HIPAA Security Rule

HIPAA safeguards, evidenced from the systems that touch ePHI.

The HIPAA Security Rule is not a checklist — it is a set of administrative, physical, and technical safeguards you must implement and be able to demonstrate. Lojycal makes the technical and administrative half continuous: who accessed what, on which device, under which agreement.

What the Security Rule actually demands

Covered entities and business associates are judged on implemented safeguards and documentation, not intentions.

  • A real risk analysis

    §164.308(a)(1) requires an accurate, thorough assessment of risks to ePHI — the single most commonly cited failure in OCR enforcement.

  • Access control and unique identification

    Unique user IDs, emergency access, automatic logoff, and encryption/decryption addressable specifications under §164.312(a).

  • Audit controls

    §164.312(b) requires mechanisms that record and examine activity in systems containing ePHI — and retention of that record.

  • Business associate agreements

    Every vendor touching ePHI needs a BAA, tracked and current, with the relationship documented.

The Lojycal HIPAA engine

Safeguards are evidenced from identity, endpoint, and vendor data rather than assembled by hand.

Workforce access and least privilege

Unique identities, role-based grants, joiner/mover/leaver evidence, and periodic access reviews across ePHI systems.

RBAC + Access Reviews

Device and transmission safeguards

Encryption state, automatic logoff, screen lock, and device disposal evidence from MDM across every endpoint in scope.

Endpoint Governance + Asset Lifecycle

Audit controls

A WORM audit log of privileged actions and policy changes, retained and queryable — the record §164.312(b) asks for.

Trust Center → Audit Log

BAA and vendor register

Vendors with ePHI exposure tracked with agreement state, renewal date, and observed security posture.

Vendor Governance

Security Rule safeguards → Lojycal controls

A sampled view of where the evidence originates:

SafeguardExample specificationLojycal source
§164.308(a)(1) Security managementRisk analysis and risk managementTrust Center → Risk
§164.308(a)(3) Workforce securityAuthorisation, clearance, terminationHR Automation
§164.308(a)(4) Information accessAccess authorisation and modificationRBAC + Access Reviews
§164.308(a)(5) Awareness trainingSecurity reminders, malicious softwareHR Automation
§164.308(b) Business associatesWritten contract / BAA in placeVendor Governance
§164.310(d) Device and mediaDisposal, media re-use, accountabilityAsset Lifecycle
§164.312(a) Access controlUnique user ID, automatic logoff, encryptionRBAC + Endpoint Governance
§164.312(b) Audit controlsRecord and examine system activityWORM Audit Log

Sampled — Lojycal maps a subset of the Security Rule specifications, focused on administrative and technical safeguards it can evidence from live data. Physical safeguards and the Privacy Rule remain outside its scope, and the export says so.

What OCR asks for is documentation

Enforcement actions turn on whether you can show the safeguard operated, and when.

Lojycal retains a write-once audit record of privileged access, configuration change, and policy decision, and bundles selected windows into a signed evidence pack with a detached signature. That is the difference between asserting a safeguard existed and demonstrating it operated on the date in question.

Getting to demonstrable

Most gaps are documentation gaps, and documentation is what automates best.

  1. Week 1–2

    Scope ePHI

    Identify the systems, vendors, and devices that touch ePHI, from live inventory rather than memory.

  2. Week 3–6

    Risk analysis

    Run the §164.308(a)(1) analysis against real data, with owners on every identified risk.

  3. Week 7–12

    Safeguards

    Close access, encryption, logging, and BAA gaps; the audit log starts building the record.

  4. Ongoing

    Demonstrate

    Export signed evidence on demand for auditors, customers, or an OCR inquiry.

HIPAA questions

Does using Lojycal make us HIPAA compliant?

No product can make you compliant. HIPAA compliance is an organisational state covering the Privacy Rule, the Security Rule, and the Breach Notification Rule. Lojycal automates evidence for a substantial part of the administrative and technical safeguards in the Security Rule — the rest, including physical safeguards and privacy practices, remains yours.

We're a business associate, not a covered entity. Does this apply?

Yes. Since the Omnibus Rule, business associates are directly liable for Security Rule compliance and must have BAAs with their own subcontractors. The evidence Lojycal produces is the same for both roles.

How does Lojycal handle 'addressable' specifications?

Addressable does not mean optional. It means you implement it, or document why it is not reasonable and appropriate and what you did instead. Lojycal tracks that documented decision alongside the control so the reasoning survives staff turnover.

Do you cover the Privacy Rule?

Not directly. Lojycal's evidence is operational — access, devices, vendors, logging. Privacy Rule obligations such as notices of privacy practices and individual rights requests sit outside its scope, and the framework export marks them as out of scope rather than implying coverage.

Where do I switch it on?

Policy Lab → Available frameworks (off) → Enable on the HIPAA card. It appears in Policy Lab, Endpoint Governance, and Shadow IT Lab immediately.

Show the safeguard operated. On the date in question.

Access, devices, vendors, and audit records — retained, signed, and ready to produce.