Skip to content
compliancebase
HIPAA164.306 — Security Standards — General Rules

§164.306

Security Standards — General Rules

HIPAA · 45 CFR Part 164 · Last verified August 2026

Objective

Apply reasonable and appropriate safeguards to protect ePHI confidentiality, integrity, and availability while accounting for organizational risk, size, cost, and technical capability.

Points of focus

  • Protect ePHI against reasonably anticipated threats and impermissible uses
  • Ensure workforce compliance with Security Rule safeguards
  • Review safeguards as environmental or operational conditions change

Implementation notes

Inventory every SaaS path that creates, receives, maintains, or transmits ePHI, document risk-driven safeguard choices, and reassess the design after new integrations, regions, or support workflows. Operationalize protect ephi against reasonably anticipated threats and impermissible uses in ticketing, IdP, or GRC workflows with named owners — not only in a static policy PDF. Retain security rule risk analysis and safeguard rationale with reviewer identity, population scope, dates, and remediation outcomes auditors can sample. A recurring failure mode is that the organization treats flexibility as permission to omit safeguards without analysis Revisit after material architecture, vendor, data-flow, or leadership changes and document the decision.

Audit tip: Sample security rule risk analysis and safeguard rationale with dates and named reviewers. Be ready to walk through how you detect and correct: the organization treats flexibility as permission to omit safeguards without analysis

Evidence auditors typically request:

  • Security Rule risk analysis and safeguard rationale
  • ePHI system inventory and data-flow diagrams
  • Periodic evaluation records following material changes

Common gaps

  • The organization treats flexibility as permission to omit safeguards without analysis
  • Safeguards cover the application database but exclude logs, queues, and backups containing ePHI

Cross-Framework Mapping

FrameworkRequirementImplementation note
HIPAA§164.306This control
SOC 2CC6.1, CC7.2SOC 2 evidence can support the safeguard, but HIPAA scope and Required/Addressable analysis remain distinct.
ISO 27001A.5.15, A.8.15ISO controls offer reusable operational evidence without replacing the Security Rule analysis.
GDPRArticle 32Article 32 overlaps for ePHI that is also EU personal data, subject to each law's scope.

Primary sources

Frequently Asked Questions

Security Standards — General Rules applies to the systems and commitments in your Security Rule scope. Translate the requirement into concrete operating workflows — protect ephi against reasonably anticipated threats and impermissible uses — with evidence stored where auditors and customers can sample it.

Lead with security rule risk analysis and safeguard rationale and pair it with ephi system inventory and data-flow diagrams. Samples should show who performed the control, when, against which population, and what changed as a result.

Teams often fail because the organization treats flexibility as permission to omit safeguards without analysis Close the loop with dated operating records and test the control on a realistic production path.

Control operation can often be shared across SOC 2, ISO 27001, GDPR, and HIPAA — but each framework uses different vocabulary and accountability. Maintain an explicit crosswalk rather than assuming equivalence.

Review at least annually and after material product, vendor, or data-flow changes. High-risk or privileged paths may need quarterly sampling even when the criterion does not prescribe a cadence.

Framework versions referenced in this page:

  • HIPAA45 CFR Part 164

Last verified: August 2026 · Primary sources linked above