HIPAA Security Rule vs. Privacy Rule: What's the Difference

Two HIPAA rules, two different jobs. Learn how the Privacy Rule and Security Rule differ, where they overlap, and what your practice must do to comply.
August 05, 2026
PolySec
Share article
Date
August 05, 2026
Category
HIPAA Information
Reading time
8 Minutes

People use "HIPAA" as if it's one thing, but compliance actually rests on two separate rules that do very different jobs. The Privacy Rule governs who can see or share patient health information and under what conditions. The Security Rule governs how you protect the electronic version of that information from being stolen, altered, or lost. Confusing the two is one of the most common reasons practices think they're compliant when they aren't.

Here's the short version: the Privacy Rule is about permission and disclosure. The Security Rule is about technical and physical protection. You need both, and they cover different scopes. This guide breaks down what each rule requires, where they overlap, and what a medical practice actually has to do to satisfy them.

The quick answer

  • Privacy Rule: Sets national standards for the use and disclosure of protected health information (PHI) in any form, on paper, spoken, or electronic. It defines patient rights and limits who can access or share PHI.
  • Security Rule: Sets standards specifically for electronic PHI (ePHI). It requires administrative, physical, and technical safeguards to keep that data confidential, intact, and available.

Think of it this way: the Privacy Rule decides whether a disclosure is allowed. The Security Rule makes sure the electronic systems holding that data can't be breached, tampered with, or knocked offline.

What the HIPAA Privacy Rule covers

The Privacy Rule was the first of the two to take effect, with a compliance date of April 14, 2003. Its scope is broad: it applies to PHI in every format, whether that's a paper chart, a conversation at the front desk, a fax, or a record in your EHR.

At its core, the Privacy Rule controls use and disclosure. It tells covered entities and their business associates when they can share patient information without authorization (for treatment, payment, and healthcare operations, for example) and when they need the patient's written permission first.

A few of its most important provisions:

The minimum necessary standard. The minimum necessary standard requires covered entities to make reasonable efforts to limit the use, sharing, or requests for protected health information to only what's necessary to accomplish the intended purpose. A billing clerk doesn't need a patient's full clinical history to process a claim, so they shouldn't have access to it. Notably, this standard has exceptions, it doesn't apply to disclosures to the patient themselves, disclosures for treatment, or uses required by law.

Patient rights. The rule gives patients concrete, enforceable rights over their own records: the right to access and get copies of their PHI, to request corrections, to receive an accounting of certain disclosures, and to ask for restrictions or confidential communications.

Notice of Privacy Practices. A HIPAA Notice of Privacy Practices advises patients and plan members of their privacy rights, how the organization can use or disclose PHI, and how an individual can complain if they believe their privacy rights have been violated or their information misused.

One more thing worth knowing: HIPAA establishes a federal floor, so if a state law is more protective of privacy, you must follow the stricter state law.

What the HIPAA Security Rule covers

The Security Rule came later, with an effective compliance date of April 21, 2005 for most covered entities. Its scope is narrower and more technical: it applies only to electronic PHI. Paper records and spoken disclosures fall under the Privacy Rule, not the Security Rule.

The Security Rule is built around three protective goals for ePHI, confidentiality, integrity, and availability, and it organizes its requirements into three categories of safeguards:

Administrative safeguards. The policies, procedures, and workforce management that govern how you protect ePHI. This includes assigning a security official, training staff, managing access privileges, and, most importantly, conducting a risk analysis.

Physical safeguards. Controls over the physical environment: facility access, workstation security, device and media disposal, and preventing unauthorized people from physically reaching systems that store ePHI.

Technical safeguards. The technology controls, access controls, audit logs, encryption, and authentication that protect ePHI as it's stored and transmitted.

The single most important requirement here is the risk analysis. Conducting a risk analysis is the first step in identifying and implementing safeguards that comply with the standards and implementation specifications in the Security Rule. It isn't optional, and it isn't a one-time checkbox. The risk analysis requirement is a required implementation specification, which means all covered entities and business associates must conduct risk assessments, and there's no alternative compliance path.

This matters more than most practices realize. When OCR investigates breaches or conducts compliance reviews, inadequate risk assessment documentation consistently appears among the most cited deficiencies. A missing or shallow risk analysis is often the first thing regulators find, and it's frequently what turns a bad situation into a costly one.

Where the two rules overlap

The rules are distinct, but they're not independent. A practice can follow the Privacy Rule perfectly, only disclosing information when permitted, and still violate HIPAA if a laptop full of unencrypted patient records gets stolen. That's a Security Rule failure, and it's also, in effect, an impermissible disclosure.

The overlap is easiest to see in a breach. When ePHI is exposed, you've usually failed a Security Rule safeguard and triggered privacy consequences at the same time, because the information ended up in unauthorized hands. Both rules also share the same enforcement body, the HHS Office for Civil Rights, and the same penalty structure. For 2025, HIPAA civil monetary penalties range from $145 per violation to $2,190,294 per violation, depending on the level of culpability.

Why the distinction matters right now

This isn't an academic exercise. Healthcare is one of the most attacked industries in the world, and the numbers from the last two years are staggering.

In 2024, an average of 792,226 individuals were affected by a healthcare data breach every day, driven in large part by the Change Healthcare breach that affected 192.7 million individuals. That single incident ranks among the largest health data breaches ever recorded. And the financial fallout is severe: healthcare data breaches cost an average of $7.42 million per incident, the costliest of any industry. The healthcare sector has held the position of most expensive industry for data breaches for 14 consecutive years.

The reason the distinction matters is that most modern breaches are Security Rule problems. Ransomware, stolen credentials, and unpatched systems don't care about your Notice of Privacy Practices. If your practice has invested heavily in privacy paperwork but never completed a real risk analysis or encrypted its data, you're exposed exactly where attackers are aiming.

What's changing: the proposed Security Rule update

The Security Rule hasn't had a major update since 2013, and the technology landscape has shifted dramatically since then. That's about to change. On December 27, 2024, the Office for Civil Rights at HHS issued a Notice of Proposed Rulemaking to modify the HIPAA Security Rule and strengthen cybersecurity protections for ePHI.

Several proposed changes would raise the bar significantly:

  • No more "addressable" safeguards. Under the current rule, some safeguards are labeled "addressable," which many organizations have historically treated as optional. The NPRM proposes to remove the distinction between "required" and "addressable" implementation specifications and make all implementation specifications required, with specific, limited exceptions.
  • Mandatory encryption. The addressable category for encryption would be eliminated, and encryption would be required for all ePHI data in transit and at rest.
  • Multi-factor authentication and asset inventories. The proposal would require MFA for systems accessing ePHI and an accurate, maintained inventory of technology assets.

A quick but important caveat on timing: this rule is not yet final. The proposed update is still not final, and OMB now targets July 2027 for final action. Even so, the direction is clear, and many of these measures (encryption, MFA, current asset inventories) are already standard security practice. Practices that adopt them now won't be scrambling later.

What your practice should actually do

If you take one thing from this comparison, make it this: privacy policies and security controls are two separate obligations, and you need to satisfy both.

  1. Handle the Privacy Rule basics. Confirm your Notice of Privacy Practices is current, your minimum-necessary access rules are enforced, and your process for patient access requests works.
  2. Complete a real Security Rule risk analysis. Not a template you filled out once. Identify where ePHI lives, what threatens it, and where your gaps are, then document the whole thing.
  3. Fix the technical basics ahead of the new rule. Encrypt data at rest and in transit, turn on MFA, and keep an accurate inventory of every device and system touching ePHI.
  4. Keep documentation for six years. Maintain all risk analysis, mitigation, and training documentation for a minimum of six years, kept organized and audit-ready.

The hard part for most practices is step two. A thorough risk analysis requires security expertise that a typical clinic or dental office doesn't have on staff, and a generic online questionnaire won't hold up if OCR comes knocking. This is where an in-person, practice-specific assessment pays off. PolySec (polysec.tech) performs on-site HIPAA security risk assessments for healthcare practices, including vulnerability and network scanning, policy and BAA review, an audit-ready findings report, and a remediation roadmap, so you're not guessing about where your gaps are. The idea is simple: you focus on patients, and a security team handles the technical compliance work.

Frequently asked questions

Is the Privacy Rule or the Security Rule more important? Neither. They cover different things and you're legally required to comply with both. The Privacy Rule governs use and disclosure of all PHI; the Security Rule protects electronic PHI specifically.

Does the Security Rule apply to paper records? No. The Security Rule applies only to electronic PHI. Paper records and spoken disclosures are covered by the Privacy Rule instead.

Do both rules apply to business associates? Yes. Both covered entities and their business associates must comply, which is significant given how many major breaches originate with vendors and third parties.

What's the first step to Security Rule compliance? A documented risk analysis. It's a required specification, it has no alternative compliance path, and it's the most common deficiency OCR cites during investigations.

When do the new Security Rule requirements take effect? The 2024 proposed rule isn't final yet, with final action currently targeted for 2027. But since measures like encryption and MFA are already best practice, implementing them now is the safe move.