Skip to main content
Compliance · HIPAA

What the Security Rule asks for in force, and what is proposed

Two registers, kept apart. In the Code of Federal Regulations today: the risk analysis at 45 CFR 164.308(a)(1)(ii)(A), marked Required, and the periodic technical and nontechnical evaluation at 164.308(a)(8). In a notice of proposed rulemaking published on 6 January 2025 at 90 FR 898: automated vulnerability scanning and penetration testing, as implementation specifications under a proposed §164.312(h). Comments on that document closed on 7 March 2025 and final action is currently targeted for July 2027. This page quotes each clause, marks which register it belongs to, and dates the reading.

In force today

The clauses the Security Rule carries

45 CFR Part 164, Subpart C, read from the Government Publishing Office’s annual editions. Each row quotes the standard or implementation specification it names and carries the date the text was read.

ClauseWhat it says
§164.308(a)(1)(i) — Security management process “Implement policies and procedures to prevent, detect, contain, and correct security violations.” This is the parent standard, and the three specifications below sit under it.
Read 2026-09-14 from the 2024 GPO annual edition of 45 CFR Part 164, volume 2. Section source note: 68 FR 8376, 20 February 2003, as amended at 78 FR 5694, 25 January 2013.
§164.308(a)(1)(ii)(A) — Risk analysis (Required) “Conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information held by the covered entity or business associate.” The assessment runs to the ePHI the entity holds, and the clause leaves the method to the entity.
Read 2026-09-14. Text identical in the 2024 and 2025 GPO annual editions. This is the live citation for risk analysis — see the proposal block for the renumbering that is often quoted in its place.
§164.308(a)(1)(ii)(B) — Risk management (Required) “Implement security measures sufficient to reduce risks and vulnerabilities to a reasonable and appropriate level to comply with § 164.306(a).” This is the clause that acts on whatever an assessment or a test surfaces.
Read 2026-09-14, 2024 GPO annual edition.
§164.308(a)(1)(ii)(D) — Information system activity review (Required) “Implement procedures to regularly review records of information system activity, such as audit logs, access reports, and security incident tracking reports.”
Read 2026-09-14, 2024 GPO annual edition. The cadence the clause calls regular is set by the entity.
§164.308(a)(8) — Evaluation “Perform a periodic technical and nontechnical evaluation, based initially upon the standards implemented under this rule and, subsequently, in response to environmental or operational changes affecting the security of electronic protected health information, that establishes the extent to which a covered entity’s or business associate’s security policies and procedures meet the requirements of this subpart.” Note what is being evaluated: your security policies and procedures, against the whole of Subpart C.
Read 2026-09-14, 2025 GPO annual edition. A standard in its own right and mandatory as written — the Required and Addressable markers at §164.306(d) attach to implementation specifications. Its stated trigger is periodicity plus environmental or operational change.
§164.306(b) — Flexibility of approach “Covered entities and business associates may use any security measures that allow the covered entity or business associate to reasonably and appropriately implement the standards and implementation specifications as specified in this subpart” — factoring in size and complexity, technical infrastructure, hardware and software security capabilities, the cost of the measures, and the probability and criticality of potential risks to ePHI.
Read 2026-09-14, 2024 GPO annual edition. Source note: 68 FR 8376, 20 February 2003; 68 FR 17153, 8 April 2003; 78 FR 5693, 25 January 2013.
§164.316(b)(1), (b)(2)(i), (b)(2)(iii) — Documentation (b)(1): “Maintain the policies and procedures implemented to comply with this subpart in written (which may be electronic) form”, and keep a written record of any action, activity or assessment this subpart requires to be documented. (b)(2)(i) Time limit (Required): “Retain the documentation required by paragraph (b)(1) of this section for 6 years from the date of its creation or the date when it last was in effect, whichever is later.” (b)(2)(iii) Updates (Required): “Review documentation periodically, and update as needed, in response to environmental or operational changes affecting the security of the electronic protected health information.”
Read 2026-09-14, 2024 GPO annual edition. Source note: 68 FR 8376, 20 February 2003, as amended at 78 FR 5695, 25 January 2013. The six-year clock is the reason a report is a document rather than a conversation.

§164.308(a)(1)(i) — Security management process

What it says
“Implement policies and procedures to prevent, detect, contain, and correct security violations.” This is the parent standard, and the three specifications below sit under it.

Read 2026-09-14 from the 2024 GPO annual edition of 45 CFR Part 164, volume 2. Section source note: 68 FR 8376, 20 February 2003, as amended at 78 FR 5694, 25 January 2013.

§164.308(a)(1)(ii)(A) — Risk analysis (Required)

What it says
“Conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information held by the covered entity or business associate.” The assessment runs to the ePHI the entity holds, and the clause leaves the method to the entity.

Read 2026-09-14. Text identical in the 2024 and 2025 GPO annual editions. This is the live citation for risk analysis — see the proposal block for the renumbering that is often quoted in its place.

§164.308(a)(1)(ii)(B) — Risk management (Required)

What it says
“Implement security measures sufficient to reduce risks and vulnerabilities to a reasonable and appropriate level to comply with § 164.306(a).” This is the clause that acts on whatever an assessment or a test surfaces.

Read 2026-09-14, 2024 GPO annual edition.

§164.308(a)(1)(ii)(D) — Information system activity review (Required)

What it says
“Implement procedures to regularly review records of information system activity, such as audit logs, access reports, and security incident tracking reports.”

Read 2026-09-14, 2024 GPO annual edition. The cadence the clause calls regular is set by the entity.

§164.308(a)(8) — Evaluation

What it says
“Perform a periodic technical and nontechnical evaluation, based initially upon the standards implemented under this rule and, subsequently, in response to environmental or operational changes affecting the security of electronic protected health information, that establishes the extent to which a covered entity’s or business associate’s security policies and procedures meet the requirements of this subpart.” Note what is being evaluated: your security policies and procedures, against the whole of Subpart C.

Read 2026-09-14, 2025 GPO annual edition. A standard in its own right and mandatory as written — the Required and Addressable markers at §164.306(d) attach to implementation specifications. Its stated trigger is periodicity plus environmental or operational change.

§164.306(b) — Flexibility of approach

What it says
“Covered entities and business associates may use any security measures that allow the covered entity or business associate to reasonably and appropriately implement the standards and implementation specifications as specified in this subpart” — factoring in size and complexity, technical infrastructure, hardware and software security capabilities, the cost of the measures, and the probability and criticality of potential risks to ePHI.

Read 2026-09-14, 2024 GPO annual edition. Source note: 68 FR 8376, 20 February 2003; 68 FR 17153, 8 April 2003; 78 FR 5693, 25 January 2013.

§164.316(b)(1), (b)(2)(i), (b)(2)(iii) — Documentation

What it says
(b)(1): “Maintain the policies and procedures implemented to comply with this subpart in written (which may be electronic) form”, and keep a written record of any action, activity or assessment this subpart requires to be documented. (b)(2)(i) Time limit (Required): “Retain the documentation required by paragraph (b)(1) of this section for 6 years from the date of its creation or the date when it last was in effect, whichever is later.” (b)(2)(iii) Updates (Required): “Review documentation periodically, and update as needed, in response to environmental or operational changes affecting the security of the electronic protected health information.”

Read 2026-09-14, 2024 GPO annual edition. Source note: 68 FR 8376, 20 February 2003, as amended at 78 FR 5695, 25 January 2013. The six-year clock is the reason a report is a document rather than a conversation.

The two markers

What Required and Addressable each oblige, under §164.306(d)

The word in parentheses after an implementation specification title is load-bearing, and it is read wrongly in both directions. This is the published vocabulary and what each state asks of an entity.

What Required and Addressable each oblige, under §164.306(d)
StateWhat it meansWhat follows
Required §164.306(d)(1): where an implementation specification is required, the word “Required” appears in parentheses after its title. Risk analysis, risk management, information system activity review and both documentation specifications above all carry it. Implement the specification.
Addressable The entity assesses whether the specification is a reasonable and appropriate safeguard in its environment, and then either implements it, or documents why it is not reasonable and appropriate in that environment and implements an equivalent alternative measure where reasonable and appropriate. Implement it, or produce the documented assessment and the equivalent alternative. Either path ends in a document, and §164.316(b) puts that document on the six-year clock.
The standard itself A standard such as the evaluation standard at §164.308(a)(8) is mandatory as written. The two markers are properties of the implementation specifications that sit beneath a standard, which is where §164.306(d) assigns them. Mandatory as written.
Key
  • Implement it as written
  • Assess, then implement or document and substitute

The proposal of 6 January 2025

What the proposed rule would add, and where the document stands

Everything in this block is proposed. Every clause number in it is proposed numbering, reproduced so that a reader who has met one elsewhere can tell which register it came from.

HIPAA Security Rule notice of proposed rulemaking — 90 FR 898, RIN 0945-AA22 As of 2026-09-14
  • Published in the Federal Register on 6 January 2025, Vol. 90, No. 3, Proposed Rules, beginning at page 898, amending 45 CFR Parts 160 and 164. The ACTION line reads “Notice of proposed rulemaking; notice of Tribal consultation.”
  • The comment period closed on 7 March 2025. There is no final rule. The OMB Unified Agenda entry for RIN 0945-AA22 targets July 2027 for final action, moved back from a spring 2026 target — so the schedule has already slipped once.
  • Proposed §164.312(h) would create a vulnerability management standard: deploy technical controls, in accordance with the entity’s patch management policies and procedures, to identify and address technical vulnerabilities in relevant electronic information systems.
  • Proposed §164.312(h)(2)(i)(A) would have an entity “conduct automated vulnerability scans to identify technical vulnerabilities” in those systems “in accordance with the covered entity’s or business associate’s risk analysis … or at least once every six months, whichever is more frequent”. On that wording six months is a floor beneath a risk-driven cadence rather than a fixed interval. Proposed (h)(2)(i)(B) would have the scanning technology itself reviewed and tested at least once every 12 months or in response to environmental or operational changes, whichever is more frequent.
  • Proposed §164.312(h)(2)(iii) would have penetration testing “performed by a qualified person”, “at least once every 12 months or in accordance with the covered entity’s or business associate’s risk analysis …, whichever is more frequent”. A qualified person is defined in the proposal by knowledge of and experience with generally accepted cybersecurity principles and methods for ensuring the confidentiality, integrity and availability of ePHI.
  • Proposed §164.306(c) would collapse the present §164.306(c) and (d) into a single paragraph covering both standards and implementation specifications, and remove the distinction between addressable and required implementation specifications.
  • The proposal would also renumber risk analysis to §164.308(a)(2). In force, §164.308(a)(2) is the assigned security responsibility standard — “Identify the security official who is responsible for the development and implementation of the policies and procedures required by this subpart” — and risk analysis is at §164.308(a)(1)(ii)(A).

Deliberately excluded

  • Nothing in this block is in force. The 2025 GPO annual edition of 45 CFR 164.308 carries the 2013 text, its source note ending at 78 FR 5694, 25 January 2013, which is independent corroboration that the proposal has not landed.
  • A proposed clause number is not a citation to law, and this page never uses one as though it were. Where a number appears above, the word proposed appears with it.
  • Proposed text can change between a notice of proposed rulemaking and a final rule. The figures above are what the January 2025 document proposed on the date it was read, not a settled cadence.

How the output maps

Which part of an engagement feeds which clause

A technical engagement is an input to three of the clauses in force and to the documentation standard that holds all of them. Each card names the clause and stops at the edge of it.

§164.308(a)(1)(ii)(A)

One input to the risk analysis

The assessment the clause asks for runs to the confidentiality, integrity and availability of the ePHI your organisation holds, across people, process and technology. Testing supplies one part of it: the vulnerabilities demonstrably reachable on the systems in scope, each with the exchange that proved it. The assessment is the wider document and it stays yours.

§164.308(a)(1)(ii)(B)

A remediation record for risk management

The specification asks for security measures sufficient to reduce risks and vulnerabilities to a reasonable and appropriate level. Findings carry through open, fixed, retested and closed, and a finding closes on a retest that cannot reproduce it — which is what shows a measure did the work it was chosen for.

§164.308(a)(8)

Technical evidence for the evaluation

The evaluation standard is expressly technical and nontechnical, and what it establishes is the extent to which your security policies and procedures meet Subpart C. An engagement produces technical evidence that feeds it: what was tested, what was found, what was remediated, and what a retest confirmed. The evaluation is the broader exercise and it sits with you.

§164.316(b)

Documentation built for a six-year file

The documentation standard requires written records retained for six years from creation or from the date last in effect, whichever is later. Scope agreements, approval records, the report and every retest result are issued as documents you retain on that clock, in a form that reads to somebody who was not in the room.

Where the mapping stops

The difference between an input and the obligation

Risk analysis under §164.308(a)(1)(ii)(A) is an accurate and thorough assessment of risks and vulnerabilities to the confidentiality, integrity and availability of the ePHI an entity holds — all of it, wherever it sits, including where the exposure is a person or a procedure rather than a system. The evaluation standard at §164.308(a)(8) is wider again: technical and nontechnical, measuring your security policies and procedures against the subpart. A penetration test is an input to both and the whole of neither, and any page telling you otherwise is selling you a document your assessor will read past. What a test usefully changes is the quality of one part of that assessment — it turns an estimate into evidence. A finding arrives with the request and response that produced it, steps your own engineer can follow, a CVSS v4.0 vector printed so the score can be recomputed, and the CWE. Where B-52 maps a finding to a framework, it maps it to the clause the finding bears on and names the clause, which is also what makes the mapping checkable.

Which model to buy

Whose verification the record carries

All three delivery models cover the same eleven classes and produce the same evidence per finding. What differs is whether a senior Security Brigade auditor was inside the engagement that produced it.

Whose verification the record carries
StateWhat it meansWhat follows
Autonomous, expert verified A senior Security Brigade auditor verifies every finding before any of it reaches you, and the engagement record carries that verification on its face. The starting point wherever the report leaves your organisation — to an assessor, to a covered entity auditing you as a business associate, or into the file a successor security official will inherit.
Human led A senior auditor runs the engagement with B-52 underneath: sets the scope, directs where the depth goes, and owns the report that comes out of it. Where the environment is unusual, where ePHI moves through paths a scope has to be argued around, or where a prior finding needs a reasoned position rather than a record.
Fully autonomous Terminal A person authorises scope and targets, and from there the run proceeds without one. There is no auditor inside the engagement. Built for coverage between the engagements that produce your documentation.
Key
  • A senior auditor is inside the engagement
  • Scope sign-off, then no auditor in the engagement
  • TerminalNo state follows this one

Why the model is the decision

Documentation is the deliverable, and documentation is attributable

Under §164.316(b)(1) the record is written and kept; under (b)(2)(i) it is retained for six years from creation or from the date it was last in effect, whichever is later. Six years is long enough that the person reading a report was not in the room when it was produced, and a record read that far downstream is read for who stood behind it as much as for what it found. That is the practical reason a regulated reader starts from the expert-verified model: every finding in it has been checked by a senior auditor at Security Brigade, which has been CERT-In empanelled since 2008 and is ISO 27001 certified. Where you also run the fully autonomous model, what it gives you is coverage in the months between those engagements, and the $500 entry tier buys one scan of one application or target if you would rather see that coverage on your own estate than read about it.

What you retain

What the report carries into the six-year file

Written for the reader §164.316(b) creates: somebody examining the record years later, without access to the people who produced it.

Per finding

The request and response behind each finding

What was sent and what came back, with the part that demonstrates the defect marked, and reproduction steps written so your own engineer can follow them years later rather than take the finding on trust.

Per finding

Severity with its vector, and the weakness class

CVSS v4.0 with the vector printed so the score can be recomputed rather than accepted, the CWE, and the clause the finding is reported against.

Per finding

A lifecycle that ends in a retest

Open, fixed, retested, closed. Closure is recorded against a retest, and the retest result stays in the file beside the original finding — which is what a risk management measure looks like once it has been shown to work.

Per engagement

Scope, authorisation and the three gates

What was in scope, who authorised it, when the testing ran, and what the three approval gates permitted or refused: destructive or state-changing actions, persistence and movement past the entry host, and live credentials or real customer data. On a system holding ePHI, the third gate is the one an assessor asks about first.

The boundary

What this page claims, and where it stops

A HIPAA page is where a security vendor is most tempted to promote a proposal into law. Each row below marks a point where this one stays with the text instead.

The position
Two registers, never mixed Every clause quoted in the first block is in the Code of Federal Regulations as published in the 2024 and 2025 annual editions. Every clause in the proposal block is proposed numbering from a notice of proposed rulemaking published on 6 January 2025 at 90 FR 898 under RIN 0945-AA22, on which comments closed on 7 March 2025 and for which final action is currently targeted for July 2027. Each number on this page says which register it belongs to.
Mapping, not issuing Findings are mapped to the clauses a framework names. Certification and attestation are issued by bodies appointed for that purpose, and that is separate work from testing. Security Brigade claims two instruments and only two — CERT-In empanelled since 2008, and ISO 27001 certified — and the B-52 platform holds none of its own.
Cadence follows the instrument that carries it Where an interval appears on this page it is attached to the clause it comes from: the six-year retention at §164.316(b)(2)(i), and the figures in the January 2025 proposal, which are proposed. The evaluation standard at §164.308(a)(8) is periodic, with the trigger stated in the clause itself as environmental or operational changes affecting the security of ePHI, and OCR’s guidance on risk analysis treats risk analysis as an ongoing process integrated into business processes, whose frequency varies among covered entities.
HHS Office for Civil Rights, Guidance on Risk Analysis Requirements under the HIPAA Security Rule. Summarised here rather than quoted: hhs.gov refused automated retrieval on 2026-09-14, so the wording reaches this page through a search restricted to hhs.gov rather than a first-hand read of the PDF.
Your determination stays yours Whether you are a covered entity or a business associate, which clauses reach the systems you run, and what is reasonable and appropriate given your size, complexity, technical infrastructure and cost profile under §164.306(b), are determinations for you and your advisers. What is stated here is what each clause says, on the date it was read, and what an engagement produces.

Two registers, never mixed

The position
Every clause quoted in the first block is in the Code of Federal Regulations as published in the 2024 and 2025 annual editions. Every clause in the proposal block is proposed numbering from a notice of proposed rulemaking published on 6 January 2025 at 90 FR 898 under RIN 0945-AA22, on which comments closed on 7 March 2025 and for which final action is currently targeted for July 2027. Each number on this page says which register it belongs to.

Mapping, not issuing

The position
Findings are mapped to the clauses a framework names. Certification and attestation are issued by bodies appointed for that purpose, and that is separate work from testing. Security Brigade claims two instruments and only two — CERT-In empanelled since 2008, and ISO 27001 certified — and the B-52 platform holds none of its own.

Cadence follows the instrument that carries it

The position
Where an interval appears on this page it is attached to the clause it comes from: the six-year retention at §164.316(b)(2)(i), and the figures in the January 2025 proposal, which are proposed. The evaluation standard at §164.308(a)(8) is periodic, with the trigger stated in the clause itself as environmental or operational changes affecting the security of ePHI, and OCR’s guidance on risk analysis treats risk analysis as an ongoing process integrated into business processes, whose frequency varies among covered entities.

HHS Office for Civil Rights, Guidance on Risk Analysis Requirements under the HIPAA Security Rule. Summarised here rather than quoted: hhs.gov refused automated retrieval on 2026-09-14, so the wording reaches this page through a search restricted to hhs.gov rather than a first-hand read of the PDF.

Your determination stays yours

The position
Whether you are a covered entity or a business associate, which clauses reach the systems you run, and what is reasonable and appropriate given your size, complexity, technical infrastructure and cost profile under §164.306(b), are determinations for you and your advisers. What is stated here is what each clause says, on the date it was read, and what an engagement produces.

How these citations were read

Primary sources, and the one that could not be reached

Source record for every clause quoted on this page As of 2026-09-14
  • All CFR text was read from govinfo.gov, the Government Publishing Office’s own repository — 45 CFR Part 164, volume 2, 2024 and 2025 annual editions. Same publisher, not a third-party mirror.
  • §164.308 was compared across both annual editions. The text is identical in the two, and the section source note ends at 78 FR 5694, 25 January 2013.
  • The proposed regulatory text was extracted from the official GPO PDF of 90 FR 898, because the HTML granule of that document stops before the regulatory-text section.
  • ecfr.gov and federalregister.gov both redirected automated retrieval to an interstitial page on 2026-09-14, and hhs.gov returned HTTP 403. Where that affected a citation, the row using it says so.

Deliberately excluded

  • The OCR risk analysis guidance is summarised rather than quoted, for the reason above, and it is cited for one point only: that the cadence of risk analysis is set by the entity and varies among them.
  • No clause number on this page came from a vendor summary or a secondary commentary. Where a number is proposed, the word proposed sits beside it.

Scope it against the clause you are filing under

Where the report is read outside your organisation, the expert-verified model is the one to start from. Scoping settles which systems hold ePHI, what goes in scope, and what the engagement has to produce for the six-year file.