Find & Ask Federal › this rule

45 CFR 164.312 — HIPAA Security Rule: Technical Safeguards

FederalregulationU.S. Department of Health and Human Services (HHS), Office for Civil Rights· effective 2005-04-20

What this rule requires your agency to do

  • 1Assign a unique name and/or number for identifying and tracking user identity, and establish emergency access procedures for obtaining ePHI during an emergency (required) (§ 164.312(a)(2)(i)-(ii)).(45 CFR 164.312 — HIPAA Security Rule: Technical Safeguards)
  • 2Implement technical security measures to guard against unauthorized access to ePHI transmitted over an electronic communications network (§ 164.312(e)(1)).(45 CFR 164.312 — HIPAA Security Rule: Technical Safeguards)
  • 3Implement integrity controls to ensure transmitted ePHI is not improperly modified without detection, and a mechanism to encrypt ePHI whenever deemed appropriate (addressable) (§ 164.312(e)(2)(i)-(ii)).(45 CFR 164.312 — HIPAA Security Rule: Technical Safeguards)
  • 4Implement procedures to verify that a person or entity seeking access to ePHI is the one claimed (§ 164.312(d)).(45 CFR 164.312 — HIPAA Security Rule: Technical Safeguards)
  • 5Implement policies and procedures to protect ePHI from improper alteration or destruction, and implement mechanisms to corroborate that ePHI has not been altered or destroyed in an unauthorized manner (addressable) (§ 164.312(c)(1)-(2)).(45 CFR 164.312 — HIPAA Security Rule: Technical Safeguards)
  • 6Implement technical policies and procedures for electronic information systems maintaining ePHI that allow access only to persons or software programs granted access rights under § 164.308(a)(4) (§ 164.312(a)(1)).(45 CFR 164.312 — HIPAA Security Rule: Technical Safeguards)
  • 7Implement electronic procedures that terminate a session after a predetermined time of inactivity and a mechanism to encrypt and decrypt ePHI (addressable) (§ 164.312(a)(2)(iii)-(iv)).(45 CFR 164.312 — HIPAA Security Rule: Technical Safeguards)
  • 8Implement hardware, software, and/or procedural mechanisms that record and examine activity in information systems containing or using ePHI (§ 164.312(b)).(45 CFR 164.312 — HIPAA Security Rule: Technical Safeguards)

Applies to: cross-cutting

This section requires covered entities and business associates to implement technical safeguards for electronic protected health information (ePHI). It mandates access controls, audit controls, integrity protections, person or entity authentication, and transmission security to guard ePHI in information systems and during electronic transmission.

Regulatory information, not legal advice — always confirm against the cited official source. Verification reduces error; it does not certify compliance.