The HIPAA Security Rule Applies to Which of the Following?
The HIPAA Security Rule applies to covered entities—health plans, health care clearinghouses, and health care providers who transmit health information electronically—and to their business associates. It specifically protects electronic protected health information (e-PHI), not paper or oral records.
The answer
The HIPAA Security Rule applies to covered entities and their business associates, and it protects electronic protected health information (e-PHI). If a multiple-choice question lists options like "covered entities," "business associates," "all of the above," or "only hospitals," the correct choice is the one covering both covered entities and business associates.
The three types of covered entities are:
- Health plans — insurers, HMOs, Medicare, Medicaid, employer group health plans.
- Health care clearinghouses — organizations that process health data from one format into another (e.g., billing services).
- Health care providers who transmit any health information electronically in connection with a covered transaction (claims, eligibility checks, referrals).
Business associates are outside persons or companies that create, receive, maintain, or transmit e-PHI on a covered entity's behalf—billing companies, cloud storage vendors, IT contractors, and third-party administrators. Since the HITECH Act (2009), business associates are directly liable under the Security Rule.
What the rule actually protects
The Security Rule governs e-PHI only—protected health information that is created, received, maintained, or transmitted in electronic form. It requires three categories of safeguards: administrative (risk analysis, workforce training, access management), physical (facility access controls, workstation and device security), and technical (access controls, audit logs, encryption, authentication).
This is the key distinction from the HIPAA Privacy Rule, which is broader: the Privacy Rule protects PHI in all forms—paper, oral, and electronic. The Security Rule is the narrower, e-PHI-only counterpart focused on the technical and organizational protection of digital records.
Why the other options are wrong
- "Only hospitals" or "only doctors": Too narrow. Hospitals and physicians are providers, but health plans, clearinghouses, and business associates are equally covered. And a provider is only covered if it transmits health data electronically.
- "Paper medical records": Wrong for the Security Rule—paper and oral PHI fall under the Privacy Rule, not the Security Rule. The Security Rule is specifically about electronic PHI.
- "Everyone / any business with health data": Also wrong. A life insurer, most employers acting as employers, and law enforcement are generally not covered entities. HIPAA applies only to the defined covered entities and their business associates.
The bigger picture
Think of it as a chain of responsibility: covered entities hold the primary duty to protect e-PHI, and they extend that duty to business associates through a Business Associate Agreement (BAA)—a contract requiring the associate to safeguard the data. If either link fails to implement reasonable safeguards, both can face civil and criminal penalties. Understanding who is covered (covered entities + business associates) and what is covered (e-PHI) is the core of nearly every HIPAA Security Rule exam question.
| Health plan | Insurers, HMOs, Medicare, Medicaid, group health plans | Yes (covered entity) |
| Health care clearinghouse | Billing/format-conversion services | Yes (covered entity) |
| Provider (electronic) | Doctors/hospitals transmitting data electronically | Yes (covered entity) |
| Business associate | Billing firms, cloud/IT vendors handling e-PHI | Yes (directly liable) |
| Provider (paper only, no e-transactions) | Practices that never transmit electronically | No |
| Life insurer / employer as employer | Not handling PHI as a covered function | No |
Frequently asked
What is the difference between the HIPAA Privacy Rule and Security Rule?
The Privacy Rule protects all protected health information—paper, oral, and electronic—and governs how it may be used and disclosed. The Security Rule is narrower, protecting only electronic PHI (e-PHI) through administrative, physical, and technical safeguards. The Privacy Rule is broader in scope; the Security Rule is digital-specific.
Who is a covered entity under HIPAA?
A covered entity is a health plan, a health care clearinghouse, or a health care provider that transmits health information electronically in connection with a covered transaction. These three types are directly bound by HIPAA's Privacy and Security Rules.
What is a business associate under HIPAA?
A business associate is a person or organization that creates, receives, maintains, or transmits e-PHI on behalf of a covered entity—such as billing companies, cloud providers, and IT contractors. They must sign a Business Associate Agreement and are directly liable under the Security Rule.
Does the HIPAA Security Rule apply to paper records?
No. The Security Rule applies only to electronic protected health information (e-PHI). Paper and oral PHI are protected under the HIPAA Privacy Rule instead. If a record was never in electronic form, the Security Rule's technical safeguards do not apply to it.
What is e-PHI?
e-PHI is electronic protected health information—any individually identifiable health information that is created, received, stored, or transmitted in electronic form. Examples include electronic health records, digital lab results, and health data in a cloud database. It is the sole focus of the HIPAA Security Rule.