The HIPAA Security Rule, in Plain English
If your clinic keeps patient information on computers — and it does — the Security Rule applies to you. Here is what it requires, translated out of legalese.

The Security Rule in one paragraph
The HIPAA Security Rule is the part of the law that protects electronic protected health information — ePHI. That is any patient information that lives on or moves through your computers: your EHR, your email, your billing software, the scanned insurance cards sitting on the front-desk PC.
The rule says you must put safeguards in place that are “reasonable and appropriate” for the size of your practice. A 200-physician hospital and a 12-person clinic in Portland are not expected to do the same things. But both are expected to do something in three categories: administrative, physical, and technical safeguards. Here is what each one means where you work.
Administrative safeguards: the people and policies part
This is the paperwork-and-habits half of compliance. It is also the half most small clinics skip, which is exactly why auditors ask about it first.
- Run a risk assessment. A documented look at where your patient data lives, what could go wrong, and what you are doing about it. The rule requires it. (We cover how to actually run one in our risk assessment guide.)
- Train your people. Every employee who touches patient information needs security training, and it needs to happen more than once — new hires, plus refreshers when something changes.
- Control who can see what. Not everyone needs the full chart. Front desk needs scheduling and insurance; they do not need clinical notes. Set access by role and stick to it.
- Have a backup and recovery plan. Written down, tested, and not just “we think the cloud handles it.” A Coastal Bend dental practice was hit by ransomware recently. The practices that recover are the ones that tested their backups before they needed them.
- Name one person responsible. The rule expects a designated security point person. In a small clinic that is often the office manager — the point is that it is written down somewhere.
Physical safeguards: the doors, desks, and devices part
This is about the real world, not software. Walk through your clinic and look with fresh eyes:
- Workstation placement. Can a patient in the waiting area or at the check-in window see a screen showing someone else’s information? Angle monitors away, or add privacy filters.
- Facility access. Who can walk into the back office after hours? Cleaning crews, the landlord, a former employee who still has a key — each one is a question worth answering.
- Devices leaving the building. Laptops, USB drives, and old phones that held patient data need encryption and a real disposal process — not the trash can behind the building.
- Paper counts too. The Security Rule covers electronic information, but printed charts left on a counter are a Privacy Rule problem. Same habit fixes both: clean desks, locked file areas.
Technical safeguards: the systems part
This is where your IT setup either carries you or sinks you:
- Unique logins for every person. No shared “frontdesk” account that six people use. If you cannot tell who opened a record, you cannot investigate a breach.
- Automatic logoff. Workstations should lock themselves after a few minutes idle. A screen left open in a treatment room is an open chart.
- Encryption. Patient data should be encrypted both stored and sent. Most modern EHRs do this — the gaps are usually email, old file shares, and laptops.
- Multi-factor authentication. A password alone is not enough anymore, especially for email and remote access. (See our MFA guide for clinics — it is the cheapest protection you can turn on.)
- Audit logs. Your systems should record who accessed what and when. When something goes wrong, these logs are how you answer the question “how bad is it?”
How the three safeguards work together
Safeguards sound abstract until you watch them handle one event. Take a departing employee — it happens in every clinic, and it touches all three categories at once.
Administrative: your termination checklist says access ends on the last day, and someone owns running it. Physical: keys and badges come back, and the alarm code changes if they had it. Technical: their logins are disabled, shared passwords they knew are changed, and their MFA enrollment is removed. Miss any one of the three and the other two do not save you — a disabled login means nothing if they still have the building key, and a collected key means nothing if their remote access still works. The categories are not three separate chores. They are three views of the same events.
What to do Monday morning
You do not need to fix everything this week. Start here: name your security point person in writing, confirm every employee has their own login, walk the waiting area and check sightlines to screens, and ask when your last backup was actually tested. Four items, one morning, and you are already ahead of most clinics your size.
Then put the risk assessment itself on the calendar — the structured afternoon that turns this article from reading material into a compliance file. Compliance is not a project you finish; it is a rhythm you keep. Monday morning is when the rhythm starts.
Not sure where your practice stands?
Our free network assessment reviews your computers, backups, and security — and gives you a plain-English read on what's solid and what isn't. No scare tactics.
Call (361) 704-1373 or request yours online.
Request your assessment →Not ready to book? Start with the checklist.
Our 10-Point Small Business IT Security Checklist walks you through the ten things that matter most — in plain English, no jargon. Work through it at your own pace. No sales call, no pitch — just the checklist.
Frequently asked questions
Does the HIPAA Security Rule apply to a small clinic, or just hospitals?
It applies to any covered entity that handles electronic protected health information, no matter the size. A two-dentist practice in Rockport has the same legal obligation as a hospital system — the rule just expects safeguards that fit the size of the practice.
What is the difference between the Security Rule and the Privacy Rule?
The Privacy Rule covers all patient information in any form and controls who may use or share it. The Security Rule covers only the electronic form of that information and requires specific safeguards — administrative, physical, and technical — to protect it.
What is the most commonly skipped requirement?
The risk assessment. It is explicitly required, auditors ask for it first, and most small clinics have never done one. It is also the foundation everything else builds on.
Do we need a full-time compliance officer?
No. The rule requires a designated security official, but in a small clinic that is typically the office manager or owner wearing one more hat — documented in writing.
Can our IT provider handle the technical safeguards for us?
A good one should handle most of the technical side — encryption, MFA, patching, backups, audit logs. But administrative safeguards like training and policies still need someone inside the clinic driving them. Ask any provider exactly which safeguards they own; we list the questions in our evaluation guide.