HomePoliciesInformation securityHIPAA Security Policies and Procedures

Policy  required document  Information security

HIPAA Security Policies and Procedures

The HIPAA Security Rule requires every covered entity and business associate to hold written policies and procedures that implement its administrative, physical and technical safeguards for electronic protected health information.

Section 164.316 is the documentation clause: the policies must be in writing, any action or assessment the rule requires must be recorded, the records must be available to the people who carry them out, and everything is kept six years and reviewed periodically.

The document set is larger than the privacy manual because most Security Rule standards produce both a policy and an operating record. A risk analysis policy produces a risk analysis report. A contingency plan policy produces a tested backup and recovery plan.

A sanction policy produces sanction records. OCR settlements in the last decade name a missing or stale risk analysis and missing policies more often than any technical failure.

Also called: HIPAA security manual, Security Rule policies, ePHI security policies
AI-compiled
Share
Sponsored
Policy  Acknowledgment  Proof
AcknowledgedSecurity policy v5by name, on record
164.316 Handledwith AllyMatter
Secure It the Modern WayYour security policies, acknowledged by everyone with a login
01
Approve it, lock the version
Non-author approval, obsolete copies blocked
02
Every user on record
Who read which version, and when
03
Open the binder before OCR asks
From $29/mo, 20 editors, unlimited staff (published)

Obligation ledger

Who requires it, and what each one says.

SourceApplies whenWhat it requiresStatus
HIPAA Security Rule, policies and procedures
45 CFR 164.316(a)
You are a covered entity or business associateImplement reasonable and appropriate policies and procedures to comply with the Security Rule, sized to the flexibility factors in 164.306(b). Legally required.Mandatory
HIPAA Security Rule, documentation
45 CFR 164.316(b)
AlwaysKeep the policies in written or electronic form, record every required action or assessment, retain six years, make available to responsible staff, review periodically and update as needed. Legally required.Mandatory
HIPAA Security Rule, security awareness and training
45 CFR 164.308(a)(5)
AlwaysA security awareness and training program for all workforce members, with addressable specifications for reminders, malware protection, log-in monitoring and password management. Legally required; the specifications are addressable, the standard is not.Mandatory
HIPAA Security Rule, sanction policy
45 CFR 164.308(a)(1)(ii)(C)
AlwaysApply appropriate sanctions against workforce members who fail to comply with the security policies. Legally required.Mandatory
HIPAA Security Rule NPRM
90 FR 898 (Jan 6, 2025), proposed
If finalizedWould make most addressable specifications required, add written asset inventory and network map, annual compliance audits, MFA and encryption mandates. Not in force; HHS listed final action for July 2027 on its regulatory agenda. Verify.Market

Required sections

  • Designated security official (164.308(a)(2))
  • Security management process: risk analysis, risk management, sanction policy, information system activity review (164.308(a)(1))
  • Workforce security: authorization, clearance, termination procedures (164.308(a)(3))
  • Information access management (164.308(a)(4))
  • Security awareness and training program (164.308(a)(5))
  • Security incident procedures (164.308(a)(6))
  • Contingency plan: data backup, disaster recovery, emergency mode operation, testing, criticality analysis (164.308(a)(7))
  • Periodic evaluation of the security program (164.308(a)(8))
  • Business associate contracts (164.308(b), 164.314)
  • Physical safeguards: facility access, workstation use and security, device and media controls (164.310)
  • Technical safeguards: access control, audit controls, integrity, authentication, transmission security (164.312)
  • Documentation, availability to staff, six-year retention, periodic review (164.316)
  • Breach notification procedures (164.400 to 164.414)

What the examiner asks for

Written planThe full security policy set with effective dates and approval, plus superseded versions for six years. vCISOs, HIPAA consultants and law firms write it; policy tools hold the versions
AttestationSecurity awareness training completions per workforce member; acknowledgment of acceptable-use and sanction policies. Policy tools, LMS platforms, security awareness vendors
Operational recordsThe current risk analysis and risk management plan, contingency plan test results, incident log, system activity reviews, business associate agreements, sanction records. The entity, MSPs, compliance automation platforms
Technical controlsAccess control configuration, audit logs, encryption status, backup verification, MFA enforcement evidence. MSPs, MSSPs, compliance automation platforms

What changed

Change log.

2026-07HHS regulatory agenda lists the Security Rule final rule as a long-term action with July 2027 as the anticipated date. Verify.
2025-03-07Comment period closed on the Security Rule NPRM.
2025-01-06Security Rule NPRM published in the Federal Register (90 FR 898).
2013-03-26Omnibus Rule extended direct Security Rule liability to business associates. Verify.

Frameworks

Where this document is required.

Who looks at it

Where this document gets checked.

No one certifies a document like this on its own. It is read during the audits and inspections below, and by the agency behind each rule.

Where it is looked atWho looks at it
42 CFR Part 2HHS Office for Civil Rights investigates complaints and breaches and can impose civil money penalties; the Department of Justice can bring criminal cases. State licensing surveys and accreditors (CARF, Joint Commission) check Part 2 practices as part of broader surveys. There is no certification
HIPAAGovernment enforcement only. OCR investigates complaints and breach reports, conducts compliance reviews and periodic audits, and can impose civil money penalties or resolution agreements; state attorneys general may also sue under HITECH. There is no HIPAA certification recognized by HHS; third-party assessments (including HITRUST) are voluntary

Who helps write it

Consultants.

Firms that name these standards in their own material.

No firm has claimed a listing for this document yet. Claim yours →

Need a hand implementing it?

Find a Consultant for HIPAA Security Policies and Procedures

Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.

From the publisher

Manage This Document in AllyMatter

Route it for approval, keep every version, and record a named acknowledgment from everyone who has to read it.

See how AllyMatter works From $29/mo, 20 editors, unlimited staff

Questions

What people ask.

Is the January 2025 proposed rule in force?

No. As of this page's last check, HHS lists final action for 2027 and no compliance date exists. Write to the current text and track the proposal; do not document controls you have not implemented.

What does OCR ask for first?

The risk analysis, the policies in force on the date of the incident, and proof of training. Published resolution agreements show the pattern. The risk analysis is the one most often missing or out of date.

Can one document cover privacy and security?

Yes, if each Security Rule standard is addressed. Most organizations keep separate manuals because the audiences differ: privacy policies go to all staff, many security procedures go only to IT.

Do business associates need the whole set?

Yes for the Security Rule. A business associate is directly liable for 164.308 through 164.316 in full.

Who owns this site?

AllyMatter, a policy management tool that may appear in listings on this page. It is labeled every time, excluded from picks, and receives nothing from the matching form unless you name it.

About this data

Pages on this site are compiled with AI from two or more linked sources, rewritten in our words, and reviewed by people in stages. Each record shows its stage and date. Nothing here is legal, audit or tax advice, and policyandcompliance.com accepts no responsibility for errors or for decisions made on it. Read the source, then decide.
How we compile and verify →

Think something is wrong?

[email protected]
Tell us the page and what you found. We check it against the source and fix it.
Corrections log →

Want to advertise here?

[email protected]
A primary ad and a secondary placement, flat fee. Buying one changes nothing else on the page.