Administrative, Physical, and Technical Safeguards

The HIPAA Security Rule sets standards for how to protect electronic PHI (ePHI) — any protected information created, stored, or shared using electronic systems (like EHRs, emails, or cloud services).

It requires that covered entities and business associates use three types of safeguards:


1. Administrative Safeguards

These are policies, procedures, and training that manage the security of ePHI.

Examples:

  • Assigning a HIPAA security officer

  • Conducting annual risk assessments

  • Creating access policies (who can access what)

  • Regular HIPAA training for all staff


2. Physical Safeguards

This refers to the protection of physical spaces and devices where ePHI is stored or accessed.

Examples:

  • Locked doors to file rooms or server rooms

  • Security cameras

  • Restricting access to computers

  • Logging off workstations when unattended

  • Securing laptops and USB drives


3. Technical Safeguards

These protect electronic systems and data through technology.

Examples:

  • Password protection and user authentication

  • Data encryption (especially when sending ePHI)

  • Automatic logoff systems

  • Firewalls and antivirus software


Bottom line: It takes both people and systems to protect ePHI. Even if you’re not in IT, you still play a part — like using strong passwords and logging off when you step away.