guidance to determine how each specification applies to your organization. Do not treat addressable as a synonym for ignorable.
Does HIPAA require MFA?
The original Security Rule text does not simply say "every organization must use MFA everywhere." However, modern security expectations, risk analysis, cyber insurance requirements, HHS guidance, and frameworks like NIST strongly support MFA for systems handling ePHI, especially remote access and privileged access.
Do not make a universal MFA mandate unless current law or regulation explicitly requires it. Instead, treat MFA as a reasonable and appropriate safeguard that risk analysis will almost always support for sensitive access.
Verify current HHS and OCR requirements and any newer regulatory changes before finalizing your security decisions. HIPAA rulemaking can evolve.
Does HIPAA require encryption?
Encryption is highly relevant to HIPAA, but the exact treatment depends on the Security Rule and the implementation specification involved. Encryption is an addressable specification for ePHI at rest and in transit, which means it must be assessed and either implemented or addressed through a documented alternative.
Encryption can reduce risk and may affect breach analysis in some situations, but do not make legal conclusions about reportability without qualified counsel. Use HHS and OCR guidance when evaluating encryption decisions.
Access control
Employees should generally only have access to the ePHI they need for their job responsibilities. Practical access control includes:
Audit logs and monitoring
Healthcare organizations need visibility into activity involving systems containing ePHI. This includes:
There is a distinction between generating logs and reviewing logs. Logs that nobody reviews provide limited security value.
Logging without review provides less security value than many organizations assume.
HIPAA does not require a specific SIEM product. The requirement is reasonable and appropriate audit controls and review practices.
Email and Microsoft 365
Email is one of the most common entry points for healthcare security incidents. Account compromise, phishing, and business email compromise can expose ePHI and disrupt operations. Relevant areas include MFA, email security filtering, secure transmission, permissions, administrator accounts, audit logging, sharing settings, and retention.
Using Microsoft 365 does not automatically make an organization HIPAA compliant. Security depends partly on configuration and licensing, not simply having a subscription.
Backups and contingency planning
HIPAA's contingency planning requirements relate to availability and recovery. They include:
A backup is only useful if the organization can actually recover from it.
Ransomware and HIPAA
Ransomware can affect the confidentiality, integrity, and availability of ePHI. Relevant defenses include endpoint security, MFA, email security, security monitoring, backup and recovery, incident response, and segmentation where appropriate.
Do not imply that every ransomware event is automatically a reportable HIPAA breach. Breach implications depend on the facts and current HHS and OCR guidance. Consult appropriate privacy and legal professionals for breach determinations.
HIPAA and business associates
Business associates can have HIPAA obligations when they create, receive, maintain, or transmit PHI on behalf of covered entities. A signed Business Associate Agreement (BAA) defines the relationship, but a signed BAA does not automatically make the underlying technology secure.
Business associates can include cloud vendors, IT providers, billing companies, consultants, and software vendors. The agreement defines responsibilities; the technical safeguards determine whether the data is actually protected.
Vendor management
Healthcare organizations need to understand which vendors touch ePHI. Practical questions include:
This is not legal advice. Vendor management decisions should involve appropriate compliance and legal review.
Incident response
Organizations should have a defined process for handling suspected security incidents. A practical incident response process may include:
Titan does not provide legal breach notification determinations. Consult appropriate privacy, legal, and compliance professionals for those questions.
Employee onboarding and offboarding
Access management failures can become HIPAA security risks. Strong onboarding and offboarding processes include:
Common HIPAA cybersecurity mistakes
HIPAA cybersecurity readiness check
A quick self-assessment to help you think through your technical security posture. It is educational and does not constitute a formal HIPAA risk analysis or legal compliance determination.
Have we completed a documented security risk analysis?
Do we know where all ePHI is stored?
Are users assigned unique accounts?
Is MFA used for important systems and remote access where appropriate?
Are administrator privileges limited?
Are systems centrally patched?
Is endpoint security deployed?
Are security alerts actively monitored?
Are backups monitored?
Have restores been tested?
Do we have an incident-response process?
Do we review access promptly when employees leave?
Answer all 12 questions to see your readiness summary.
What should a HIPAA security assessment produce?
A useful assessment should translate technical findings into prioritized business actions. Findings should be prioritized by risk rather than presented as one massive checklist.
HIPAA compliance is more than cybersecurity
Titan's technical focus is only part of HIPAA. HIPAA also includes privacy, organizational, documentation, policy, workforce, and legal considerations outside an MSP's technical role.
Good cybersecurity supports HIPAA compliance, but cybersecurity alone does not equal HIPAA compliance.
What Titan can and cannot do
Titan CAN
- Review technical cybersecurity controls
- Help with IT risk assessment and ePHI scoping
- Implement MFA, endpoint security, and email security
- Configure Microsoft 365 security
- Set up security monitoring and logging
- Manage backups and tested recovery
- Support patch management and network security
- Help document the technical environment
- Explain technical safeguard terminology
Titan DOES NOT
- Provide legal advice
- Certify HIPAA compliance
- Determine breach reportability
- Replace privacy officers or legal counsel
- Guarantee a specific regulatory outcome
How Titan helps healthcare organizations
Titan IT Management is a technical HIPAA cybersecurity and readiness partner, not a law firm or an organization issuing a certification. We help healthcare organizations with IT risk assessment, ePHI system scoping, Microsoft 365 security, MFA and identity, endpoint security, email security, security monitoring, patch management, backup and recovery, network security, logging, access control, technical documentation, and remediation planning.
We serve healthcare organizations throughout Florida's Treasure Coast, including Stuart, Port St. Lucie, Jensen Beach, and Fort Pierce. Our philosophy is simple: compliance must come before claim.
Common questions about HIPAA cybersecurity
What cybersecurity does HIPAA require?
HIPAA's Security Rule requires covered entities and business associates to implement reasonable and appropriate administrative, physical, and technical safeguards to protect the confidentiality, integrity, and availability of ePHI. It does not prescribe a specific product stack. Requirements are risk-based and depend on the organization's size, complexity, and risk profile. Verify current HHS and OCR guidance.
Does HIPAA require MFA?
The original Security Rule text does not simply mandate MFA everywhere. However, modern security expectations, risk analysis, cyber insurance requirements, and frameworks like NIST strongly support MFA for systems handling ePHI, especially remote access and privileged access. Do not assume a universal mandate unless current law explicitly requires it. Treat MFA as a reasonable and appropriate safeguard that risk analysis will almost always support.
Does HIPAA require encryption?
Encryption is an addressable implementation specification for ePHI at rest and in transit. Addressable does not mean optional. An organization must assess whether encryption is reasonable and appropriate, implement it, or document an appropriate alternative. Encryption can reduce risk and may affect breach analysis in some situations, but do not make legal conclusions about reportability without qualified counsel. Use HHS and OCR guidance.
Does HIPAA require backups?
Yes. The Security Rule's contingency planning standard requires a data backup plan and disaster recovery plan. Organizations must also establish emergency mode operations and test and revise procedures. A backup is only useful if the organization can actually recover from it, so restore testing is essential.
What is a HIPAA security risk analysis?
A HIPAA risk analysis is an accurate and thorough assessment of potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI. It considers where ePHI is stored and transmitted, who can access it, threats, vulnerabilities, existing safeguards, likelihood, and potential impact. It is broader than a vulnerability scan, which is only one possible input.
Does HIPAA require antivirus?
HIPAA does not name a specific antivirus product. It requires reasonable and appropriate technical safeguards, which typically include endpoint protection and malicious software protection as part of a layered security program. Antivirus alone is not a complete security program.
What is ePHI?
ePHI is electronic protected health information: individually identifiable health information created, received, maintained, or transmitted in electronic form. It includes any health information that can be linked to an individual and exists in electronic format, such as in EHR systems, email, file shares, Microsoft 365, backups, and mobile devices.
What is the difference between required and addressable safeguards?
HIPAA implementation specifications may be categorized as required or addressable. Required specifications must be implemented as written. Addressable does not mean optional. An organization must assess whether the specification is reasonable and appropriate, implement it, or consider and document an appropriate alternative where the rule requires it. Use current HHS guidance to determine how each specification applies.
Does Microsoft 365 make my business HIPAA compliant?
No. Using Microsoft 365 does not automatically make an organization HIPAA compliant. HIPAA compliance depends on risk analysis, safeguards, policies, documentation, and configuration. Microsoft 365 security depends partly on configuration and licensing, not simply having a subscription. A BAA with Microsoft addresses the business associate relationship but does not by itself make the underlying configuration compliant.
Can an MSP certify HIPAA compliance?
No. An MSP like Titan IT Management can help implement technical safeguards, perform IT risk assessment, configure security controls, and support documentation, but it does not certify HIPAA compliance. HIPAA compliance involves privacy, legal, organizational, and documentation considerations beyond an MSP's technical role. Consult qualified privacy and legal professionals for compliance determinations.
Keep exploring
Microsoft 365 Security Assessment
A free self-assessment scoring your Microsoft 365 security posture.
ExploreCybersecurity Services
Identity, email, endpoint, and monitoring protections for your practice.
ExploreDoes Microsoft 365 Include Backup?
Understand Microsoft 365 resiliency, retention, and backup.
ExploreHow Small Businesses Get Hit With Ransomware
How ransomware progresses and which layered controls interrupt it.
ExploreWhat Is Business Email Compromise?
Why fraudulent email looks legitimate and why verification matters.
ExploreCyber Insurance Requirements
What insurers ask about and how to verify your answers.
ExploreOfficial HIPAA resources & further reading
HIPAA obligations depend on the organization's role, systems, risks, and circumstances. The sources below support general guidance, not legal advice. Verify current HHS, OCR, and eCFR language before finalizing decisions.
U.S. Department of Health and Human Services (HHS)
HIPAA Security Rule (Current)
Official HHS guidance on administrative, physical, and technical safeguards for ePHI.
View sourceHHS HIPAA for Professionals (Current)
General HIPAA guidance for covered entities and business associates.
View sourceOffice for Civil Rights (OCR)
OCR Cybersecurity Guidance (Current)
OCR resources on cybersecurity, ransomware, and breach notification for HIPAA-covered organizations.
View sourceOCR Ransomware Guidance (Current)
Guidance on ransomware and its relationship to HIPAA breach analysis.
View sourceElectronic Code of Federal Regulations (eCFR)
45 CFR Part 164 — Security and Privacy (Current)
The official regulatory text of the HIPAA Security Rule.
View sourceNIST
NIST SP 800-66 Rev. 2 (2024)
Implementing the HIPAA Security Rule: A Cybersecurity Resource Guide for small and medium-sized practices.
View sourceNIST Cybersecurity Framework (Current)
A widely used framework that supports HIPAA risk management and safeguards.
View sourceCISA
CISA Cybersecurity Best Practices (Current)
General cybersecurity guidance that supports HIPAA technical safeguards, including MFA and patch management.
View sourceUnderstand your HIPAA security posture before you need to prove it.
Titan helps Treasure Coast healthcare organizations implement the technical safeguards that support HIPAA compliance, from risk analysis and ePHI scoping to MFA, monitoring, and tested recovery. No fear-based marketing, no compliance certification claims, just a clear technical readiness partner.
