Skip to content
Mandatory · lawUS HHSUSv45 CFR 164

HIPAA

HIPAA Security Rule (45 CFR Part 164, Subpart C)

The US rule setting administrative, physical and technical safeguards to protect electronic protected health information (ePHI). Combined with the Breach Notification Rule, it governs healthcare data security.

Official source ↗

Who it applies to

HealthcareUSProcesses PHI

US healthcare 'covered entities' (health plans, healthcare clearinghouses and most healthcare providers) and their 'business associates' that create, receive, maintain or transmit electronic protected health information (ePHI).