+91 98804 42758

HIPAA Safeguards Explained

18 standards across 3 categories, here's exactly what each one requires

Sudhakar Varma Delivery Head, Avantcert
August 13, 2026 9 min read

The Short Answer

The HIPAA Security Rule contains 18 standards across three categories: 9 Administrative Safeguards, 4 Physical Safeguards, and 5 Technical Safeguards. Each standard breaks down further into implementation specifications that are either required or addressable. See our HIPAA compliance guide for the broader picture, or our HIPAA compliance cost breakdown for the budget side.


The 18 Standards by Category

Administrative Safeguards (9 standards)

  • Security Management Process — the risk analysis and risk management foundation everything else builds on
  • Assigned Security Responsibility — a named individual accountable for security
  • Workforce Security — authorization and supervision of workforce access to PHI
  • Information Access Management — access authorization and establishment procedures
  • Security Awareness and Training — workforce training, including periodic reminders
  • Security Incident Procedures — identifying and responding to security incidents
  • Contingency Plan — data backup, disaster recovery, and emergency mode operation
  • Evaluation — periodic technical and non-technical evaluation of safeguards
  • Business Associate Contracts and Other Arrangements — written assurances from vendors touching PHI

Physical Safeguards (4 standards)

  • Facility Access Controls — limiting physical access to facilities housing PHI systems
  • Workstation Use — policies governing how workstations accessing PHI are used
  • Workstation Security — physical safeguards restricting access to workstations
  • Device and Media Controls — disposal, reuse, and movement of hardware and media containing PHI

Technical Safeguards (5 standards)

  • Access Control — unique user identification, emergency access, automatic logoff, encryption
  • Audit Controls — hardware, software, and procedural mechanisms recording system activity
  • Integrity — protecting PHI from improper alteration or destruction
  • Person or Entity Authentication — verifying that whoever seeks access is who they claim to be
  • Transmission Security — guarding against unauthorized access to PHI transmitted over networks

9 + 4 + 5 = 18 standards. Each one contains implementation specifications underneath it, some marked required, some addressable.

Required vs Addressable: The Distinction That Confuses Most People

Required specifications must be implemented exactly as written, no discretion. Addressable specifications must still be assessed for whether they're reasonable and appropriate given your environment, and if you decide not to implement one as written, you must document that decision and implement a documented equivalent alternative that achieves the same protective purpose.

Addressable does not mean optional. Skipping an addressable specification with no documented risk-based justification and no alternative control is a compliance gap, not a valid interpretation of the rule.

Not sure which safeguards apply to your specific setup?

A risk assessment maps all 18 standards against your actual systems and tells you what's genuinely applicable.

Get a Free Quote

Where Software Companies Usually Spend the Most Effort

Technical Safeguards tend to demand the most work from a software company, since access control, audit logging, and transmission security map directly onto application architecture decisions the engineering team controls. Physical Safeguards are often lighter for a cloud-native company, since a HIPAA-eligible cloud provider's own facility controls cover much of the physical-layer requirement, though your own office and device policies still need addressing.

The 18 Safeguards Are Part of HIPAA, Not All of It

These 18 standards belong specifically to the Security Rule. HIPAA also includes the Privacy Rule, governing how PHI can be used and disclosed, and the Breach Notification Rule, governing what happens after an incident. Satisfying all 18 Security Rule safeguards is necessary but doesn't by itself cover Privacy Rule or Breach Notification Rule obligations.

Ready to map the 18 safeguards to your organization?

We've guided 3,000+ organisations through HIPAA risk assessment and safeguard implementation.

Talk to an Avantcert Expert

Frequently asked questions about HIPAA safeguards

How many HIPAA safeguards are there in total?

18 standards under the Security Rule: 9 Administrative Safeguards, 4 Physical Safeguards, and 5 Technical Safeguards. Each standard breaks down further into specific implementation specifications, some required, some addressable.

What does "addressable" actually mean if it isn't optional?

Addressable means you must assess whether the specification is reasonable and appropriate for your organization, and if you decide not to implement it as written, you must document why and implement an equivalent alternative that achieves the same protective purpose. Doing nothing and calling it addressable is not a valid interpretation.

Which safeguard category is usually the most work for a software company?

Technical Safeguards, generally, since access control, audit controls, and transmission security map directly onto application architecture decisions that a software company controls. Physical Safeguards are often lighter for a cloud-native company, since a HIPAA-eligible cloud provider handles much of the facility-level requirement.

Do all 18 safeguards apply to every organization equally?

The standards apply universally, but how they're satisfied depends on your risk assessment. A small startup and a hospital system both address all 18 standards, but the specific controls, policies, and technical measures implemented under each will look very different based on actual risk and organizational scale.

Which Administrative Safeguard standard is usually the most involved to implement?

Security Management Process, since it encompasses the risk analysis itself along with risk management, sanction policy, and information system activity review. It's effectively the foundation the other eight Administrative Safeguards standards build on.

Does satisfying all 18 safeguards mean an organization is fully HIPAA compliant?

The Security Rule's 18 safeguards are necessary but not the whole of HIPAA. The Privacy Rule and Breach Notification Rule impose separate obligations around use and disclosure of PHI and incident reporting, so Security Rule safeguards are one major component of compliance, not the entirety of it.

About Avantcert. Avantcert is a compliance consultancy that has guided 3,000+ organisations across 40+ markets through HIPAA risk assessment, remediation, and independent attestation. See our HIPAA compliance service or request a free quote.

Ready to get certified?

Join 3,000+ organizations that trust Avantcert. Get a free, scoped quote today.