Security Rule
CIPP/US glossary · Last reviewed: · By Victor Humenhuk (CIPP/US certified)
Security Rule - The HIPAA rule (finalized 2003, modified 2013) setting minimum security requirements for ePHI.
In the CIPP/US body of knowledge, Security Rule comes up under Chapter 8: Medical Privacy.
Security Rule in context
- Key principles include [[zero trust]], [[least privilege]] with [[role-based access controls]] (required by the HIPAA Security Rule), [[defense in depth]], and [[security by default]]. (The Adversarial Mindset: STRIDE, Zero Trust and Least Privilege)
- Finalized in 2003, the ==Security Rule covers only ePHI== and binds both covered entities and business associates. (The HIPAA Security Rule)
- In ==February 2025== OCR imposed a ==$1.5 million== penalty on [[Warby Parker]] for ==HIPAA Security Rule== failures. (Online Tracking Technologies, HIPAA, and the Warby Parker Penalty)
Where Security Rule is covered in the CIPP/US study notes
Related terms
- Addressable specification
- Required specification
Test yourself on Security Rule
Recognising a definition is not the same as applying it in an exam scenario. Work through the free CIPP/US practice questions, or read the full CIPP/US study guide - every study note is free.