Resource Guide

HIPAA Cybersecurity Requirements

HIPAA does not prescribe one specific cybersecurity product stack. It requires covered entities and business associates to implement reasonable and appropriate safeguards to protect electronic protected health information.

HIPAA in plain English

If your organization creates, receives, maintains, or transmits electronic protected health information (ePHI), HIPAA requires administrative, physical, and technical safeguards designed to protect the confidentiality, integrity, and availability of that information.

This page provides general educational information and is not legal advice. HIPAA obligations depend on the organization's role, systems, risks, and specific circumstances. Verify current HHS, OCR, and eCFR requirements before finalizing decisions.

The Philosophy

HIPAA is risk-based, not product-based

HIPAA does not say 'Buy Product X' or 'Install Tool Y and you are compliant.' The Security Rule requires organizations to assess risk and implement safeguards that are reasonable and appropriate for their environment.

Two healthcare organizations may need different technical implementations depending on their size, complexity, capabilities, infrastructure, cost, and the probability and criticality of potential risks. These factors are drawn from the Security Rule's flexibility language, so verify current HHS guidance.

This is why a checklist of products is not a HIPAA program. A defensible approach starts with understanding risk and then selecting safeguards that fit the organization.

HIPAA compliance is a risk-management program, not a software bundle.

The Foundation

What is ePHI?

Electronic protected health information (ePHI) is individually identifiable health information transmitted by or maintained in electronic form. It includes any health information that can be linked to an individual and is created, received, maintained, or transmitted in electronic format.

ePHI may exist in places such as:

EHR systems
Email
File shares
Microsoft 365
Cloud applications
Workstations
Laptops
Mobile devices
Backups
Scanners
Patient portals
Imaging systems
Vendor platforms

The first step in HIPAA cybersecurity is knowing where ePHI actually exists and how it moves through the organization.

The Security Rule

The three HIPAA Security Rule safeguard categories

The Security Rule organizes safeguards into administrative, physical, and technical categories. Use current HHS terminology when documenting your program.

Administrative Safeguards

  • Risk analysis
  • Risk management
  • Workforce security
  • Information access management
  • Security awareness and training
  • Security incident procedures
  • Contingency planning
  • Evaluation
  • Business associate considerations

Physical Safeguards

  • Facility access controls
  • Workstation use
  • Workstation security
  • Device and media controls

Technical Safeguards

  • Access control
  • Audit controls
  • Integrity
  • Authentication
  • Transmission security
The Requirement

The risk analysis requirement

HIPAA requires an accurate and thorough assessment of potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI.

A risk analysis should consider:

Where ePHI is stored
Where ePHI is transmitted
Who can access ePHI
Threats to ePHI
Vulnerabilities in systems
Existing safeguards
Likelihood of occurrence
Potential impact

A risk analysis is not the same thing as a vulnerability scan. A scan can be one input, but a HIPAA risk analysis is broader and considers people, processes, and the business context around the technology.

You cannot manage HIPAA security risk if you do not know where the ePHI is or how it is exposed.

Implementation Specifications

Required vs. addressable

HIPAA Security Rule implementation specifications may be categorized as required or addressable. This distinction matters and is often misunderstood.

Addressable does not mean optional. An organization must assess whether the specification is reasonable and appropriate for its environment. If it is not implemented as written, the organization must consider and document an appropriate alternative where the rule requires it.

Use current HHS guidance to determine how each specification applies to your organization. Do not treat addressable as a synonym for ignorable.

Nuance

Does HIPAA require MFA?

The original Security Rule text does not simply say "every organization must use MFA everywhere." However, modern security expectations, risk analysis, cyber insurance requirements, HHS guidance, and frameworks like NIST strongly support MFA for systems handling ePHI, especially remote access and privileged access.

Do not make a universal MFA mandate unless current law or regulation explicitly requires it. Instead, treat MFA as a reasonable and appropriate safeguard that risk analysis will almost always support for sensitive access.

Verify current HHS and OCR requirements and any newer regulatory changes before finalizing your security decisions. HIPAA rulemaking can evolve.

Nuance

Does HIPAA require encryption?

Encryption is highly relevant to HIPAA, but the exact treatment depends on the Security Rule and the implementation specification involved. Encryption is an addressable specification for ePHI at rest and in transit, which means it must be assessed and either implemented or addressed through a documented alternative.

Encryption can reduce risk and may affect breach analysis in some situations, but do not make legal conclusions about reportability without qualified counsel. Use HHS and OCR guidance when evaluating encryption decisions.

Data at rest
Data in transit
Laptops and mobile devices
Email
Backups
Removable media
Technical Safeguard

Access control

Employees should generally only have access to the ePHI they need for their job responsibilities. Practical access control includes:

Unique user accounts
No shared accounts where avoidable
Least privilege
Role-based access
Administrator access controls
Prompt termination and offboarding
Emergency access procedures
Password and authentication controls
MFA where appropriate
Technical Safeguard

Audit logs and monitoring

Healthcare organizations need visibility into activity involving systems containing ePHI. This includes:

Audit logs
Sign-in logs
Security alerts
Endpoint alerts
Administrative activity
Failed login events
Unusual access patterns

There is a distinction between generating logs and reviewing logs. Logs that nobody reviews provide limited security value.

Logging without review provides less security value than many organizations assume.

HIPAA does not require a specific SIEM product. The requirement is reasonable and appropriate audit controls and review practices.

Practical

Email and Microsoft 365

Email is one of the most common entry points for healthcare security incidents. Account compromise, phishing, and business email compromise can expose ePHI and disrupt operations. Relevant areas include MFA, email security filtering, secure transmission, permissions, administrator accounts, audit logging, sharing settings, and retention.

Using Microsoft 365 does not automatically make an organization HIPAA compliant. Security depends partly on configuration and licensing, not simply having a subscription.

Administrative Safeguard

Backups and contingency planning

HIPAA's contingency planning requirements relate to availability and recovery. They include:

Data backup plan
Disaster recovery plan
Emergency mode operations
Testing and revision
Criticality analysis where applicable

A backup is only useful if the organization can actually recover from it.

Threat Context

Ransomware and HIPAA

Ransomware can affect the confidentiality, integrity, and availability of ePHI. Relevant defenses include endpoint security, MFA, email security, security monitoring, backup and recovery, incident response, and segmentation where appropriate.

Do not imply that every ransomware event is automatically a reportable HIPAA breach. Breach implications depend on the facts and current HHS and OCR guidance. Consult appropriate privacy and legal professionals for breach determinations.

Organizational

HIPAA and business associates

Business associates can have HIPAA obligations when they create, receive, maintain, or transmit PHI on behalf of covered entities. A signed Business Associate Agreement (BAA) defines the relationship, but a signed BAA does not automatically make the underlying technology secure.

Business associates can include cloud vendors, IT providers, billing companies, consultants, and software vendors. The agreement defines responsibilities; the technical safeguards determine whether the data is actually protected.

Practical

Vendor management

Healthcare organizations need to understand which vendors touch ePHI. Practical questions include:

Does the vendor handle ePHI?
Is a BAA required?
What security controls are used?
Who has administrative access?
How is data protected in transit and at rest?
What happens when the vendor relationship ends?

This is not legal advice. Vendor management decisions should involve appropriate compliance and legal review.

Preparedness

Incident response

Organizations should have a defined process for handling suspected security incidents. A practical incident response process may include:

Internal escalation procedures
IT and security response
Evidence preservation
Containment
Recovery
Leadership involvement
Legal and compliance involvement where appropriate
Cyber insurance notification where applicable

Titan does not provide legal breach notification determinations. Consult appropriate privacy, legal, and compliance professionals for those questions.

Administrative Safeguard

Employee onboarding and offboarding

Access management failures can become HIPAA security risks. Strong onboarding and offboarding processes include:

Creating appropriate access
MFA enrollment
Role assignment
Device provisioning
Removing access promptly
Disabling former employee accounts
Revoking active sessions
Handling email and data
Recovering company devices
Avoid These

Common HIPAA cybersecurity mistakes

Treating HIPAA as paperwork only
Assuming a BAA makes a vendor secure
Using shared accounts
No documented risk analysis
Not knowing where ePHI exists
Weak employee offboarding
Backups that are never tested
No security monitoring
Policies that do not match real operations
Assuming antivirus alone is a complete security program
Interactive Tool

HIPAA cybersecurity readiness check

A quick self-assessment to help you think through your technical security posture. It is educational and does not constitute a formal HIPAA risk analysis or legal compliance determination.

Have we completed a documented security risk analysis?

Do we know where all ePHI is stored?

Are users assigned unique accounts?

Is MFA used for important systems and remote access where appropriate?

Are administrator privileges limited?

Are systems centrally patched?

Is endpoint security deployed?

Are security alerts actively monitored?

Are backups monitored?

Have restores been tested?

Do we have an incident-response process?

Do we review access promptly when employees leave?

Answer all 12 questions to see your readiness summary.

The Output

What should a HIPAA security assessment produce?

A useful assessment should translate technical findings into prioritized business actions. Findings should be prioritized by risk rather than presented as one massive checklist.

Current-state summary
ePHI scope
Identified risks
Existing safeguards
Gaps
Prioritized remediation
Documentation needs
Recommended next steps
The Boundary

HIPAA compliance is more than cybersecurity

Titan's technical focus is only part of HIPAA. HIPAA also includes privacy, organizational, documentation, policy, workforce, and legal considerations outside an MSP's technical role.

Good cybersecurity supports HIPAA compliance, but cybersecurity alone does not equal HIPAA compliance.

Transparency

What Titan can and cannot do

Titan CAN

  • Review technical cybersecurity controls
  • Help with IT risk assessment and ePHI scoping
  • Implement MFA, endpoint security, and email security
  • Configure Microsoft 365 security
  • Set up security monitoring and logging
  • Manage backups and tested recovery
  • Support patch management and network security
  • Help document the technical environment
  • Explain technical safeguard terminology

Titan DOES NOT

  • Provide legal advice
  • Certify HIPAA compliance
  • Determine breach reportability
  • Replace privacy officers or legal counsel
  • Guarantee a specific regulatory outcome
About Titan

How Titan helps healthcare organizations

Titan IT Management is a technical HIPAA cybersecurity and readiness partner, not a law firm or an organization issuing a certification. We help healthcare organizations with IT risk assessment, ePHI system scoping, Microsoft 365 security, MFA and identity, endpoint security, email security, security monitoring, patch management, backup and recovery, network security, logging, access control, technical documentation, and remediation planning.

We serve healthcare organizations throughout Florida's Treasure Coast, including Stuart, Port St. Lucie, Jensen Beach, and Fort Pierce. Our philosophy is simple: compliance must come before claim.

FAQ

Common questions about HIPAA cybersecurity

What cybersecurity does HIPAA require?

HIPAA's Security Rule requires covered entities and business associates to implement reasonable and appropriate administrative, physical, and technical safeguards to protect the confidentiality, integrity, and availability of ePHI. It does not prescribe a specific product stack. Requirements are risk-based and depend on the organization's size, complexity, and risk profile. Verify current HHS and OCR guidance.

Does HIPAA require MFA?

The original Security Rule text does not simply mandate MFA everywhere. However, modern security expectations, risk analysis, cyber insurance requirements, and frameworks like NIST strongly support MFA for systems handling ePHI, especially remote access and privileged access. Do not assume a universal mandate unless current law explicitly requires it. Treat MFA as a reasonable and appropriate safeguard that risk analysis will almost always support.

Does HIPAA require encryption?

Encryption is an addressable implementation specification for ePHI at rest and in transit. Addressable does not mean optional. An organization must assess whether encryption is reasonable and appropriate, implement it, or document an appropriate alternative. Encryption can reduce risk and may affect breach analysis in some situations, but do not make legal conclusions about reportability without qualified counsel. Use HHS and OCR guidance.

Does HIPAA require backups?

Yes. The Security Rule's contingency planning standard requires a data backup plan and disaster recovery plan. Organizations must also establish emergency mode operations and test and revise procedures. A backup is only useful if the organization can actually recover from it, so restore testing is essential.

What is a HIPAA security risk analysis?

A HIPAA risk analysis is an accurate and thorough assessment of potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI. It considers where ePHI is stored and transmitted, who can access it, threats, vulnerabilities, existing safeguards, likelihood, and potential impact. It is broader than a vulnerability scan, which is only one possible input.

Does HIPAA require antivirus?

HIPAA does not name a specific antivirus product. It requires reasonable and appropriate technical safeguards, which typically include endpoint protection and malicious software protection as part of a layered security program. Antivirus alone is not a complete security program.

What is ePHI?

ePHI is electronic protected health information: individually identifiable health information created, received, maintained, or transmitted in electronic form. It includes any health information that can be linked to an individual and exists in electronic format, such as in EHR systems, email, file shares, Microsoft 365, backups, and mobile devices.

What is the difference between required and addressable safeguards?

HIPAA implementation specifications may be categorized as required or addressable. Required specifications must be implemented as written. Addressable does not mean optional. An organization must assess whether the specification is reasonable and appropriate, implement it, or consider and document an appropriate alternative where the rule requires it. Use current HHS guidance to determine how each specification applies.

Does Microsoft 365 make my business HIPAA compliant?

No. Using Microsoft 365 does not automatically make an organization HIPAA compliant. HIPAA compliance depends on risk analysis, safeguards, policies, documentation, and configuration. Microsoft 365 security depends partly on configuration and licensing, not simply having a subscription. A BAA with Microsoft addresses the business associate relationship but does not by itself make the underlying configuration compliant.

Can an MSP certify HIPAA compliance?

No. An MSP like Titan IT Management can help implement technical safeguards, perform IT risk assessment, configure security controls, and support documentation, but it does not certify HIPAA compliance. HIPAA compliance involves privacy, legal, organizational, and documentation considerations beyond an MSP's technical role. Consult qualified privacy and legal professionals for compliance determinations.

Research & Sources

Official HIPAA resources & further reading

HIPAA obligations depend on the organization's role, systems, risks, and circumstances. The sources below support general guidance, not legal advice. Verify current HHS, OCR, and eCFR language before finalizing decisions.

U.S. Department of Health and Human Services (HHS)

HIPAA Security Rule (Current)

Official HHS guidance on administrative, physical, and technical safeguards for ePHI.

View source

HHS HIPAA for Professionals (Current)

General HIPAA guidance for covered entities and business associates.

View source

Office for Civil Rights (OCR)

OCR Cybersecurity Guidance (Current)

OCR resources on cybersecurity, ransomware, and breach notification for HIPAA-covered organizations.

View source

OCR Ransomware Guidance (Current)

Guidance on ransomware and its relationship to HIPAA breach analysis.

View source

Electronic Code of Federal Regulations (eCFR)

45 CFR Part 164 — Security and Privacy (Current)

The official regulatory text of the HIPAA Security Rule.

View source

NIST

NIST SP 800-66 Rev. 2 (2024)

Implementing the HIPAA Security Rule: A Cybersecurity Resource Guide for small and medium-sized practices.

View source

NIST Cybersecurity Framework (Current)

A widely used framework that supports HIPAA risk management and safeguards.

View source

CISA

CISA Cybersecurity Best Practices (Current)

General cybersecurity guidance that supports HIPAA technical safeguards, including MFA and patch management.

View source

Understand your HIPAA security posture before you need to prove it.

Titan helps Treasure Coast healthcare organizations implement the technical safeguards that support HIPAA compliance, from risk analysis and ePHI scoping to MFA, monitoring, and tested recovery. No fear-based marketing, no compliance certification claims, just a clear technical readiness partner.