Skip to main content
U.S. flag

An official website of the United States government

Here’s how you know

Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

HTTPS

Secure .gov websites use HTTPS
A lock (LockA locked padlock) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Freedom 250 banner logo Join HHS in Celebrating Freedom 250
    • About HHS

      HHS is a U.S. executive department that touches the lives of nearly all Americans by protecting your rights, research, food safety, health care, aging, and much more.

      Explore About HHS
    • About the Department
      • Leadership
      • HHS Divisions
      • Organizational Chart
      • Priorities
      • Budget in Brief
      • Contact Us
    • Press Room
      • Press Releases
      • Request for Comment
      • Request for Interview
      • Connect on Social Media
      • HHS Live
      • Podcasts
    • Careers
      • Working at HHS
      • Opportunities for Attorneys
      • Join the Health Workforce
      • I am HHS
      • New Employee Orientation
      • Transportation Services
    • Standards and Compliance
      • Gold Standard Science
      • Accessibility
      • Plain Writing
      • Digital Communications Standards
      • Records Management
    • Accountability and Transparency
      • Freedom of Information Act (FOIA)
      • Open Government
      • No Fear Act
      • Privacy at HHS
  • RealFood.gov
  • MAHA
    • Programs & Services

      HHS is responsible for public health, health care, and human/social services for the United States of America. This includes administering over 100 programs and services.

      Explore Programs & Services
    • Health Care
      • Find a Health Center
      • Find an Indian Health Service Facility
      • Find Support for Mental Health, Drugs, or Alcohol
      • Find a Cancer Center
      • Dental Care Options
      • Telehealth
    • Health Insurance
      • Medicare – 65+ or With Disability
      • Medicaid - Low-Income, With Disability, or Pregnant
      • Children’s Health Insurance Programs (CHIP)
      • Find Health Insurance Coverage
      • Insurance Help for Mental Health and Substance Use
      • No Surprise Medicals Bills
    • Social Services
      • Programs for Children and Families
      • Programs for People with Disabilities
      • Programs for Older Adults
      • Resources for Caregivers
    • Public Health and Prevention
      • Emergency Preparedness and Response
      • Healthy Lifestyle
      • Mental Health and Substance Use
      • Food Safety and Nutrition
      • Drug and Product Safety
    • Health Research and Information
      • National Library of Medicine
      • Surgeon General Reports
      • Health Data
      • National Center for Health Statistics
      • Medline Plus
      • Clinical Research Studies
      • Volunteering to Participate in Research
    • Laws & Regulations

      HHS protects and helps you understand the laws and regulations, also known as "rules," that govern the nation. You also have the power to voice your opinion on these laws and regulations.

      Explore Laws & Regulations
    • Regulatory Information
      • What is a Rule?
      • Find Rules by Division
      • Comment on Open Rules
      • Suggest Deregulatory Actions
      • Understand Key Federal Laws
    • Civil Rights
      • Your Civil Rights
      • Civil Rights Laws Enforced by HHS
      • Health Information Privacy
      • Substance Use Disorder Patient Confidentiality
      • Conscience and Religious Freedom
    • Laws and Regulations by Topic
      • HIPAA Privacy Rule
      • Health Insurance Protections
      • Health IT Legislation
      • Food and Drug Safety
      • Public Health Emergencies
    • Human Research Protections
      • The Belmont Report
      • Regulations, Policy, and Guidance
      • Human Subjects Regulations (45 CFR 46)
      • Register IRBs and Obtain FWAs
      • Trainings, Tutorials, and Workshops
      • International Research
    • Complaints and Appeals
      • File a Medicare Complaint
      • File a HIPAA Complaint
      • File a Civil Rights Complaint
      • Appeal an Insurance Company Decision
      • Report Fraud, Waste, and Abuse to OIG
      • Report a Problem to the FDA
      • Report a Tip on the Chemical and Surgical Mutilation of Children
    • Grants & Contracts

      HHS gives the most money in grants of any federal agency in the U.S. Find out about our grants and how your organization can apply for them. We also provide information on how you can work with us and our support of small businesses.

      Explore Grants & Contracts
    • Grants
      • Get Ready for Grants Management
      • Grant Policies and Regulations
      • Research Grants and Funding from NIH
      • Search Grants.gov
      • Avoid Grant Scams
      • Contact HHS Grant Officials
    • Contracts
      • Get Ready to Do Business with HHS
      • Programs for Businesses
      • Contract Policies and Regulations
      • Search Opportunities on SAM.gov
      • Contact HHS Contracting Managers
    • Small Business
      • Contract Opportunities
      • Small Business Programs
      • Small Business Resources
      • Contact Small Business Staff
    • Radical Transparency

      HHS protects and helps you understand the laws and regulations, also known as "rules," that govern the nation. You also have the power to voice your opinion on these laws and regulations.

      Explore Radical Transparency
    • CDC’s ACIP Conflicts of Interest
    • Ending Anti-Semitism on College Campuses
    • Ending Wasteful Spending
    • Keeping Food Ingredients Safe
    • Chemical Contaminants Transparency Tool
  • HIPAA for Individuals
  • Filing a Complaint
  • HIPAA for Professionals
  • Newsroom
Breadcrumb
  1. HHS
  2. HIPAA Home
  3. For Professionals
  4. The Security Rule
  5. Security Rule Guidance Material
  • HIPAA for Professionals
  • Regulatory Initiatives
  • Privacy
    • Summary of the Privacy Rule
    • Guidance
    • Combined Text of All Rules
    • HIPAA Related Links
  • Security
    • Security Rule NPRM
    • Summary of the Security Rule
    • Security Guidance
    • Cyber Security Guidance
  • Breach Notification
    • Breach Reporting
    • Guidance
    • Reports to Congress
    • Regulation History
  • Compliance & Enforcement
    • Enforcement Rule
    • Enforcement Process
    • Enforcement Data
    • Resolution Agreements
    • Case Examples
    • Audit
    • Reports to Congress
    • State Attorneys General
  • Special Topics
    • Parental Access
    • Mental and Behavioral Health
    • Change Healthcare Cybersecurity Incident FAQs
    • HIPAA and COVID-19
    • HIPAA and Reproductive Health
      • HIPAA and Final Rule Notice
    • HIPAA and Telehealth
    • HIPAA and FERPA
    • Research
    • Public Health
    • Emergency Response
    • Health Information Technology
    • Health Apps
  • Patient Safety
  • Covered Entities & Business Associates
    • Business Associate Contracts
    • Business Associates
  • Training & Resources
  • FAQs for Professionals
  • Other Administrative Simplification Rules
  • Substance Use Disorder Confidentiality

Security Rule Guidance Material

In this section, you will find educational materials to help you learn more about the HIPAA Security Rule and other sources of standards for safeguarding electronic protected health information (e-PHI).

Risk Management Video Presentation

This video presentation is intended to raise awareness and provide practical education to HIPAA covered entities and business associates of the HIPAA Security Rule’s Risk Management requirement.

Like risk analysis, effective risk management is an essential component of both HIPAA Security Rule compliance and broader cybersecurity preparedness. Risk management is a critical step not only for safeguarding electronic protected health information, but also for defending against cyber-attacks more generally by reducing risks and vulnerabilities to a reasonable and appropriate level.

Topics include:

  • HIPAA Security Rule Risk Management requirements
  • OCR investigation findings of potential Risk Management violations
  • Risk Management and cybersecurity resources

In developing this video, OCR engaged with the regulated community by soliciting questions on risk management. The final segment of the presentation addresses a selection of these questions.

The video is available on OCR’s YouTube channel, @USGovHHSOCR.

Recognized Security Practices Video Presentation

The HHS Office for Civil Rights (OCR) has produced a pre-recorded video presentation for HIPAA covered entities and business associates (regulated entities) on “recognized security practices,” as set forth in Public Law 116-321 (Section 13412 of the Health Information Technology for Economic and Clinical Health Act (HITECH). The statute requires OCR to take into consideration in certain Security Rule enforcement and audit activities whether a regulated entity has adequately demonstrated that recognized security practices were “in place” for the prior 12 months.

This presentation is intended to educate regulated entities on the categories of recognized security practices and how entities may demonstrate implementation. Topics include:

  • The 2021 HITECH Amendment regarding recognized security practices
  • How regulated entities can adequately demonstrate that recognized security practices are in place
  • How OCR is requesting evidence of recognized security practices
  • Resources for information about recognized security practices
  • OCR’s answers to questions on recognized security practices

The video may be found on OCR’s YouTube channel, @USGovHHSOCR.

Security Rule Educational Paper Series

The HIPAA Security Information Series is a group of educational papers which are designed to give HIPAA covered entities insight into the Security Rule and assistance with implementation of the security standards.

Security 101 for Covered Entities

Administrative Safeguards

Physical Safeguards

Technical Safeguards

Organizational, Policies and Procedures and Documentation Requirements

Basics of Risk Analysis and Risk Management

Security Standards: Implementation for the Small Provider

HIPAA Security Guidance

HHS has developed guidance and tools to assist HIPAA covered entities in identifying and implementing the most cost effective and appropriate administrative, physical, and technical safeguards to protect the confidentiality, integrity, and availability of e-PHI and comply with the risk analysis requirements of the Security Rule.

Risk Analysis
HHS Security Risk Assessment Tool

HHS has also developed guidance to provide HIPAA covered entities with general information on the risks and possible mitigation strategies for remote use of and access to e-PHI.

Remote Use

HHS has gathered tips and information to help you protect and secure health information patients entrust to you when using mobile devices.

Mobile Device

HHS has developed guidance to help covered entities and business associates better understand and respond to the threat of ransomware.

Ransomware

National Institute of Standards and Technology (NIST) Special Publications

NIST is a federal agency that sets computer security standards for the federal government and publishes reports on topics related to IT security. The following special publications are provided as an informational resource and are not legally binding guidance for covered entities.

NIST Special Publication 800-30: Risk Management Guide for Information Technology Systems

NIST Special Publication 800-52: Guidelines for the Selection and Use of Transport Layer Security (TLS) Implementations

NIST Special Publication 800-66 Rev. 2: Implementing the HIPAA Security Rule: A Cybersecurity Resource Guide

NIST Special Publication 800-77: Guide to IPsec VPNs

NIST Special Publication 800-88: Computer Security, Guidelines for Media Sanitization

NIST Special Publication 800-111: Guide to Storage Encryption Technologies for End User Devices

NIST Special Publication 800-113: Guide to SSL VPNs

Federal Information Processing Standards Publication 140-2: Security Requirements for Cryptographic Modules

NIST HIPAA Security Rule Toolkit Application

NIST Cyber Security Framework to HIPAA Security Rule Crosswalk

The Federal Trade Commission Guidance

Security Risks to Electronic Health Information from Peer-to-Peer File Sharing Applications-The Federal Trade Commission (FTC) has developed a guide to Peer-to-Peer (P2P) security issues for businesses that collect and store sensitive information.

Safeguarding Electronic Protected Health Information on Digital Copiers-The Federal Trade Commission (FTC) has tips on how to safeguard sensitive data stored on the hard drives of digital copiers.

Medical Identity Theft: FAQs for Health Care Providers and Health Plans-The Federal Trade Commission (FTC) has tips on how to minimize the risk of medical identity theft and how to help patients if they’re victimized.

OCR Cyber Awareness Newsletters

In 2019, OCR moved to quarterly cybersecurity newsletters. The purpose of the newsletters remains unchanged: to help HIPAA covered entities and business associates remain in compliance with the HIPAA Security Rule by identifying emerging or prevalent issues, and highlighting best practices to safeguard PHI. Visit our Cybersecurity Newsletter Archive page to view previous newsletters from 2016.

  • January 2026 OCR Cybersecurity Newsletter: System Hardening and Protecting ePHI
  • October 2024 OCR Cybersecurity Newsletter: Social Engineering: Searching for Your Weakest Link
  • August 2024 OCR Cybersecurity Newsletter: HIPAA Security Rule Facility Access Controls – What are they and how do you implement them?
  • October 2023 OCR Cybersecurity Newsletter: How Sanction Policies Can Support HIPAA Compliance
  • June 2023 OCR Cybersecurity Newsletter: HIPAA and Cybersecurity Authentication
  • October 2022 OCR Cybersecurity Newsletter: HIPAA Security Rule Security Incident Procedures
  • Quarter 1 2022 OCR Cybersecurity Newsletter: Defending Against Common Cyber-Attacks
  • Fall 2021 OCR Cybersecurity Newsletter: Securing Your Legacy [System Security]
  • Summer 2021 OCR Cybersecurity Newsletter: Controlling Access to ePHI: For Whose Eyes Only?
  • Summer 2020 OCR Cybersecurity Newsletter: HIPAA and IT Asset Inventories
  • Summer 2019 OCR Cybersecurity Newsletter: Managing Malicious Insider Threats
  • Spring 2019 OCR Cybersecurity Newsletter: Advanced Persistent Threats and Zero Day Vulnerabilities
  • Fall 2019 OCR Cybersecurity Newsletter: What Happened to My Data?: Update on Preventing, Mitigating and Responding to Ransomware

Sign up for the OCR Security Listserv to receive the OCR Cyber Awareness Newsletters in your email inbox.

Frequently Asked Questions for Professionals - Please see the HIPAA FAQs for additional guidance on health information privacy topics.

Content last reviewed April 8, 2026
Back to top
Secretary Robert F. Kennedy Jr.

Follow @SecKennedy

HHS icon

Follow @HHSGov

HHS Email updates

Receive email updates from HHS.

Subscribe

HHS Logo

HHS Headquarters

200 Independence Avenue, S.W.
Washington, D.C. 20201
Toll Free Call Center: 1-877-696-6775​

  • Contact HHS
  • Careers
  • HHS FAQs
  • Nondiscrimination Notice
  • Press Room
  • HHS Archive
  • Accessibility Statement
  • Budget/Performance
  • Inspector General
  • Web Site Disclaimers
  • EEO/No Fear Act
  • FOIA
  • The White House
  • USA.gov
  • Vulnerability Disclosure Policy