Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

HIPAA Security Rule vs Privacy Rule - protecting electronic PHI versus governing use and disclosure

HIPAA Security Rule vs Privacy Rule Explained

Two rules sit at the heart of HIPAA, and understanding the difference — HIPAA Security Rule vs Privacy Rule — is essential to a well-scoped compliance programme. They are related but distinct, covering different aspects of protecting health information. This guide explains each rule, how they differ, and how they work together.

HIPAA Security Rule vs Privacy Rule - protecting electronic PHI versus governing use and disclosure

For the wider context, see our complete HIPAA guide.

HIPAA Security Rule vs Privacy Rule at a glance

The Privacy Rule governs who may access and disclose protected health information and what rights patients have over it. The Security Rule governs how you protect that information when it is held electronically. Put simply: the Privacy Rule is about the appropriate use of health data in any form, while the Security Rule is about safeguarding electronic health data against threats.

What is the HIPAA Privacy Rule?

The Privacy Rule sets national standards for the protection of protected health information in all forms — paper, electronic, and oral. It defines when PHI may be used or disclosed without patient authorisation (for example, for treatment, payment, and healthcare operations), requires the “minimum necessary” use of PHI, and grants patients rights such as access to their records and the ability to request amendments. It applies broadly to how your organization handles health information day to day.

What is the HIPAA Security Rule?

The Security Rule focuses specifically on electronic protected health information (ePHI). It requires covered entities and business associates to implement three categories of safeguards: administrative (risk analysis, workforce training, access management), physical (facility and device controls), and technical (access controls, encryption, audit logs). A HIPAA risk assessment is a core Security Rule requirement, driving which safeguards you implement.

Key differences

  • Scope of data: the Privacy Rule covers PHI in all forms; the Security Rule covers electronic PHI only.
  • Focus: the Privacy Rule is about appropriate use and disclosure; the Security Rule is about protecting data from threats.
  • Core mechanisms: the Privacy Rule centres on permitted uses and patient rights; the Security Rule centres on administrative, physical, and technical safeguards.

How they work together

The two rules are complementary, and full HIPAA compliance requires both. The Privacy Rule tells you what you may do with health information and the rights you must respect; the Security Rule tells you how to protect the electronic form of that information. A strong programme addresses them together — privacy policies governing use and disclosure, and security safeguards protecting ePHI — supported by a single risk assessment and a unified set of documentation.

Cover both rules with confidence.

Our HIPAA Toolkit addresses both the Privacy and Security Rules — use-and-disclosure policies, patient-rights procedures, and administrative, physical, and technical safeguards — in Word and Excel.

Explore the HIPAA Toolkit →

Frequently asked questions

What is the difference between the HIPAA Privacy Rule and Security Rule?

The Privacy Rule governs the appropriate use and disclosure of protected health information in all forms and patient rights; the Security Rule governs how electronic protected health information is safeguarded against threats.

Does the Security Rule cover paper records?

No. The Security Rule applies only to electronic protected health information. Paper and oral PHI are covered by the Privacy Rule.

Do I need to comply with both rules?

Yes. Full HIPAA compliance requires meeting both the Privacy Rule and the Security Rule, along with the Breach Notification Rule.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.