A medical billing company in Tennessee assumed the HIPAA Security Rule didn't apply to them. They weren't a hospital. They weren't a doctor's office. They just processed claims. Then in 2023, the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) came knocking — and MedInform, Inc. paid $100,000 to settle potential HIPAA Security Rule violations. That assumption cost them six figures. If you've ever searched "the HIPAA Security Rule applies to which of the following," you're asking the right question before trouble finds you.

This isn't a trick question on a compliance exam. It's a fundamental distinction that determines whether your organization faces federal enforcement — or flies under the radar. Let me break it down clearly.

The HIPAA Security Rule Applies to Which of the Following? A Direct Answer

The HIPAA Security Rule applies to covered entities and business associates that create, receive, maintain, or transmit electronic protected health information (ePHI). That's it. Two categories. But the devil lives in the details of who falls into each one.

Covered entities include:

  • Health plans (insurance companies, HMOs, employer-sponsored health plans, Medicare, Medicaid)
  • Health care clearinghouses (entities that process nonstandard health information into standard formats)
  • Health care providers who transmit any health information electronically in connection with a HIPAA-covered transaction

Business associates include any person or organization that performs functions or activities on behalf of a covered entity that involve access to ePHI. Think IT vendors, cloud storage providers, billing companies, shredding services, and legal consultants who handle patient data.

The Security Rule does not apply to PHI in purely paper or oral form. It's specifically about electronic protected health information. The Privacy Rule casts a wider net over all forms of PHI. The Security Rule zeroes in on ePHI.

Why the "Business Associate" Category Catches People Off Guard

I've seen it dozens of times: a software company builds a patient portal for a hospital system and never signs a Business Associate Agreement (BAA). A pharmacy outsources its prescription management to a third-party app and nobody asks whether ePHI protections are in place. These aren't hypotheticals. They're Tuesday.

Before the HITECH Act of 2009, business associates lived in a gray zone. Covered entities were responsible for making sure their vendors complied, but OCR couldn't directly enforce against the vendors themselves. HITECH changed that completely. Now, business associates face the same civil and criminal penalties as covered entities under the HIPAA Security Rule.

If your organization touches ePHI on behalf of a covered entity — even if you never see a patient — the Security Rule applies to you. Full stop.

The $4.3 Million Wake-Up Call for a Health System That Ignored Safeguards

In 2016, Advocate Health Care Network agreed to pay $5.55 million to settle multiple potential violations of the HIPAA Security Rule. Among the findings: unencrypted laptops containing ePHI of approximately 4 million patients were stolen, and the organization failed to conduct an adequate risk assessment.

This case illustrates what happens when covered entities treat the Security Rule's requirements as optional. The three categories of safeguards — administrative, physical, and technical — aren't suggestions. They're enforceable mandates.

Administrative Safeguards

These are the policies and procedures that govern how your workforce handles ePHI. Risk assessments, workforce training, access management, and contingency planning all fall here. Administrative safeguards make up the largest section of the Security Rule, and OCR scrutinizes them the hardest during investigations.

If your staff can't articulate your organization's security policies, you have a problem. Workforce training isn't a checkbox — it's the foundation. For organizations navigating this, our HIPAA training catalog covers the specific scenarios your teams face daily.

Physical Safeguards

Facility access controls, workstation security, device and media controls. Who can walk into your server room? What happens to a laptop when an employee is terminated? Where do old hard drives go?

Physical safeguards are the ones most organizations think they've nailed — until a contractor walks out of a building with an unencrypted thumb drive.

Technical Safeguards

Access controls, audit controls, integrity controls, transmission security. Encryption. Multi-factor authentication. Automatic logoff. These are the digital locks on ePHI.

Technical safeguards have become more complex as organizations adopt AI tools for clinical documentation, diagnostics, and patient communication. If your team uses any AI-powered platform that processes ePHI, our course on using AI tools and PHI addresses the specific risks and compliance requirements you need to know about.

Remote Work Changed the Security Rule Calculus

Here's what I've seen shift dramatically since 2020: the perimeter disappeared. When your workforce operates from kitchen tables, coffee shops, and home offices, every single device becomes a potential breach point. The HIPAA Security Rule doesn't care where your employee is sitting. If they're accessing ePHI, the safeguards apply.

That means your organization needs enforceable remote work policies. VPN requirements. Approved device lists. Screen lock timeouts. Rules about who else in the household can see or hear patient data.

Most organizations I work with have remote work policies, but they were written in 2020 under duress and never updated. If that sounds familiar, our Working from Home and PHI training walks your staff through exactly what's required in a remote or hybrid environment.

Who the Security Rule Does NOT Apply To

This matters just as much as knowing who it covers. The HIPAA Security Rule does not apply to:

  • Employers acting in their capacity as employers (even if they have employee health data from HR functions)
  • Life insurers
  • Workers' compensation carriers
  • Most schools and school districts (they fall under FERPA)
  • Law enforcement agencies
  • Municipal offices that don't function as covered entities

A common misconception: just because your organization has health-related data doesn't make you a covered entity. The definition is specific and codified in 45 CFR Part 160. If you don't meet the definition of a covered entity or business associate, the HIPAA Security Rule doesn't apply to you — though state privacy laws might.

Pharmacy Professionals Face Unique Security Rule Pressure

Pharmacies are covered entities. Every one of them. And they handle massive volumes of ePHI daily — prescription records, insurance claims, patient profiles, medication histories. Yet many independent and chain pharmacies operate with security practices that haven't evolved past 2015.

I've walked into pharmacies where the prescription management system runs on an unpatched Windows machine with a shared login. Where patient labels print on an unsecured printer in a back hallway. Where staff text prescription details to patients on personal phones without encryption.

Every one of those scenarios is a potential Security Rule violation. Pharmacy teams need targeted training that speaks to their specific workflows, not generic compliance videos. That's why our HIPAA & HITECH for Pharmacy Professionals course exists — it addresses the real-world scenarios pharmacy staff encounter every shift.

What OCR Actually Looks For During an Investigation

When OCR investigates a potential Security Rule violation — usually triggered by a breach report or a complaint — they follow a predictable pattern. Here's what they zero in on:

  • Risk analysis: Did you conduct one? When was it last updated? Was it comprehensive? This is the number one deficiency OCR finds. Year after year.
  • Risk management: Did you act on the findings from your risk analysis, or did it sit in a drawer?
  • Access controls: Who has access to ePHI, and is that access limited to the minimum necessary?
  • Encryption: Is ePHI encrypted at rest and in transit?
  • Training: Can you prove your workforce received Security Rule training? Can you produce records?
  • BAAs: Do you have signed, current Business Associate Agreements with every vendor that touches ePHI?

The Security Rule requires you to document everything. If you can't produce evidence that you implemented a safeguard, OCR treats it as if you didn't. Documentation isn't bureaucracy — it's your defense.

The Risk Analysis Gap That Costs Organizations Millions

I cannot overstate this: the single most common finding in OCR enforcement actions is the failure to conduct a thorough, organization-wide risk analysis. It appeared in the Advocate Health Care settlement. It appeared in the Premera Blue Cross $6.85 million settlement in 2020. It appears in nearly every corrective action plan OCR publishes.

A proper risk analysis under the HIPAA Security Rule isn't a checklist you download and fill out in an afternoon. It requires identifying every system that touches ePHI, evaluating threats and vulnerabilities, assessing the likelihood and impact of potential risks, and implementing measures to reduce those risks to a reasonable level.

If your last risk analysis was more than 12 months ago — or if you've never done one — you're operating without the most basic requirement the Security Rule demands.

Your Next Step

The HIPAA Security Rule applies to covered entities and business associates. If your organization falls into either category, you're already on the hook for administrative, physical, and technical safeguards that protect ePHI. The question isn't whether the rule applies to you. The question is whether you can prove compliance when OCR comes asking.

Start with training. Start with a risk analysis. Start with getting your BAAs in order. The organizations that treat compliance as an ongoing practice — not a one-time project — are the ones that stay off OCR's wall of shame.