Research · 11 min read
What a Security Standard Requires, and Who It Binds
One federal subpart says how electronic health records have to be protected. It reaches a narrow list of organizations, it asks for a process rather than a product, and it tells the organizations inside it to weigh their own costs while deciding what to build.
Key takeaways
- The federal security standards for electronic health records bind a named category of organization, not everyone who holds medical facts about you.
- The applicability sentence carries a tail most summaries drop: the duty runs to electronic protected health information of a covered entity.
- The general requirements are four outcomes — confidentiality, integrity and availability, protection against reasonably anticipated threats and against impermissible uses, and workforce compliance.
- No product, vendor, certification or technique is named anywhere in the subpart; the rule asks for a process and leaves the method open.
- An organization is instructed to weigh its own size, its technical capabilities, the costs of security measures and the probability of risk when deciding what to build.
- The subpart defines confidentiality, integrity, availability, encryption and authentication for itself, and warns that its definition of access does not carry into the neighboring subparts.
- A security incident includes an attempt and includes interference with system operations, which makes it a wider term than the breach definition next door.
Answer first: the rule binds a category, and the category is narrow
There is a federal rulebook about keeping electronic health records safe. It is separate from the rulebook about who may see them and separate again from the one about what happens after a loss.
Its own applicability section is one sentence, and the sentence names who carries the duty. A covered entity or business associate must comply with the applicable standards, implementation specifications, and requirements of the subpart with respect to electronic protected health information of a covered entity.
Read the tail as carefully as the opening. The duty attaches to a named category of organization, and it runs to one kind of information rather than to everything a company holds.
So the first question about any business is not how careful it sounds. It is whether it sits inside that category at all, and that is a question about the organization rather than about the information.
Where the standard comes from, and the noun in the statute
The subpart cites its own authority, and the statute it names is worth opening.
That statute directs the Secretary to adopt security standards, and it lists five things the standards must take into account. The technical capabilities of record systems used to maintain health information. The costs of security measures. The need for training persons who have access to health information. The value of audit trails in computerized record systems. And the needs and capabilities of small health care providers and rural health care providers.
Cost and small size are written into the statute before a single regulation exists. That is not an accident and it explains a great deal about the shape of the rule underneath.
The statute then states a duty of its own. Each person described in a named applicability section who maintains or transmits health information shall maintain reasonable and appropriate administrative, technical, and physical safeguards.
Those safeguards must ensure the integrity and confidentiality of the information. They must protect against reasonably anticipated threats or hazards to its security or integrity, and against reasonably anticipated unauthorized uses or disclosures. And they must otherwise ensure compliance by the officers and employees of that person.
⭐ And the applicability section it points at is a closed list of three. A health plan. A health care clearinghouse. And a health care provider who transmits any health information in electronic form in connection with a named kind of transaction.
A section title that hides its own contents
The statutory security standards are not in a section called anything of the sort. They are subsection (d) of a section whose printed title is "Standards for information transactions and data elements".
That matters for anyone trying to check this themselves. A search by section heading walks straight past the material, because the heading describes the rest of the section rather than this part of it.
It is a small thing and it is the reason so many summaries cite the regulation and never the statute underneath it.
The four things the rule asks for
The general requirements are short enough to read whole, and each one is a verb rather than a technology.
Ensure the confidentiality, integrity, and availability of all electronic protected health information the covered entity or business associate creates, receives, maintains, or transmits.
Protect against any reasonably anticipated threats or hazards to the security or integrity of such information.
Protect against any reasonably anticipated uses or disclosures of such information that are not permitted or required under the privacy subpart.
And ensure compliance with the subpart by its workforce.
Four sentences, and not one of them names a product, a vendor, a certification or a technique. The obligation is stated as an outcome, and how to reach it is left to the organization.
Flexibility is written in, and so is cost
The rule then says so directly, in a paragraph headed flexibility of approach.
A covered entity or business associate may use any security measures that allow it to reasonably and appropriately implement the standards and implementation specifications as specified in the subpart.
In deciding which measures to use, it must take four factors into account. The size, complexity, and capabilities of the organization. Its technical infrastructure, hardware, and software security capabilities. The costs of security measures. And the probability and criticality of potential risks to the information.
The third factor is the one people are surprised by. Cost is not a defense somebody invented after the fact; the regulation instructs an organization to weigh it, and the statute above told the Secretary to build that in.
The rule closes the loop with a maintenance duty. Security measures must be reviewed and modified as needed to continue reasonable and appropriate protection, with the documentation updated to match.
⚖ That flexibility cuts both ways for a reader. It is why two organizations can both comply while looking nothing alike, and it is why a comparison between them is harder than it looks.
The vocabulary the subpart defines for itself
The subpart carries its own definitions section, and several of the words it fixes are words people already think they know.
Confidentiality means the property that data or information is not made available or disclosed to unauthorized persons or processes. Integrity means the property that data or information have not been altered or destroyed in an unauthorized manner. Availability means the property that data or information is accessible and useable upon demand by an authorized person.
Those three are the outcome the general requirements ask for, and defining them as properties of the information rather than as feelings about a company is what makes the requirement testable at all.
Encryption is defined too, as the use of an algorithmic process to transform data into a form in which there is a low probability of assigning meaning without use of a confidential process or key.
Authentication means the corroboration that a person is the one claimed. Security or security measures encompass all of the administrative, physical, and technical safeguards in an information system.
⛔ One definition carries a warning inside it. Access is defined as the ability or the means necessary to read, write, modify, or communicate data or information or otherwise use any system resource. The regulation then adds a parenthesis: that definition applies to access as used in this subpart, not as used in the breach or privacy subparts. The same word means two different things two pages apart.
A security incident is a wider word than a breach
The definitions section fixes one more term that is easy to confuse with a neighbor.
A security incident means the attempted or successful unauthorized access, use, disclosure, modification, or destruction of information or interference with system operations in an information system.
The word attempted is doing real work there. An unsuccessful attempt is inside the definition, and so is interference with how a system runs rather than with the records themselves.
The breach rules in the neighboring subpart use a narrower test with its own exclusions and its own presumption, and a companion article covers it. The two words are not interchangeable, and a document that uses one is not answering the question posed by the other.
These dates are two decades old
The subpart's last section is a compliance timetable, and it is worth knowing simply because of how old it is.
A health plan that is not a small health plan had to comply no later than April 2005. A small health plan had until April 2006. A health care clearinghouse and a covered health care provider each had until April 2005.
Nothing here is new law and nothing here is pending. For any organization inside the category, these standards have been in force for about twenty years.
The part also carries a short cross-reference of its own. It requires covered entities and, where provided, business associates, to comply with the applicable provisions of two other parts of the same subchapter.
What a reader can actually look at
Whether the company publishes a document that names the entity holding the medical record, since that entity is the one the category question is about.
Whether any document names a person responsible for security, since the subpart requires one to be identified and a name is a fact rather than a promise.
Whether the language you are shown describes a process — review, assessment, policies that get updated — or only an adjective. The rule asks for the first.
Whether a policy distinguishes the medical record from the marketing record, since the duty described here runs only to one of them.
And whether the words security and privacy are being used as if they meant the same thing. They are two different rulebooks with different scopes, and a document that blurs them is telling you something about itself.
What this does not decide
It does not say whether any particular company is a covered entity or a business associate. That is a legal conclusion about a specific business, it depends on facts a homepage does not show, and nothing here reaches it.
It does not say that any company is or is not complying with anything. No such claim is made and none is implied.
It does not describe what the neighboring breach subpart requires, which companion articles cover, and it describes no state statute.
And it is not legal advice. It reports what four sections of one federal subpart and two statutory sections say.
Sources
- 45 CFR 164.302, "Applicability"The whole of the section, quoted in the body and again in an FAQ: a covered entity or business associate must comply with the applicable standards, implementation specifications, and requirements of this subpart with respect to electronic protected health information of a covered entity. The subpart's own authority line, printed on the same page, naming 42 U.S.C. 1320d-2 and 1320d-4 and section 13401 of Public Law 111-5, with a source note of 68 FR 8376, Feb. 20, 2003 unless otherwise noted.
- 45 CFR 164.304, "Definitions"The definitions quoted in the body: confidentiality as the property that data or information is not made available or disclosed to unauthorized persons or processes; integrity as the property that data or information have not been altered or destroyed in an unauthorized manner; availability as the property that data or information is accessible and useable upon demand by an authorized person; encryption as the use of an algorithmic process to transform data into a form in which there is a low probability of assigning meaning without use of a confidential process or key; authentication as the corroboration that a person is the one claimed; security or security measures as encompassing all of the administrative, physical, and technical safeguards in an information system; security incident as the attempted or successful unauthorized access, use, disclosure, modification, or destruction of information or interference with system operations in an information system; and access, together with the parenthetical stating that the definition applies to access as used in this subpart and not as used in subparts D or E of the part.
- 45 CFR 164.306, "Security standards: General rules"Paragraph (a), the four general requirements quoted in the body. Paragraph (b)(1), stating that covered entities and business associates may use any security measures that allow them to reasonably and appropriately implement the standards and implementation specifications as specified in the subpart. Paragraph (b)(2), the four factors that must be taken into account: the size, complexity, and capabilities of the covered entity or business associate; its technical infrastructure, hardware, and software security capabilities; the costs of security measures; and the probability and criticality of potential risks to electronic protected health information. Paragraph (e), the maintenance duty to review and modify the security measures implemented under the subpart as needed to continue provision of reasonable and appropriate protection, and to update documentation accordingly. ⚠ Paragraph (d), the required and addressable machinery, is the spine of a companion article and is not described here.
- 45 CFR 164.318, "Compliance dates for the initial implementation of the security standards"Paragraph (a)(1) and (a)(2), the compliance dates of April 20, 2005 for a health plan that is not a small health plan and April 20, 2006 for a small health plan. Paragraph (b), April 20, 2005 for a health care clearinghouse. Paragraph (c), April 20, 2005 for a covered health care provider.
- 45 CFR 164.106, "Relationship to other parts"The whole of the section: in complying with the requirements of the part, covered entities and, where provided, business associates, are required to comply with the applicable provisions of parts 160 and 162 of the subchapter.
- 42 U.S.C. 1320d-2, "Standards for information transactions and data elements"Subsection (d), "Security standards for health information", and the observation in the body that it sits inside a section whose printed title names information transactions and data elements. Paragraph (d)(1)(A), the five matters the Secretary must take into account in adopting security standards: the technical capabilities of record systems used to maintain health information; the costs of security measures; the need for training persons who have access to health information; the value of audit trails in computerized record systems; and the needs and capabilities of small health care providers and rural health care providers. Paragraph (d)(2), requiring each person described in the applicability section who maintains or transmits health information to maintain reasonable and appropriate administrative, technical, and physical safeguards to ensure the integrity and confidentiality of the information, to protect against any reasonably anticipated threats or hazards to its security or integrity and any reasonably anticipated unauthorized uses or disclosures, and otherwise to ensure compliance by the officers and employees of such person.
- 42 U.S.C. 1320d-1, "General requirements for adoption of standards"Subsection (a), the applicability clause the safeguards paragraph points at, stating that any standard adopted under the part shall apply, in whole or in part, to a health plan, a health care clearinghouse, and a health care provider who transmits any health information in electronic form in connection with a transaction referred to in the transactions paragraph of the neighboring section.
Frequently asked questions
Does this rule apply to every company that holds health information?
No, and the subpart's own applicability section is the shortest place to see that. It states that a covered entity or business associate must comply with the applicable standards, implementation specifications, and requirements of the subpart with respect to electronic protected health information of a covered entity. Two limits sit in that sentence. The duty attaches to named categories of organization rather than to anyone holding medical facts, and it runs to one kind of information rather than to everything a company stores. Which category a given business falls into is a legal question about that business.
Does the rule tell a company what technology to use?
It does not, and it says so. The general requirements are stated as outcomes: ensure confidentiality, integrity and availability; protect against reasonably anticipated threats or hazards; protect against reasonably anticipated impermissible uses or disclosures; and ensure workforce compliance. A separate paragraph headed flexibility of approach then states that an organization may use any security measures that let it reasonably and appropriately implement the standards. No product, vendor or certification is named anywhere in the subpart.
Is cost really something a company is allowed to weigh?
Yes, and it is written into both layers. The regulation lists four factors an organization must take into account when deciding which security measures to use, and the third is the costs of security measures. The other three are its size, complexity and capabilities; its technical infrastructure, hardware and software security capabilities; and the probability and criticality of potential risks. The statute above the regulation had already directed that security standards take cost into account, along with the needs and capabilities of small and rural health care providers.
What is the difference between a security incident and a breach?
They are two defined terms in two different subparts, and the security one is wider. A security incident means the attempted or successful unauthorized access, use, disclosure, modification, or destruction of information, or interference with system operations in an information system. An attempt counts, and so does interference with how a system runs. The breach definition in the neighboring subpart sets a narrower test with its own exclusions and its own presumption. A document answering one question has not answered the other.
Why do the same words mean different things in different places?
Because the regulation says so on purpose, at least once. Access is defined in the security subpart as the ability or the means necessary to read, write, modify, or communicate data or information or otherwise use any system resource. A parenthesis immediately adds that the definition applies to access as used in that subpart and not as used in the breach or privacy subparts. That is a drafting instruction, and it is a warning for anyone reading a summary that quotes a definition without naming which subpart it came from.
How new are these requirements?
They are not new. The subpart's final section sets the compliance dates, and they have all passed. A health plan that is not a small health plan had until April 2005, and a small health plan until April 2006. A health care clearinghouse and a covered health care provider each had until April 2005. For an organization inside the category, these standards have been in force for roughly two decades. Nothing described here is proposed, pending or forthcoming.