Who Must Comply with the Security Rule

Who Must Comply with the Security Rule

If you’re trying to figure out who must comply with the security rule, here’s the quickest, most useful answer: it applies to regulated entities—mainly HIPAA covered entities and business associates—when they handle electronic protected health information (ePHI) as part of HIPAA-regulated activity. Covered entities (and regulated entities in general) must follow every Security Rule standard, not just the parts that seem relevant.

From there, the question becomes more practical: are you a covered entity or a business associate, and do you work with ePHI?

Who must comply with the HIPAA Security Rule

The HIPAA Security Rule is the HIPAA rule focused on keeping electronic health information secure. It’s designed to protect electronically stored protected health information, usually called ePHI.

So, the eligibility question is pretty direct:

  • Who must comply? The regulated entities identified under HIPAA—especially covered entities and business associates—when they handle ePHI.
  • When does it kick in? When the entity is involved in HIPAA-regulated activity and ePHI is part of what they create, receive, maintain, or transmit.
  • How much do they have to do? Regulated entities are required to comply with every Security Rule standard. You don’t get to pick and choose.

People also talk about “PHI rules” more broadly, and that’s where confusion shows up. The Security Rule is specifically about electronic PHI (ePHI). It isn’t the same thing as every other HIPAA obligation that may apply to PHI in other formats.

Covered entity vs. business associate: a simpler way to think about it

To make “who must comply with the security rule” easier, sort yourself into one of these buckets:

  1. Are you a HIPAA covered entity?

If yes, the Security Rule applies when you handle ePHI in HIPAA-regulated transactions.

  1. If you’re not a covered entity, are you a business associate?

If yes, the Security Rule applies when you handle ePHI as part of providing services to a covered entity.

  1. If neither of those fits, you’re more likely outside the core Security Rule compliance duty. You might still have other contractual or privacy duties, but the Security Rule obligation described here is tied to being a regulated entity handling ePHI.

Covered entities subject to the Security Rule

Covered entities are the “core” group that HIPAA regulates. For Security Rule purposes, the big idea is simple: if you’re a covered entity and you handle ePHI as part of HIPAA-regulated transactions, you must comply with the Security Rule.

In plain terms, covered entities typically include organizations in the healthcare space that deal with health information in ways HIPAA regulates. The Security Rule doesn’t protect health information “in general.” It protects the electronic version—ePHI.

Also, remember the strict part: regulated entities must comply with every Security Rule standard. Even if you think your risk is low or your setup is already strong, you’re still expected to meet the full set of required standards.

How business associates fit into HIPAA compliance

A business associate is an entity that works with a covered entity and supports functions that involve protected health information. The key point for your decision-making is this:

  • Business associates must comply with Security Rule requirements when they handle ePHI.

So the framework looks like this:

  • Covered entity: responsible for Security Rule compliance for its own ePHI handling.
  • Business associate: responsible for Security Rule compliance for its own ePHI handling while providing services to the covered entity.

You’ll often see this come up in contracts, but the compliance duty still depends on whether the organization is a regulated entity and whether it works with ePHI.

Why electronically stored PHI, or ePHI, is central to the rule

The Security Rule isn’t built around all protected health information forms. It’s built around electronic protected health information—ePHI.

That matters because it narrows what the Security Rule is “about”:

  • If the information is stored or handled electronically, it falls under the Security Rule.
  • If you only deal with health information in ways that aren’t electronic (in the sense of ePHI), that does not automatically make you subject to the specific Security Rule obligation described here.

When you ask who must comply with the HIPAA security rule, the ePHI part is the anchor.

The three categories of Security Rule safeguards

The Security Rule groups its requirements into three safeguard categories. They cover different angles of security: how you manage security, where the equipment is, and how data is protected in systems.

1) Administrative safeguards under the Security Rule

These are the “people and process” protections. They cover how the organization manages security risk and handles security-related tasks day to day.

2) Physical safeguards under the Security Rule

These focus on the “where.” That includes controls around physical access to equipment and storage areas that involve ePHI.

3) Technical safeguards under the Security Rule

These focus on “how systems protect ePHI.” This includes technology controls that help keep electronic information secure.

If you’re mapping requirements internally, these categories can also help you bring the right teams in—leadership and policies (administrative), facility and access (physical), and IT system controls (technical).

What every Security Rule standard means in practice

One compliance point you can’t ignore: regulated entities are required to comply with every Security Rule standard.

That doesn’t mean you have to copy-paste the same system or process as another organization. It means the organization has to address the required standards and meet the rule’s expectations across the three safeguard categories.

Here’s what “every standard” usually implies in a practical sense:

  • You need coverage across administrative, physical, and technical safeguards.
  • Your security approach can’t be only partial. If a standard requires an administrative protection and you focus only on technical controls, you leave gaps.
  • You should be able to show your safeguards align with the Security Rule standards, even if you’re not ready for an audit tomorrow.

This is why the covered entity vs. business associate distinction matters. Each regulated entity is responsible for its own ePHI handling, and each has to meet the full set of Security Rule expectations.

Are any organizations exempt from the Security Rule?

Some people come across the phrase “exempt,” so it’s worth being careful here.

The research notes mention an apparent small-health-plan exception tied to Security Rule compliance timing. That’s generally discussed as a limited “small plan” carve-out, not a general exemption that applies across the board.

What you should take from that, without expanding beyond the source:

  • There is an exception mentioned for small health plans (in terms of compliance timing).
  • The research does not support turning that into a broad exemption for other types of organizations.

So if you’re asking who must comply with the security rule in healthcare, the safe, research-supported answer remains: regulated entities must comply with the Security Rule standards when they handle ePHI, with the note that small health plans are the group where an exception is described.

If you think you might fall into that small-health-plan category, confirm it with the right HIPAA compliance professional before relying on any “exception” assumption.

How to check whether your organization is covered

Here’s a concise decision path you can actually use. You don’t need to be a lawyer—just answer the questions in order.

Step 1: Are you a covered entity or a business associate?

  • If you’re a HIPAA covered entity, you’re in the main group.
  • If you’re not, check whether you function as a business associate.

If neither label fits, you may not have the Security Rule compliance duty described here. You might still have other obligations through contracts or other privacy rules.

Step 2: Do you handle **ePHI**?

Ask this in plain terms: do you store, receive, create, or transmit health information electronically that is considered protected health information?

If yes, you’re in the zone where the Security Rule is built to apply.

Step 3: Is it part of HIPAA-regulated transactions or activity?

The Security Rule is described as mandatory for covered entities that handle ePHI as part of HIPAA-regulated transactions. Business associates are included as key regulated entities when they handle ePHI in that support role.

Step 4: Plan for “every standard” expectations

Step 4

If you’re covered, you must comply with every Security Rule standard. That’s where many teams get surprised. Security Rule compliance isn’t only about the biggest obvious controls—it’s about having an organized set of safeguards that spans administrative, physical, and technical categories.

A quick checklist you can start with

  • [ ] We are a covered entity or a business associate
  • [ ] We handle ePHI (electronically stored protected health information)
  • [ ] Our work touches HIPAA-regulated activity
  • [ ] We can map controls across administrative, physical, and technical safeguard categories
  • [ ] We’re treating compliance as “all standards,” not “some items”

If you get stuck on any of those, it’s a good sign you need a closer look at your role and your data flows.

A few common questions

Who must comply with the security rule?

The research points to regulated entities, including HIPAA covered entities and business associates, when they handle ePHI. In other words: if you’re one of those groups and you work with electronic protected health information as part of HIPAA-related activity, the Security Rule is the rule you follow.

Who must comply with the HIPAA security rule?

Again, the main groups are HIPAA covered entities and business associates. The rule is focused on ePHI, and regulated entities must comply with every Security Rule standard.

What are the HIPAA Security Rule requirements?

What are the HIPAA Security Rule requirements?

The requirements are organized into three safeguard categories:

  • Administrative safeguards under the Security Rule
  • Physical safeguards
  • Technical safeguards

Does the security rule apply to all PHI?

Based on the research provided, the Security Rule is described as protecting electronically stored protected health information (ePHI). It doesn’t establish that the Security Rule applies to every form of PHI in every format.

Does the rule exempt anyone?

The research notes mention an exception for small health plans (described as an “apparent small-health-plan exception” in relation to compliance timing). It does not support treating that as an exemption for other organization types.

Before you rely on your final answer about eligibility, verify whether you’re a covered entity or a business associate with a qualified HIPAA compliance professional. That’s the safest way to make sure you’re applying the Security Rule correctly to your specific situation.

DH

Written by Dennis Haymon

Dennis Haymon is a security professional and manager at Safe & Sound Security LLC. With experience in security guard and patrol services, he shares practical information about protecting homes, businesses, and properties. Through Safe & Sound Security LLC, Dennis and the team provide security-focused guidance designed to help individuals and businesses better understand their security needs and available protection options.