Skip to content
compliancebase

Theme comparison · hipaa-rule-comparison

HIPAA Privacy Rule vs Security Rule

HIPAA Privacy Rule vs Security Rule for health-tech SaaS: compare PHI scope, ePHI safeguards, permitted uses, individual rights, and required evidence.

Frameworks covered: HIPAA

Key differences

DimensionApproach AApproach B
Primary objectiveThe Privacy Rule governs uses and disclosures of PHI and gives individuals rights over their information.The Security Rule requires administrative, physical, and technical safeguards for electronic PHI.
Data formatPHI in oral, paper, and electronic form is covered when held by a covered entity or business associate.Only ePHI is covered, although systems and facilities affecting its confidentiality, integrity, or availability enter scope.
Who must complyCovered entities apply the full rule; business associates receive direct duties plus restrictions through BAAs and permitted-use terms.Covered entities and business associates must implement Security Rule standards for ePHI within their environments.
Core provisions45 CFR §§164.502–514 address permitted uses, minimum necessary, authorization, de-identification, marketing, and organizational requirements.§§164.308, 164.310, and 164.312 define administrative, physical, and technical safeguard standards.
Individual rights§§164.520–528 cover notice, access, amendment, accounting, restrictions, and confidential communications.The rule does not create a parallel rights catalog; security controls protect systems used to fulfill Privacy Rule rights.
Implementation approachPolicies encode who may use or disclose PHI, for what purpose, and what documentation or authorization is required.Risk analysis drives safeguards; specifications are labeled required or addressable, with documented alternatives or rationale where allowed.
Typical evidenceNotices, authorizations, access-request files, disclosure logs, sanctions, minimum-necessary role design, BAAs, and training.Risk analysis, risk plan, access lists, audit logs, encryption decisions, facility controls, contingency tests, incidents, and evaluations.

Control overlap

The two rules are interdependent rather than alternatives. Privacy decisions define legitimate users, purposes, and minimum-necessary access; Security Rule controls enforce those decisions in ePHI systems. Workforce access procedures under /controls/hipaa/164-308-a-3 and information-access management under /controls/hipaa/164-308-a-4 support Privacy Rule role restrictions. Unique users and encryption under /controls/hipaa/164-312-a-2-iv, audit controls at /controls/hipaa/164-312-b, authentication at /controls/hipaa/164-312-d, and transmission safeguards at /controls/hipaa/164-312-e-1 create evidence of protection. A security risk analysis does not replace minimum-necessary, authorization, notice, accounting, or individual-access workflows.

Sequencing advice

A health-tech SaaS company should begin with role and data-flow analysis: identify covered-entity or business-associate status, PHI purposes, permitted disclosures, BAA restrictions, and every ePHI system. Translate Privacy Rule minimum-necessary decisions into groups, application roles, support-access paths, and logging requirements, then complete the Security Rule risk analysis and remediation plan. Operate one workforce onboarding, training, sanction, incident, and vendor process with evidence tagged to both rules. Test an individual access request and a suspected breach end to end, including export, identity verification, legal review, system logs, and customer escalation. Do not wait for a SOC 2 audit to close HIPAA obligations.

Frequently Asked Questions

No. The Privacy Rule covers PHI in any medium and governs use, disclosure, and individual rights. The Security Rule is the ePHI safeguard layer; most regulated organizations need coordinated compliance with both.

The Security Rule does not apply to paper-only PHI as data, but systems controlling facilities, scanning, storage, or workforce access may still affect ePHI scope. Privacy Rule protections continue regardless of format.

Addressable means the organization must assess reasonableness and appropriateness and document implementation, an equivalent alternative, or a permitted rationale. It is not a blanket option to ignore the specification.

Minimum necessary starts as a Privacy Rule determination about appropriate access and disclosure. IAM roles, approval workflows, periodic reviews, and audit logs then implement and evidence that determination under the Security Rule.

A BAA should authorize and restrict PHI handling, require safeguards and incident reporting, and flow obligations to subcontractors. It supports both rules but does not replace the business associate’s own policies and controls.

Framework versions referenced in this page:

  • HIPAA45 CFR Part 164

Last verified: August 2026 · Primary sources linked above