In 2018, the University of Texas MD Anderson Cancer Center lost a Supreme Court appeal and got stuck with a $4.3 million penalty — all because three unencrypted devices went missing over a span of years. No hacker broke in. No insider sold data. Laptops and thumb drives simply walked out the door. That case tells you everything about what the HIPAA Security Rule's broader objectives were designed to accomplish: build a culture of protection around electronic protected health information (ePHI) so that a single lost device doesn't become a catastrophe.

If you've landed here because you're studying for a certification, answering an exam question, or trying to understand why your compliance officer keeps pushing new policies — this post breaks it all down with real enforcement actions and practical advice.

What Were the HIPAA Security Rule's Broader Objectives Designed to Do?

The HIPAA Security Rule's broader objectives were designed to ensure the confidentiality, integrity, and availability of all ePHI that a covered entity or business associate creates, receives, maintains, or transmits. That three-part framework — confidentiality, integrity, availability — is the backbone of every safeguard requirement in the rule.

But HHS didn't stop there. The rule was also designed to protect against reasonably anticipated threats and hazards, guard against reasonably anticipated impermissible uses or disclosures, and ensure workforce compliance. Those four objectives appear in 45 CFR Part 164, Subpart C, and every audit OCR conducts traces back to them.

Confidentiality: Only the Right Eyes

Confidentiality means ePHI is accessible only to authorized individuals. I've seen clinics where every front-desk employee had admin-level access to the EHR. No role-based controls. No audit logs reviewed. That's a confidentiality failure waiting to become an OCR investigation.

When Anthem Inc. settled with HHS for $16 million in 2018 after a breach affecting nearly 79 million people, insufficient access controls played a starring role. Attackers used spear-phishing to harvest credentials — and the credentials they stole had far too much reach.

Integrity: No Unauthorized Alterations

Integrity means ePHI hasn't been altered or destroyed in an unauthorized manner. Think about a pharmacy where a technician can modify prescription records without an audit trail. That's not just a compliance gap — it's a patient safety crisis.

If your organization handles medication records, the stakes multiply. Our HIPAA & HITECH training for pharmacy professionals walks through exactly how integrity controls apply in dispensing workflows.

Availability: Accessible When Needed

Availability means ePHI is accessible and usable on demand by authorized persons. Ransomware attacks have made this objective painfully relevant. When Hollywood Presbyterian Medical Center paid a $17,000 ransom in 2016 to regain access to its own systems, it exposed what happens when availability safeguards fail.

Your disaster recovery plan, your backup procedures, your contingency operations — they all exist to serve this single objective.

The Four Pillars Behind the Rule's Design

Let me restate the Security Rule's broader objectives in plain language, because I've found that most workforce members never see the actual regulatory text:

  • Ensure confidentiality, integrity, and availability of all ePHI you create, receive, maintain, or transmit.
  • Protect against reasonably anticipated threats to the security or integrity of ePHI.
  • Protect against reasonably anticipated impermissible uses or disclosures.
  • Ensure compliance by your workforce.

That fourth pillar — workforce compliance — is the one most organizations underestimate. You can buy the best firewall on the market. But if a staff member shares login credentials over a text message, your technical investment means nothing.

The $2.1 Million Question: What Happens When You Ignore These Objectives?

In 2019, Sentara Hospitals paid $2.175 million to settle with OCR after sending billing statements containing PHI to wrong patient addresses — and then failing to properly report the breach. OCR's investigation revealed that Sentara didn't classify the mailing error as a breach because "only" billing information was exposed, not clinical data.

That interpretation directly contradicts the Security Rule's objectives. PHI is PHI. The rule doesn't rank sensitivity. Sentara's failure to conduct a proper risk assessment of the incident — and report it under the Breach Notification Rule — compounded the violation.

The lesson: the broader objectives don't give you wiggle room to decide what "counts" as protected information.

How the Objectives Shape Your Day-to-Day Compliance

Risk Analysis Is the Starting Line

Every covered entity and business associate must conduct a thorough risk analysis. Not once. Not annually. Continuously. OCR has cited insufficient risk analysis in more settlements than any other single deficiency. The HHS guidance on risk analysis spells out the expectation: identify every system that touches ePHI and evaluate the threats to confidentiality, integrity, and availability.

In my experience, organizations that treat risk analysis as an annual checkbox end up with blind spots — especially around newer technologies like AI-powered transcription tools or cloud-based scheduling platforms.

AI Tools Are a New Frontier for These Objectives

Here's a scenario I've encountered more than once in 2026: a clinician pastes patient notes into an AI chatbot to generate a referral letter. That ePHI just left the organization's control. No BAA. No encryption in transit to the AI provider's servers. No risk assessment conducted before adopting the tool.

The Security Rule's objectives apply to every system that touches ePHI — including AI. If you haven't trained your staff on this, our Using AI Tools & PHI course covers the exact scenarios that trip up covered entities.

Remote Work Multiplies the Attack Surface

When your workforce accesses ePHI from home networks, coffee shops, or shared family computers, every one of the Security Rule's broader objectives gets harder to achieve. Confidentiality is at risk on shared screens. Integrity is at risk without proper device management. Availability is at risk when home internet goes down and there's no contingency plan.

I've worked with organizations that had excellent in-office controls but zero remote work policies. If that sounds familiar, our Working from Home & PHI training fills that gap fast.

Why Workforce Training Is the Fourth Objective — Not an Afterthought

HHS put workforce compliance in the same sentence as threat protection for a reason. Technology fails when people fail. The best encryption protocol in the world doesn't help when an employee emails a spreadsheet of patient SSNs to their personal Gmail.

OCR's enforcement history bears this out. In settlement after settlement — from the $5.55 million penalty against Advocate Health Care in 2016 to the $3 million Cottage Health settlement in 2019 — the root cause traces back to a workforce member doing something a proper training program would have prevented.

Training isn't about checking a box. It's about making sure every person in your organization understands that the HIPAA Security Rule's broader objectives were designed to protect ePHI at every touchpoint — and that they are one of those touchpoints.

How to Audit Your Alignment with the Security Rule's Objectives

Here's a quick gut-check I give to every organization I advise. Score yourself honestly:

  • Confidentiality: Do you have role-based access controls, and do you review access logs at least quarterly?
  • Integrity: Can you detect unauthorized changes to ePHI, and do you maintain audit trails?
  • Availability: Have you tested your backup and disaster recovery plan in the last 12 months?
  • Threat Protection: Is your risk analysis current, and does it account for new technologies like AI tools and remote work?
  • Workforce Compliance: Has every member of your workforce — including contractors — completed Security Rule training within the last year?

If you answered "no" to even one of these, you have a gap that OCR could cite in an investigation. And investigations don't always start with a breach. Sometimes they start with a disgruntled employee's complaint.

The Bottom Line: Protection by Design, Not by Accident

The HIPAA Security Rule's broader objectives were designed to create a systematic, ongoing framework for protecting ePHI. Not a one-time project. Not a binder on a shelf. A living, breathing compliance program that adapts as threats evolve — from lost laptops in 2012 to AI-assisted data leaks in 2026.

Your organization's job is to translate those four objectives into policies, procedures, technology, and training that actually work on a Tuesday afternoon when a staff member is rushing between patients and tempted to take a shortcut.

That's where compliance lives or dies. Not in the regulation's text — in your hallways, your inboxes, and your workflows. Build your program around these objectives, and you won't just pass an audit. You'll actually protect your patients.

Ready to bring your workforce up to speed? Browse the full HIPAA training catalog and find the right course for every role in your organization.