HIPAA Security Rule compliance title card
UI Design Illustration

Avoid OCR Penalties: $143M, HIPAA Security Rule for U.S. Practices

The HIPAA Security Rule requires covered entities and business associates to protect the confidentiality, integrity, and availability of electronic protected health information, full stop. If you take one action this week, make it a documented risk analysis: HHS guidance treats it as the foundation everything else rests on, and NIST provides the roadmap for turning that analysis into real controls.


TL;DR:

  • Conduct a documented risk analysis of all systems, applications, and devices that create, store, or transmit ePHI, and regularly reassess risks when changes occur.
  • Implement unique user IDs, multi-factor authentication, role-based permissions, and encryption for ePHI at rest and in transit to meet technical safeguards.
  • Maintain comprehensive records of policies, training, incident responses, and remediation efforts, as enforcement heavily focuses on missing risk analyses and safeguards.
  • Use NIST SP 800-66r2 to map security controls and prioritize core measures like access control, logging, and encryption, especially for small healthcare practices.
  • Ensure signed business associate agreements, enforce patch management, keep logs reviewed, and stay current with SOPs to reduce the risk of OCR penalties and breaches.

tekrescue
mytekrescue.com
Strengthen Your HIPAA Security
tekRESCUE helps healthcare providers protect sensitive data through HIPAA-focused compliance, cybersecurity, and managed IT services.

Explore tekRESCUE services

Table of Contents

Who the Security Rule covers and what counts as ePHI

The Rule applies to two groups: covered entities (health plans, health care clearinghouses, and providers who transmit health information electronically) and business associates, the vendors and contractors who touch that data on a covered entity’s behalf. If your practice uses a billing service, a cloud EHR, or an IT vendor with system access, that vendor is a business associate and needs a signed agreement that spells out its security obligations.

Electronic protected health information, or ePHI, is any individually identifiable health data created, stored, or transmitted electronically. That includes obvious things like EHR records, but also email threads referencing a patient’s diagnosis, text messages between staff about a case, and photos on a clinician’s phone.

Three quick indicators you’re in scope:

  • You bill insurance electronically or use an electronic health record system.
  • A vendor, cloud host, or IT contractor has access to systems containing patient data.
  • Staff use email, mobile devices, or messaging apps to discuss patient care.

Administrative safeguards: program-level controls and documented processes

Administrative safeguards are the backbone of the Rule, the policies and processes that decide how everything else gets built and maintained. Risk analysis and risk management come first: you cannot claim compliance without a documented assessment of where ePHI lives and what threatens it.

From there, a working administrative program includes:

  1. Written policies and procedures covering access management, workforce training, and sanctions for violations.
  2. A designated security official responsible for overseeing the program.
  3. Documented workforce training at hiring and on a recurring schedule.
  4. Formal incident response procedures, including who gets notified and when.
  5. Periodic review and update of all policies as systems or staff change.

Pro Tip: Keep every policy, training log, and incident report in one place. When OCR asks for evidence, “we did it” means nothing without a paper trail.

Physical safeguards: protecting facilities, devices, and media that handle ePHI

Physical safeguards cover the tangible side of security: who can walk into a server room, what happens to a retired laptop, and how a workstation is positioned so a waiting room visitor can’t read a screen over someone’s shoulder.

  • Restrict facility access to authorized staff and log visitors near areas with ePHI systems.
  • Position workstations so screens aren’t visible to unauthorized people, and enable auto-lock after inactivity.
  • Wipe or destroy hard drives before disposing of or reselling old computers.
  • Encrypt and track laptops and mobile devices before they leave the building.
  • For small practices, a locked closet for servers and a written device inventory cost little and close obvious gaps.

Technical safeguards: access control, audit controls, and transmission security

This is where most SMB healthcare organizations fall short, and where the December 2024 NPRM signals HHS wants tighter expectations going forward. Access control means every user gets a unique login, multifactor authentication is enforced on anything touching ePHI, and permissions follow the principle of least privilege: nobody sees more than their job requires.

Audit controls are just as critical. Systems need to log access to ePHI, and someone needs to actually review those logs on a set schedule, not just collect them. Encryption rounds out the picture: data at rest on servers and devices, and data in transit over email or between systems, should be encrypted using current standards.

  • Enforce unique user IDs and multi-factor authentication for all ePHI access.
  • Set role-based permissions so access matches job function, nothing more.
  • Log system activity and review logs on a defined cadence, not ad hoc.
  • Encrypt ePHI at rest and in transit, including email containing patient information.

The proposed rule would require vulnerability scanning at least every six months and penetration testing at least once every 12 months, a signal that OCR sees continuous testing, not annual checkboxes, as the coming standard. The current Security Rule remains in effect while that rulemaking proceeds, so acting on this cadence now puts you ahead rather than scrambling later. Our vulnerability assessment guide breaks down what a scan actually looks for.

Risk analysis and risk management: how to run an OCR-ready process

A defensible risk analysis follows a repeatable sequence, and skipping steps is exactly what shows up in enforcement files.

  1. Inventory every system, application, and device that creates, stores, or transmits ePHI.
  2. Identify realistic threats and vulnerabilities for each, from phishing to unpatched software.
  3. Assess likelihood and potential impact for each identified risk.
  4. Build a prioritized remediation plan with owners and deadlines.
  5. Reassess periodically and whenever systems, vendors, or staff change materially.

Our risk assessment checklist walks through this in more detail for teams building the process from scratch.

Pro Tip: Document not just what you found, but what you fixed and when. OCR investigators look for evidence of remediation, not just an audit that sat on a shelf.

Required vs addressable implementation specifications: making defensible choices

The Security Rule sorts specifications into two categories. Required specifications must be implemented, no exceptions. Addressable specifications give you flexibility, but flexibility is not the same as optional: HHS guidance is explicit that you must either implement the specification, implement an equivalent alternative measure, or document in writing why it isn’t reasonable for your organization.

  • Common addressable items include encryption, automatic logoff, and data backup procedures.
  • If you skip an addressable item, your documentation should name the alternative measure and the reasoning.
  • “We didn’t think it applied to us” is not documentation OCR accepts.

The Breach Notification Rule sets clear clocks: breaches affecting 500 or more individuals must be reported to HHS without unreasonable delay and no later than 60 days after discovery, with media notice required in many cases. Smaller breaches can be logged and reported annually, within 60 days of year end.

OCR enforcement actions have produced civil money penalties totaling roughly $143,978,972 across 148 resolved cases, and the recurring findings are strikingly consistent: missing risk analyses and inadequate administrative safeguards.

  • Keep incident logs, remediation records, and training documentation organized and current.
  • Assume any investigation will start with “show me your risk analysis.”

NIST SP 800-66r2 and HHS implementation resources

NIST SP 800-66 Revision 2, finalized in February 2024, maps Security Rule standards to specific NIST Cybersecurity Framework subcategories and SP 800-53r5 controls, turning regulatory language into an actual technical checklist.

  • Use the SP 800-66r2 mappings to select and document controls by standard.
  • HHS publishes factsheets and risk analysis guidance alongside the regulation text itself.
  • Smaller organizations should prioritize access control, encryption, and logging first, then build outward.

What smaller healthcare practices consistently get wrong

Most small practices treat HIPAA as a document they filed once, not a program they maintain. That gap, between paperwork and practice, is where OCR penalties come from and where real breaches happen.

The practices that hold up under scrutiny share a few habits: a current risk analysis, multi-factor authentication everywhere ePHI lives, signed business associate agreements with every vendor, a patching cadence that doesn’t wait for a crisis, and logs someone actually reviews. None of this requires an enterprise budget. It requires consistency, which is the thing most SMBs underestimate until an incident forces the issue.

— Randy Bryan

How tekRESCUE helps healthcare practices meet Security Rule requirements

You didn’t get into health care to become a cybersecurity expert, and the Security Rule doesn’t expect you to build this alone. tekRESCUE’s cybersecurity services include risk assessments built around the same NIST-mapped framework covered above, paired with managed IT services that keep patching, logging, and access controls running without you having to chase them.

NIST assessment and managed IT safeguards

If a breach or suspicious activity hits before your program is ready, our incident response team handles containment and documentation. tekRESCUE offers expertise in HIPAA and NIST-aligned compliance, providing assessments designed to align with OCR expectations. Reach out through our HIPAA compliance page to schedule a risk assessment and find out where your gaps are before an auditor does.

This article is general information, not a substitute for advice from a qualified lawyer. Consult a qualified legal professional about your own circumstances before acting on anything here.

FAQ

What is the new HIPAA rule in 2026?

There is no finalized new rule yet. HHS issued a Notice of Proposed Rulemaking in December 2024 proposing stricter cybersecurity requirements, including regular vulnerability scanning and penetration testing, but the current Security Rule remains in effect while that process continues.

What are the three main rules of HIPAA security?

The Security Rule organizes requirements into administrative safeguards, physical safeguards, and technical safeguards. Administrative safeguards cover policies and training, physical safeguards cover facilities and devices, and technical safeguards cover access control, audit logging, and encryption.

What are the 5 main HIPAA rules?

HIPAA includes several rules: the Privacy Rule, the Security Rule, the Breach Notification Rule, the Enforcement Rule, and the Omnibus Rule, which extended obligations to business associates. Each addresses a different aspect of protecting health information, from patient rights to breach reporting timelines.

What is the HIPAA law in the United States?

HIPAA, the Health Insurance Portability and Accountability Act, is a federal law that sets national standards for protecting patient health information, including how it’s secured electronically under the Security Rule. It applies to covered entities like providers and health plans, along with their business associates.

Previous Post
5 Compliance Essentials for Small Business Website Maintenance Plans

Related Posts

Decorative website compliance title card

5 Compliance Essentials for Small Business Website Maintenance Plans

Decorative AI policy governance title card

Enforceable AI Policy for Employees: Few Pages, NIST and EEOC Aligned

Decorative AI search visibility title card

90 Day AI Search Visibility for SMB Marketers: Measure Mentions First