§164.306
Security Standards — General Rules
HIPAA · 45 CFR Part 164 · Last verified August 2026
Objective
Apply reasonable and appropriate safeguards to protect ePHI confidentiality, integrity, and availability while accounting for organizational risk, size, cost, and technical capability.
Points of focus
- Protect ePHI against reasonably anticipated threats and impermissible uses
- Ensure workforce compliance with Security Rule safeguards
- Review safeguards as environmental or operational conditions change
Implementation notes
Inventory every SaaS path that creates, receives, maintains, or transmits ePHI, document risk-driven safeguard choices, and reassess the design after new integrations, regions, or support workflows. Operationalize protect ephi against reasonably anticipated threats and impermissible uses in ticketing, IdP, or GRC workflows with named owners — not only in a static policy PDF. Retain security rule risk analysis and safeguard rationale with reviewer identity, population scope, dates, and remediation outcomes auditors can sample. A recurring failure mode is that the organization treats flexibility as permission to omit safeguards without analysis Revisit after material architecture, vendor, data-flow, or leadership changes and document the decision.
Audit tip: Sample security rule risk analysis and safeguard rationale with dates and named reviewers. Be ready to walk through how you detect and correct: the organization treats flexibility as permission to omit safeguards without analysis
Evidence auditors typically request:
- Security Rule risk analysis and safeguard rationale
- ePHI system inventory and data-flow diagrams
- Periodic evaluation records following material changes
Common gaps
- The organization treats flexibility as permission to omit safeguards without analysis
- Safeguards cover the application database but exclude logs, queues, and backups containing ePHI
Cross-Framework Mapping
| Framework | Requirement | Implementation note |
|---|---|---|
| HIPAA | §164.306 | This control |
| SOC 2 | CC6.1, CC7.2 | SOC 2 evidence can support the safeguard, but HIPAA scope and Required/Addressable analysis remain distinct. |
| ISO 27001 | A.5.15, A.8.15 | ISO controls offer reusable operational evidence without replacing the Security Rule analysis. |
| GDPR | Article 32 | Article 32 overlaps for ePHI that is also EU personal data, subject to each law's scope. |
Primary sources
- HHS HIPAA Security Rule: 45 CFR Part 164 — Security and Privacy Rules; topic: §164.306