Get Demo
↑

HIPAA Administrative, Physical and Technical Safeguards Explained

Security Rule safeguard categories under §§164.308, 164.310, and 164.312 — with Required vs Addressable clarified.

Published: September 2026 Compliance · HIPAA 8–12 min read

The HIPAA Security Rule organises ePHI protections into three safeguard categories: Administrative (§164.308), Physical (§164.310), and Technical (§164.312). Each contains standards and implementation specifications that are Required or Addressable under 164.306(d).

Related: HIPAA hub · §164.312 deep dive · Checklist.

Required vs Addressable (Security Rule) — 45 CFR 164.306(d): Required implementation specifications must be implemented. Addressable specs: implement if reasonable and appropriate; if not, document why and implement an equivalent alternative measure if reasonable and appropriate. Addressable ≠ optional.

Administrative Safeguards (§164.308)

Policies, risk analysis/management, workforce security, information access management, security awareness and training, security incident procedures, contingency planning, evaluation, and business associate contracts. Risk analysis under §164.308(a)(1) is a frequent OCR finding when missing or stale.

Physical Safeguards (§164.310)

Facility access controls, workstation use/security, and device and media controls — including disposal and media re-use expectations for hardware that stored ePHI.

Technical Safeguards (§164.312)

Access control, audit controls, integrity, person or entity authentication, and transmission security. See our dedicated §164.312 guide for Required vs Addressable specs.

How to Work the Categories

  1. Map every ePHI system to applicable standards in all three categories.
  2. For each Addressable specification, implement or document why not + equivalent alternative.
  3. Retain Security Rule documentation for 6 years under 164.316(b)(2).

How CyberSilo Helps

Map All Three Safeguard Categories

Stop treating Technical controls as the whole Security Rule — close Administrative and Physical gaps with tracked evidence.

Frequently Asked Questions

What are the three HIPAA Security Rule safeguard types?

Administrative (§164.308), Physical (§164.310), and Technical (§164.312).

Are Addressable safeguards optional?

No. Addressable means implement if reasonable and appropriate, or document why not and implement an equivalent alternative if reasonable and appropriate (164.306(d)).

Where do BAAs fit?

Business associate contracts appear in Administrative safeguards (§164.308(b)) and related provisions; see also 164.314(a) and 164.504(e).

HIPAA hub · Risk analysis · Policies · CSA

📰 More from CyberSilo

Latest Articles

Stay ahead of evolving cyber threats with our expert insights

✅ Link copied!