Get Demo
↑

HIPAA §164.312 Technical Safeguards: Access, Audit, Integrity, Authentication, Transmission

§164.312 standards and implementation specifications — Required vs Addressable for access, audit, integrity, authentication, and transmission.

Published: September 2026 Compliance · HIPAA 8–12 min read

45 CFR §164.312 is the Technical Safeguards section of the HIPAA Security Rule. It contains five standards. Two of those standards — Audit Controls and Person or Entity Authentication — are themselves Required standards with no Addressable escape hatch for the standard. Implementation specifications under Access Control, Integrity, and Transmission Security mix Required and Addressable labels.

Related: HIPAA hub · Audit logs · Encryption.

§164.312 Technical Safeguards — Standards: Access Control (a), Audit Controls (b) Required, Integrity (c), Person/Entity Authentication (d) Required, Transmission Security (e). Implementation specifications under each standard are Required or Addressable as listed in the regulation.

Required vs Addressable (Security Rule) — 45 CFR 164.306(d): Required implementation specifications must be implemented. Addressable specs: implement if reasonable and appropriate; if not, document why and implement an equivalent alternative measure if reasonable and appropriate. Addressable ≠ optional.

§164.312 At a Glance

Standard
Cite
Notes
Access Control
(a)
Unique user ID (R); emergency access (R); automatic logoff (A); encryption/decryption (A)
Audit Controls
(b)
Required standard — mechanisms to record and examine activity in systems with ePHI
Integrity
(c)
Mechanism to authenticate ePHI (A)
Person/Entity Authentication
(d)
Required standard — verify that a person or entity seeking access is the one claimed
Transmission Security
(e)
Integrity controls (A); encryption (A)

R = Required implementation specification; A = Addressable. Confirm the live CFR text for your programme.

NPRM Context

The January 2025 NPRM proposed elevating several technical expectations (including encryption and MFA-related controls). Those proposals are not final. See Security Rule 2025–2026 update.

How CyberSilo Helps

Prove §164.312 With Logs and Decisions

Connect Access Control policies to live audit trails and authentication evidence.

Frequently Asked Questions

Which §164.312 standards are Required?

Audit Controls (b) and Person or Entity Authentication (d) are Required standards. Access Control, Integrity, and Transmission Security include Required and/or Addressable implementation specifications as listed in the CFR.

Is encryption required under §164.312 today?

Encryption/decryption under Access Control and encryption under Transmission Security are Addressable today. The 2025 NPRM proposed making encryption required — not final as of 2026.

What do audit controls require?

§164.312(b) requires hardware, software, and/or procedural mechanisms that record and examine activity in information systems that contain or use ePHI.

HIPAA hub · HIPAA SIEM · MFA · CSA

📰 More from CyberSilo

Latest Articles

Stay ahead of evolving cyber threats with our expert insights

✅ Link copied!