Blog

HIPAA Compliance for Healthcare Practices: Part 3

Posted by Heather Danesh | Jul 30, 2026 | 0 Comments

PART 3 OF 4: The Security Rule and Safeguarding ePHI

Protecting electronic health information in practice.

As practices have moved to electronic records, the Security Rule has become central to HIPAA compliance. It requires practices to protect electronic protected health information through a combination of administrative, physical, and technical safeguards — and to base those safeguards on an honest assessment of their own risks. This post addresses what the Security Rule requires.

The risk analysis

The foundation of Security Rule compliance is a thorough, documented risk analysis: an assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of the practice's ePHI. Many enforcement actions trace directly to the absence of a genuine risk analysis. It is not a one-time exercise; it should be revisited as the practice and its technology change.

Administrative safeguards

These are the policies and workforce measures that manage security:

  • A designated security official responsible for the program.

  • Workforce training and sanctions for violations.

  • Access management so staff reach only the ePHI their roles require.

  • A contingency plan for data backup and disaster recovery.

Physical and technical safeguards

Physical safeguards protect the facilities and devices where ePHI lives — facility access controls, workstation security, and device and media controls. Technical safeguards protect the data itself, through access controls, audit logging, integrity controls, and transmission security such as encryption of ePHI in transit and at rest.

Business associate agreements

Any vendor that creates, receives, maintains, or transmits ePHI on the practice's behalf — billing companies, IT and cloud providers, and many software platforms — must be bound by a business associate agreement. The practice should maintain a current inventory of its business associates and confirm an agreement is in place with each.

How West Coast Health Law Can Help

We help practices meet the Security Rule — conducting and documenting risk analyses, drafting safeguard policies, and putting compliant business associate agreements in place with every vendor that touches ePHI.

West Coast Health Law offers a FREE consultation which you may schedule by clicking the button on our website.

This article is provided for general informational purposes only and does not constitute legal advice or create an attorney-client relationship. Laws change and every practice is different; consult a qualified attorney about your specific circumstances.

About the Author

Heather Danesh

Dr. Heather N. Danesh is a healthcare attorney specializing in practice startups, transitions, regulatory compliance, and corporate healthcare governance. She provides strategic legal support to medical and dental practices, ensuring compliance with healthcare regulations and managing complex legal issues related to mergers, acquisitions, and practice formation.

Comments

There are no comments for this post. Be the first and Add your Comment below.

Leave a Comment