Policy required document Information security
HIPAA Security Policies and Procedures
The HIPAA Security Rule requires every covered entity and business associate to hold written policies and procedures that implement its administrative, physical and technical safeguards for electronic protected health information.
Section 164.316 is the documentation clause: the policies must be in writing, any action or assessment the rule requires must be recorded, the records must be available to the people who carry them out, and everything is kept six years and reviewed periodically.
The document set is larger than the privacy manual because most Security Rule standards produce both a policy and an operating record. A risk analysis policy produces a risk analysis report. A contingency plan policy produces a tested backup and recovery plan.
A sanction policy produces sanction records. OCR settlements in the last decade name a missing or stale risk analysis and missing policies more often than any technical failure.
Obligation ledger
Who requires it, and what each one says.
| Source | Applies when | What it requires | Status |
|---|---|---|---|
| HIPAA Security Rule, policies and procedures 45 CFR 164.316(a) | You are a covered entity or business associate | Implement reasonable and appropriate policies and procedures to comply with the Security Rule, sized to the flexibility factors in 164.306(b). Legally required. | Mandatory |
| HIPAA Security Rule, documentation 45 CFR 164.316(b) | Always | Keep the policies in written or electronic form, record every required action or assessment, retain six years, make available to responsible staff, review periodically and update as needed. Legally required. | Mandatory |
| HIPAA Security Rule, security awareness and training 45 CFR 164.308(a)(5) | Always | A security awareness and training program for all workforce members, with addressable specifications for reminders, malware protection, log-in monitoring and password management. Legally required; the specifications are addressable, the standard is not. | Mandatory |
| HIPAA Security Rule, sanction policy 45 CFR 164.308(a)(1)(ii)(C) | Always | Apply appropriate sanctions against workforce members who fail to comply with the security policies. Legally required. | Mandatory |
| HIPAA Security Rule NPRM 90 FR 898 (Jan 6, 2025), proposed | If finalized | Would make most addressable specifications required, add written asset inventory and network map, annual compliance audits, MFA and encryption mandates. Not in force; HHS listed final action for July 2027 on its regulatory agenda. Verify. | Market |
Required sections
- Designated security official (164.308(a)(2))
- Security management process: risk analysis, risk management, sanction policy, information system activity review (164.308(a)(1))
- Workforce security: authorization, clearance, termination procedures (164.308(a)(3))
- Information access management (164.308(a)(4))
- Security awareness and training program (164.308(a)(5))
- Security incident procedures (164.308(a)(6))
- Contingency plan: data backup, disaster recovery, emergency mode operation, testing, criticality analysis (164.308(a)(7))
- Periodic evaluation of the security program (164.308(a)(8))
- Business associate contracts (164.308(b), 164.314)
- Physical safeguards: facility access, workstation use and security, device and media controls (164.310)
- Technical safeguards: access control, audit controls, integrity, authentication, transmission security (164.312)
- Documentation, availability to staff, six-year retention, periodic review (164.316)
- Breach notification procedures (164.400 to 164.414)
What the examiner asks for
What changed
Change log.
Frameworks
Where this document is required.
Who looks at it
Where this document gets checked.
No one certifies a document like this on its own. It is read during the audits and inspections below, and by the agency behind each rule.
| Where it is looked at | Who looks at it |
|---|---|
| 42 CFR Part 2 | HHS Office for Civil Rights investigates complaints and breaches and can impose civil money penalties; the Department of Justice can bring criminal cases. State licensing surveys and accreditors (CARF, Joint Commission) check Part 2 practices as part of broader surveys. There is no certification |
| HIPAA | Government enforcement only. OCR investigates complaints and breach reports, conducts compliance reviews and periodic audits, and can impose civil money penalties or resolution agreements; state attorneys general may also sue under HITECH. There is no HIPAA certification recognized by HHS; third-party assessments (including HITRUST) are voluntary |
Who helps write it
Consultants.
Firms that name these standards in their own material.
No firm has claimed a listing for this document yet. Claim yours →
Where it lives
Software.
Tools that hold documents like this one and record who has read them.
Need a hand implementing it?
Find a Consultant for HIPAA Security Policies and Procedures
Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.
From the publisher
Manage This Document in AllyMatter
Route it for approval, keep every version, and record a named acknowledgment from everyone who has to read it.
Questions
What people ask.
Is the January 2025 proposed rule in force?
No. As of this page's last check, HHS lists final action for 2027 and no compliance date exists. Write to the current text and track the proposal; do not document controls you have not implemented.
What does OCR ask for first?
The risk analysis, the policies in force on the date of the incident, and proof of training. Published resolution agreements show the pattern. The risk analysis is the one most often missing or out of date.
Can one document cover privacy and security?
Yes, if each Security Rule standard is addressed. Most organizations keep separate manuals because the audiences differ: privacy policies go to all staff, many security procedures go only to IT.
Do business associates need the whole set?
Yes for the Security Rule. A business associate is directly liable for 164.308 through 164.316 in full.
Who owns this site?
AllyMatter, a policy management tool that may appear in listings on this page. It is labeled every time, excluded from picks, and receives nothing from the matching form unless you name it.