What category of obligation this is
The HIPAA Security Rule is a U.S. federal rule. HHS describes it as a national set of security standards for certain health information that is maintained or transmitted in electronic form. The safeguards it names fall into three categories: administrative, physical, and technical.
The rule text HHS points to is 45 CFR Part 160 and Part 164, Subparts A and C. A major goal, in HHS's summary, is to ensure the confidentiality, integrity, and availability of electronic protected health information (ePHI) that a regulated entity creates, receives, maintains, or transmits. Confidentiality, here, means the information is not made available or disclosed to unauthorized persons or processes. Integrity means it has not been altered or destroyed in an unauthorized manner. Availability means an authorized person can access and use it on demand.
That is a safeguard goal for ePHI. It is not a gadget list, and it is not the Privacy Rule. HHS says its own summary is an overview, not a comprehensive compliance guide, and that the Security Rule governs if the summary and the rule conflict.
Who HHS says the Security Rule applies to
HHS says the Security Rule applies to covered entities and to their business associates. The covered-entity list on the HHS summary is: health plans; health care clearinghouses; and a health care provider that transmits health information in electronic form in connection with a transaction for which the Secretary of HHS has adopted standards under HIPAA.
Business associates are in that same frame. The HITECH Act made the Security Rule's administrative, physical, and technical safeguards, and its policy and documentation requirements, apply to business associates in the same manner as to covered entities. This page does not decide whether a named vendor is a business associate. That question belongs to the privacy officer and counsel, using the relationship and the HHS materials, not a product slogan.
What information the Security Rule protects
The Security Rule protects electronic protected health information: protected health information that is maintained in or transmitted by electronic media. HHS is explicit that, unlike the Privacy Rule and the Breach Notification Rule, the Security Rule does not apply to protected health information that is only on paper or only spoken.
Health-related data is not the same sentence as ePHI at a covered entity or business associate. The healthcare industry path already says HIPAA does not automatically cover every health app or every kind of health-related data. A consumer wellness startup is not inside this frame just because the product mentions health.
Why there is no universal gadget list
HHS describes the Security Rule as flexible, scalable, and technology neutral, because regulated entities differ in size, organizational structure, and risks to ePHI. When an entity selects security measures, HHS says it considers its size, complexity, and capabilities; its technical infrastructure; the cost of measures; and the probability and criticality of risks to ePHI. The rule does not dictate one product stack.
Read that as why a single encryption checkbox cannot be the whole answer. Do not read it as permission to skip the rule. HHS also says some implementation specifications are required and some are addressable. Addressable does not mean optional. Where an addressable specification is reasonable and appropriate, the entity implements it. Where it is not, the entity may use an alternative that achieves the standard's purpose, and it documents why. This page stops at that category. It does not walk specification by specification, and it does not tell you which alternative is reasonable for a real system.
HHS notes that a proposed modification to the Security Rule has its own page. This explainer teaches the summary of the rule HHS says is currently in effect. It does not treat a proposal as a present obligation.
Who to ask
Ask the privacy officer or security official your organization has designated, and qualified counsel, before you treat a system, a vendor, or a dataset as inside or outside this rule. Atlas can name the categories HHS publishes. It cannot make the determination.
For the habit underneath the legal name, use the privacy-versus-security lesson: security questions (confidentiality, integrity, availability, resilience) are not the same sentences as privacy questions (purpose, minimization, and what a person is owed). Do not paste the Security Rule into that lesson.
Claims to retire
If it is health data, HIPAA applies.
HHS limits the Security Rule to ePHI at covered entities and business associates. A health-related app is not automatically in that frame. Coverage is an entity and relationship question for counsel or the privacy officer.
The encryption checkbox means the Security Rule is done.
Encryption can support confidentiality of ePHI. The Security Rule also frames integrity, availability, and administrative, physical, and technical safeguards. One control setting is not the rule.
The Security Rule and the Privacy Rule are the same rule.
HHS says the Security Rule complements the Privacy Rule. The Security Rule is about safeguarding ePHI. It does not apply to paper or verbal PHI. The Privacy Rule is a different rule.
A SOC 2 report means HIPAA is met.
A SOC 2 report is an attestation about a described system and criteria. It is not the HIPAA Security Rule, and it does not decide that a covered entity or business associate has met that rule.
The HHS cybersecurity performance goals are a HIPAA certification.
The healthcare industry path already labels those performance goals as voluntary guidance. They are not a certification, and they do not replace the Security Rule.
CHECK THE CATEGORY
Sort the two synthetic items. Which one sits in the Security Rule frame HHS describes?
Glossary and nearby pages
Use the agency page in the sources for the authoritative text. This page has no figure.