Medical Office IT: HIPAA Technical Safeguards Guide
What the HIPAA Security Rule's technical safeguards mean as real settings for a medical office, plus what is law today and what HHS has only proposed.
The HIPAA Security Rule’s technical safeguards come down to five things a medical office has to be able to show: each person has their own login, the systems record who did what, records cannot be altered without detection, people prove who they are before getting in, and patient data is protected while it travels. As of September 2026 the rule in force is still the 2013 version. The stricter update HHS proposed in January 2025 has not been finalized. This guide maps each safeguard to settings you can check.
It is the technical companion to two other pages. The medical office IT services page describes what we do for practices. The HIPAA IT compliance guide covers the big picture: the three safeguard families, business associate agreements, and backups. Neither is repeated here. This is IT guidance, not legal advice, so involve your compliance adviser in decisions.
What is law today and what is only proposed?
This matters because the proposed update is often discussed as though it were already in force. It is not.
In force: the Security Rule at 45 CFR Part 164, Subpart C, last amended in 2013. Its technical safeguards are in section 164.312.
Proposed, not final: HHS published a notice of proposed rulemaking in the Federal Register on January 6, 2025. The comment period closed March 7, 2025. The federal regulatory agenda now lists the rule as a long-term action with a target of July 2027 for final action. Agenda dates are estimates, not commitments, and the final text could differ from the proposal or never arrive.
| Topic | Current rule (enforceable now) | January 2025 proposal (not in force) |
|---|---|---|
| Required vs. addressable | Some specifications are “addressable” | Distinction removed, nearly everything required |
| Encryption | Addressable | Encrypt patient data at rest and in transit, with limited exceptions |
| Multi-factor authentication | Not named. “Person or entity authentication” is required | Expressly required |
| Inventory and network map | Implied by risk analysis | Written inventory and network map, reviewed at least every 12 months |
| Vulnerability scans | Not specified | At least every six months |
| Penetration testing | Not specified | At least every 12 months |
| Recovery | Backup and disaster recovery plans required | Written procedures to restore critical systems within 72 hours |
| Network segmentation | Not specified | Required |
The sensible reading for a small practice: nothing in the right-hand column is a legal deadline today, and almost all of it is good practice you would want anyway. Building toward it now is cheaper than rushing if a final rule lands with a short compliance window. The proposal referred to the standard 180 days after a final rule takes effect.
What does “addressable” actually mean?
It does not mean optional. Under section 164.306(d), for an addressable specification you must assess whether it is reasonable and appropriate for your office. If it is, you implement it. If it is not, you document why and implement an equivalent alternative where reasonable. “We decided not to” without a written reason is not one of the choices.
For a modern office, encryption and automatic logoff are inexpensive and built into the tools you already own, so the written case for skipping them is hard to make.
The five technical safeguards, mapped to real settings
“ePHI” below means electronic protected health information: any patient-identifiable health data on a computer, phone, server, or cloud service.
| Safeguard (164.312) | Status | What it means in the office | Where to check |
|---|---|---|---|
| Unique user identification | Required | One named account per person in Windows, the EHR, and email. No shared front-desk login. | EHR user list, Microsoft 365 or Google user list, Windows accounts |
| Emergency access procedure | Required | A documented way to reach patient information when the normal route fails: EHR downtime procedure, a sealed emergency administrator account, printed schedules. | Written procedure, tested once |
| Automatic logoff | Addressable | Screens lock after a short idle time. EHR session timeout set, not disabled. | Windows policy “Interactive logon: Machine inactivity limit”, EHR security settings |
| Encryption and decryption | Addressable | Full-disk encryption on every laptop, desktop, and phone that touches ePHI. | BitLocker on Windows Pro, FileVault on Mac, device passcode on phones |
| Audit controls | Required | Logs that record sign-ins and record access, kept and reviewed on a schedule. | EHR audit report, Microsoft Purview audit log |
| Integrity | Required standard | Protection against improper alteration: role-based permissions, versioned backups, endpoint protection. | EHR roles, backup retention settings |
| Person or entity authentication | Required | Proof of identity before access. In practice, multi-factor authentication on email, remote access, and cloud EHR. | Microsoft Entra security defaults or Conditional Access, EHR login settings |
| Transmission security | Addressable specs | Encrypted connections for anything carrying ePHI: TLS for portals and email, VPN or vendor-secured remote access, no patient data over open Wi-Fi. | Email encryption settings, remote access method |
Settings worth a closer look
Audit logging in Microsoft 365 is not on by default for small business plans. Microsoft states that auditing is not enabled by default for Business Basic, Standard, or Premium and must be turned on manually. To check: sign in to the Microsoft Purview portal, open Audit, and look for a banner asking you to start recording user and admin activity. Once on, records are kept for 180 days by default. If mailboxes hold patient information, this log is how you would reconstruct who accessed what.
Multi-factor authentication costs nothing extra to switch on. In Microsoft 365, security defaults require every user to register for MFA and block older sign-in methods. The path is Microsoft Entra admin center, then Entra ID > Overview > Properties > Manage security defaults. Microsoft documents the steps and notes no license is required. Practices on Business Premium can use Conditional Access for finer control.
Confirm the business associate agreement for your email and file platform. Microsoft makes its HIPAA BAA available by default through its data protection addendum for covered services, and says plainly that a BAA does not by itself make your use compliant. Whatever platform you use, keep a copy of the BAA with your compliance records.
EHR access ends the day employment ends. The EHR, email, remote access, and the patient portal’s staff side are usually four separate accounts. A written onboarding and offboarding checklist that lists all four is the control. Review the EHR user list quarterly against the current staff roster.
The risk analysis comes first
Every choice above is supposed to flow from one document. The rule requires “an accurate and thorough assessment of the potential risks and vulnerabilities” to ePHI. HHS publishes guidance on what a risk analysis must cover.
For a small office, a workable method is:
- List every place ePHI lives or passes through: EHR, email, scanners, fax service, phones, laptops, backups, the copier’s hard drive, staff home computers if remote access is allowed.
- For each, note who can reach it and how it is protected now.
- Write down what could go wrong (lost laptop, phishing, ransomware, a former employee’s live account) and how likely and how damaging each is.
- Decide what to fix, by when, and who owns it.
- Keep it. Security Rule documentation must be retained for six years.
- Revisit when something changes: new EHR, new location, new telehealth tool.
HHS and the health IT office offer a free Security Risk Assessment Tool aimed at small and medium practices. It runs on your own computer and does not send your answers to HHS. HHS is clear that using it does not guarantee compliance. It is a structured starting point.
Should patient Wi-Fi be separate from the office network?
Yes. Guest Wi-Fi in the waiting room should reach the internet and nothing else: not the EHR workstations, not the printers, not the network-attached scanner.
What good looks like:
- A guest network on its own VLAN (a virtual network that shares the hardware but not the traffic), with device-to-device traffic blocked.
- Staff Wi-Fi with a different password that is not posted anywhere.
- Medical devices and anything the vendor cannot patch on a third network with only the access they need.
- A test after setup: join the guest network with a phone and confirm you cannot reach a printer or a shared folder.
Two Wi-Fi names on a consumer router do not guarantee this. The network segmentation guide covers how to verify it.
Fax and scanning: the overlooked patient data
Faxing is still permitted. HHS confirms that a physician’s office may fax patient information to another office with reasonable safeguards. Its examples: confirm a number you do not use regularly before sending, and pre-program frequent numbers to avoid misdials.
Practical additions:
- Put the fax machine or printer where patients cannot read the output tray.
- If you use an online fax service, it stores patient documents, so treat it as a business associate and get a BAA.
- Fax-to-email delivery puts ePHI in mailboxes. Those mailboxes need MFA and the retention rules you apply to other patient data.
Multifunction copiers keep copies. The FTC’s copier data security guide explains that a digital copier’s hard drive stores data about the documents it copies, prints, scans, faxes, or emails. It recommends that your lease or purchase agreement state that you keep the drive at end of life or that the provider will overwrite it. The rule’s device and media controls require procedures for disposal and re-use.
Scan-to-email can break when you tighten security. Turning on security defaults blocks the older sign-in methods some scanners use to send mail. Microsoft’s security defaults page links to its supported ways to set up a scanner. Plan that change rather than finding out when the front desk cannot scan an insurance card. Scanning to a permission-controlled folder is often the cleaner option. Our email encryption guide covers sending patient information outside the office.
Telehealth after the pandemic flexibilities
During the public health emergency, HHS did not penalize good-faith use of everyday video apps for telehealth. That ended. The enforcement discretion expired May 11, 2023, and the 90-day transition period ended August 9, 2023. HHS’s HIPAA and telehealth page has the current guidance, including separate guidance on audio-only visits.
Checklist for a video visit setup:
- A video platform whose vendor signs a BAA, on a plan that the BAA covers. Consumer accounts generally are not covered.
- Waiting room and meeting lock features on, so a second patient cannot join early.
- Recording off unless there is a clinical and documented reason, with a known storage location if on.
- Clinicians connect from a practice-managed, encrypted device, from a private room, on a trusted network.
- Wired Ethernet or strong Wi-Fi at the clinician’s desk. Dropped video is a care problem before it is an IT problem.
- A fallback (phone number on file) agreed with the patient at the start.
When a small practice does not need more
A practice whose EHR, e-prescribing, and patient messaging all live in the vendor’s cloud has far less to build than the full list suggests. There is no server to patch and no local database to back up. What remains is real but modest: encrypted, updated computers, unique accounts with MFA, a separate guest network, a BAA file, offboarding discipline, and the written risk analysis.
Continuous monitoring services, penetration tests, or a dedicated log management system are reasonable for larger organizations. For a five-person office on a cloud EHR, under the current rule, they may be more than the risk analysis calls for. If the proposed rule is finalized as written, that calculation changes, which is the reason to watch it.
Common questions
Is multi-factor authentication required by HIPAA right now?
Not by name. The current rule requires “person or entity authentication” without naming a method. The January 2025 proposal would require MFA expressly, but it is not final. MFA is a direct way to meet the existing standard for email and remote access, and leaving it off is difficult to justify in a written risk analysis.
When will the new HIPAA Security Rule take effect?
Nobody can say. The proposal was published January 6, 2025, and the federal regulatory agenda currently targets July 2027 for final action, which is an estimate. If finalized, regulated entities would generally have 180 days after the effective date to comply. Until a final rule is published in the Federal Register, the 2013 rule is the law.
Does a cloud EHR make the practice HIPAA compliant?
No. The vendor secures its platform and signs a BAA. The practice is still responsible for who has accounts, the devices used to reach the EHR, the office network, email, scanned documents, staff training, and its own risk analysis. Compliance belongs to the practice as a whole, not to any product.
Can staff use personal phones for work email?
They can if the risk analysis supports it and the controls exist: a device passcode, encryption, MFA, and the ability to remove practice data when someone leaves. Mobile device management makes the last part enforceable. Without those controls, keep patient information off personal devices.
How we can help
Coastal Growth Co. sets up and documents the technical side: accounts and MFA, device encryption, audit logging, network separation, scanner and fax workflows, and the device inventory a risk analysis depends on. Your EHR vendor stays responsible for its application, and your compliance adviser for legal interpretation. Ongoing upkeep fits under managed IT. To start, send us a note describing your systems, without any patient information, and we will agree on scope and price before paid work begins.
- medical office IT
- HIPAA Security Rule
- technical safeguards
- EHR access
- telehealth
Need a hand with this?
I offer IT support across Orange County, with on-site work in Los Angeles and nearby areas by arrangement.
Let's talk arrow_forward