Guide

HIPAA Administrative Safeguards

The largest safeguard category and the source of most findings — nine standards and what each demands operationally.

Administrative safeguards Physical safeguards Technical safeguards Privacy rule Breach notification

The largest safeguard category and the source of most findings — nine standards and what each demands operationally.

Why this category matters most

Administrative safeguards live at 45 CFR §164.308 and account for more than half of the Security Rule by volume. They are also where most findings occur, because they cannot be bought. You can purchase encryption and access control from a vendor; you cannot purchase a risk analysis you actually performed, a training programme your staff actually completed, or a termination procedure that actually runs on someone’s last day. Administrative safeguards are the management layer of the rule — the part that proves security is an organised programme rather than a collection of tools.

There are nine standards. Some contain required implementation specifications, some contain addressable ones, and a few contain none at all — which means the standard itself is the requirement. Here is what each demands operationally.

Security management process

Risk analysis, risk management, sanction policy, and information system activity review. All four required. The sanction policy is the one everyone forgets.

This standard, §164.308(a)(1), is the foundation the rest of the rule stands on. The risk analysis identifies where ePHI lives and what threatens it; the risk management plan says what you are doing about it; the sanction policy says what happens to workforce members who violate your policies; and information system activity review means someone periodically looks at audit logs, access reports, and incident records rather than merely generating them.

The sanction policy deserves its reputation as the forgotten specification. It does not need to be draconian — a graduated scale from retraining through termination is standard — but it must exist, be applied consistently, and leave a record when applied. OCR asks for it because an unenforced policy set is evidence that the programme is paper.

Assigned security responsibility

§164.308(a)(2) requires one identified individual responsible for the security programme — the Security Officer. Not a committee, not a shared inbox, one named person. In a small organisation this is a hat someone wears, not a full-time role, and it can be the same person as the Privacy Officer. What matters is that the designation is written down and the person actually owns the calendar of recurring obligations.

Workforce security and access management

Authorisation, clearance, and termination procedures, plus access authorisation and modification. Termination is the highest-frequency failure: accounts that outlive employment.

The operational shape of these two standards is a joiner–mover–leaver process. When someone joins, access is granted based on role and documented. When someone changes roles, access is adjusted — the “mover” step is the one that quietly decays, producing employees who accumulate permissions across years of internal transfers. When someone leaves, access is revoked the same day, and someone verifies it across every system, not just the identity provider. A quarterly access review that compares live accounts against the HR roster is the cheapest control in HIPAA relative to the findings it prevents.

Training, incident procedures, contingency planning

Awareness training, incident response and reporting, and the data backup, disaster recovery, and emergency mode operation plans — with testing.

Security awareness training under §164.308(a)(5) applies to the entire workforce, including management and including contractors with system access. The rule does not prescribe frequency; the defensible convention is at hire and annually, with records showing who completed what and when.

Incident procedures under §164.308(a)(6) require you to identify, respond to, and document security incidents — all of them, not only the ones that become reportable breaches. A one-page intake process and a log are the minimum viable implementation; the incident response guide covers the full workflow.

The contingency plan under §164.308(a)(7) is the standard most often failed on the testing component. Backups that have never been restored are hope, not a control. Test a restore at least annually, walk through the disaster recovery plan on paper, and record both.

Evaluation §164.308(a)(8)

Periodic technical and non-technical evaluation. This is the specification that makes an annual review non-optional.

Evaluation means periodically checking that your safeguards still meet the rule’s requirements in light of environmental and operational changes — new systems, new vendors, office moves, workforce changes. In practice most organisations satisfy it with an annual programme review plus a triggered review after any material change. The output should be written: what was reviewed, what was found, what was fixed.

Business associate contracts

§164.308(b) closes the category by requiring written satisfactory assurances — a business associate agreement — before any vendor creates, receives, maintains, or transmits ePHI on your behalf. The administrative-safeguard framing is a useful reminder that BAAs are a programme activity with an owner and a register, not a one-time procurement artefact.

How to sequence the work

If you are starting from little, the order that works is: name the Security Officer, run the risk analysis, write the policy set against what you actually do, deliver training, then build the recurring calendar — access reviews, log reviews, backup tests, annual evaluation. Everything in this category compounds: each cycle you complete becomes evidence, and evidence is what distinguishes a programme from a binder. Expect the first cycle to be rough and the third to be routine — that trajectory, visible in your dated records, is itself the strongest signal a reviewer can see.

The evidence each standard leaves behind

A useful final pass: for every standard in §164.308, name the artefact that proves it ran this year. Security management: the dated risk analysis, the remediation plan with owners, at least one sanction record or a documented zero, and log-review entries. Assigned responsibility: the written designation. Workforce and access management: provisioning records, a termination checklist executed for each departure, and the quarterly reconciliation export. Training: the completion report reconciled against the full roster. Incident procedures: the incident log — populated, because an empty log at any real organisation reads as no detection, not no incidents. Contingency planning: the restore test result and the tabletop walk-through notes. Evaluation: the annual review report itself. Business associate contracts: the register with signed copies linked.

If you can produce all nine artefact sets inside an hour, your administrative safeguards are in the strong minority. If three or more are missing, that is your remediation queue in priority order — and it is worth being honest that the missing ones are usually missing because no calendar owner exists, not because anyone decided against them. The free readiness assessment scores exactly this artefact-by-artefact view, and the annual review checklist is the run-book that keeps the set current once you have it.

Where SuperHIPAA fits

Everything above is work. The platform does the parts that are mechanical — evidence collection, acknowledgement tracking, register maintenance, renewal reminders — and our team does the parts that need judgement. You keep the parts that need to be yours.

Start where you are

Take the free readiness assessment — 24 questions, about eight minutes, no call required. You get a scored report identifying which required specifications you are missing and what to fix first. If it turns out you are further along than you thought, we will tell you that too.

Questions

Is this legal advice?

No. It is operational guidance from practitioners who build HIPAA programs. Regulatory interpretation for your specific situation should come from counsel.

Can we become HIPAA certified?

No. HHS operates no certification program and no private body can confer one. What exists is an independent third-party assessment, which is what customers and insurers actually accept.

How current is this page?

Last reviewed 2026-08-04. We review every guide quarterly and after any HHS rulemaking or significant enforcement action.

See your compliance program in one place

A 20-minute walkthrough with a practitioner. No slides, no pressure.

Book a demo