Theme comparison · hipaa-rule-comparison
HIPAA Privacy Rule vs Security Rule
HIPAA Privacy Rule vs Security Rule for health-tech SaaS: compare PHI scope, ePHI safeguards, permitted uses, individual rights, and required evidence.
Frameworks covered: HIPAA
Key differences
| Dimension | Approach A | Approach B |
|---|---|---|
| Primary objective | The Privacy Rule governs uses and disclosures of PHI and gives individuals rights over their information. | The Security Rule requires administrative, physical, and technical safeguards for electronic PHI. |
| Data format | PHI in oral, paper, and electronic form is covered when held by a covered entity or business associate. | Only ePHI is covered, although systems and facilities affecting its confidentiality, integrity, or availability enter scope. |
| Who must comply | Covered entities apply the full rule; business associates receive direct duties plus restrictions through BAAs and permitted-use terms. | Covered entities and business associates must implement Security Rule standards for ePHI within their environments. |
| Core provisions | 45 CFR §§164.502–514 address permitted uses, minimum necessary, authorization, de-identification, marketing, and organizational requirements. | §§164.308, 164.310, and 164.312 define administrative, physical, and technical safeguard standards. |
| Individual rights | §§164.520–528 cover notice, access, amendment, accounting, restrictions, and confidential communications. | The rule does not create a parallel rights catalog; security controls protect systems used to fulfill Privacy Rule rights. |
| Implementation approach | Policies encode who may use or disclose PHI, for what purpose, and what documentation or authorization is required. | Risk analysis drives safeguards; specifications are labeled required or addressable, with documented alternatives or rationale where allowed. |
| Typical evidence | Notices, authorizations, access-request files, disclosure logs, sanctions, minimum-necessary role design, BAAs, and training. | Risk analysis, risk plan, access lists, audit logs, encryption decisions, facility controls, contingency tests, incidents, and evaluations. |
Control overlap
The two rules are interdependent rather than alternatives. Privacy decisions define legitimate users, purposes, and minimum-necessary access; Security Rule controls enforce those decisions in ePHI systems. Workforce access procedures under /controls/hipaa/164-308-a-3 and information-access management under /controls/hipaa/164-308-a-4 support Privacy Rule role restrictions. Unique users and encryption under /controls/hipaa/164-312-a-2-iv, audit controls at /controls/hipaa/164-312-b, authentication at /controls/hipaa/164-312-d, and transmission safeguards at /controls/hipaa/164-312-e-1 create evidence of protection. A security risk analysis does not replace minimum-necessary, authorization, notice, accounting, or individual-access workflows.
Sequencing advice
A health-tech SaaS company should begin with role and data-flow analysis: identify covered-entity or business-associate status, PHI purposes, permitted disclosures, BAA restrictions, and every ePHI system. Translate Privacy Rule minimum-necessary decisions into groups, application roles, support-access paths, and logging requirements, then complete the Security Rule risk analysis and remediation plan. Operate one workforce onboarding, training, sanction, incident, and vendor process with evidence tagged to both rules. Test an individual access request and a suspected breach end to end, including export, identity verification, legal review, system logs, and customer escalation. Do not wait for a SOC 2 audit to close HIPAA obligations.