IT Solutions for Healthcare: HIPAA Technical Safeguards
October 8th, 2026
The HIPAA Security Rule divides its requirements into three categories: administrative, physical, and technical safeguards. Most healthcare organizations can produce a policy binder for the first two. The technical safeguards are the ones that live or die on your actual infrastructure, and they are the ones an auditor will ask a system administrator to demonstrate rather than describe.
For a practice, clinic, or hospital department, that distinction matters. A written policy that says ePHI is encrypted does not satisfy the standard if nobody can show where the encryption is enforced. Here is what the technical safeguards require, and where healthcare environments usually have gaps.
The Five Technical Standards
The Security Rule names five technical safeguard standards, each with implementation specifications marked either required or addressable:
- Access control (164.312(a)): unique user identification, emergency access procedure, automatic logoff, encryption and decryption
- Audit controls (164.312(b)): hardware, software, and procedural mechanisms that record and examine activity in systems containing ePHI
- Integrity (164.312(c)): protections against improper alteration or destruction of ePHI
- Person or entity authentication (164.312(d)): verify that the person seeking access is who they claim to be
- Transmission security (164.312(e)): integrity controls and encryption for ePHI in transit
Addressable does not mean optional. It means you either implement the specification or document why it is not reasonable and appropriate, and implement an equivalent alternative. Auditors read that documentation closely.
Access Control Is an Identity Problem
Unique user identification is the required floor, and shared logins are the most common place healthcare organizations fall below it. A nursing station account that six people use cannot produce a meaningful audit trail, which means the access control failure and the audit control failure are the same finding.
What a defensible implementation looks like:
- Individual accounts tied to a directory, not local logins on each workstation
- Role based access, so a scheduler and a clinician see different records
- Multi-factor authentication on anything reachable from outside the building
- Automatic logoff on clinical workstations, with a timeout short enough to survive a shift change
- A documented break-glass procedure for emergencies, and a review of every use of it
The break-glass piece is where policy and practice usually diverge. Clinicians will find a way into the record during an emergency. The question is whether that access is designed in advance and logged, or improvised and invisible. This is also the layer where general network security work and HIPAA compliance stop being separate projects, because identity is the control both depend on.
Audit Controls: If You Cannot Show It, You Cannot Prove It
Audit controls are required, and they are the safeguard most often implemented as a logging setting nobody reads. Logs that exist but are never reviewed satisfy the letter of the standard and fail its purpose, because the point is detecting inappropriate access before a patient complaint arrives.
What to build:
- Centralize logs from the EHR, the directory, and the file shares holding ePHI into one searchable location
- Set retention that matches your state record retention requirement, not the default 30 days
- Alert on specific events: after-hours record access, bulk exports, terminated accounts still active, repeated failed logins
- Review access to VIP and employee records on a schedule, and keep the review
That last item is the one that turns a technical control into a document an auditor will accept.
The Devices Nobody Counts
This is the gap we see most often in healthcare environments, and it has nothing to do with the EHR. Patient information passes through a long tail of equipment that sits outside the clinical system and outside most IT inventories:
- Multifunction printers and copiers, many with internal hard drives that store every job they process
- Scanners that cache a document image before it reaches its destination
- Fax servers and analog lines still carrying referrals and lab results
- Dictation and transcription systems
- Mobile devices and tablets used at the bedside
Each one can hold ePHI at rest with no encryption and no access control. A copier pulled off lease and returned with its drive intact is a breach waiting on a disclosure requirement. The fixes are straightforward once someone owns the device list:
- Authenticated print release, so a job does not print until the badge or login appears at the machine
- Authenticated scanning and secure firmware from the manufacturer
- Encrypted drives, and documented sanitization before disposal or lease return
- Every printer and scanner included in the risk analysis, not just the servers
Paper is the same problem in a slower form. Legacy records in a file room have no access log at all until they are digitized. That work is a document management and scanning project before it is a compliance project, and it is the part of HIPAA readiness that healthcare organizations can actually finish. One Indiana hospital needed 1.5 million patient records indexed and secured inside a 90 day window before the storage building came down, and you can read how that patient records scanning project ran.
Transmission Security and Business Associate Agreements
Encryption in transit is addressable, and in practice there is no reasonable alternative for ePHI. Email carrying patient information needs transport encryption at minimum, and a secure portal or encrypted message is the better answer. Remote access belongs on a VPN with MFA, never on a published desktop with a password.
The requirement that catches healthcare organizations off guard is the business associate agreement. Every vendor that creates, receives, maintains, or transmits ePHI on your behalf needs a signed BAA, and that list is longer than most people expect:
- Your cloud and hosting providers
- The software behind your print fleet and its reporting
- Your phone system vendor, if calls are recorded
- Anything that stores or indexes patient documents
- Your IT provider itself
If a vendor will not sign a BAA, that is your answer about whether the tool should touch patient data.
Start With the Risk Analysis
None of this works as a checklist applied from the outside. The Security Rule requires a risk analysis first, and failures to conduct one are among the most frequently cited findings in HIPAA enforcement. The analysis is what tells you which of the safeguards above are actually missing in your environment, as opposed to missing on paper.
That is the shape of managed IT services in a healthcare setting. It is not a different discipline from business IT. It is the same work held to a documented standard, with the device inventory and the audit trail to prove it.
If your organization has never had a technical safeguards review, or the last one predates a new EHR, a merged practice, or a fleet of printers you inherited, start there. See our healthcare technology solutions for the full picture of how we support Indiana providers across IT, print, communications, and records.
Posted in: Managed IT Services
