Why HIPAA matters to your IT team
For healthcare organizations and their business associates, HIPAA's Security Rule is not a checkbox — it is a continuous operational requirement. The HHS Office for Civil Rights (OCR) levied over $14 million in HIPAA penalties in 2024 alone, with the most common findings being missing risk analyses, lack of encryption, and inadequate access controls.
The Security Rule defines three categories of safeguards for protecting electronic protected health information (ePHI). Here is what each category means for your IT environment and the specific controls that satisfy them.
Figure 1 — HIPAA Security Rule safeguard categories. Technical safeguards are the IT team's primary responsibility and the most common area of OCR findings.
Technical safeguards — the IT checklist
| HIPAA Requirement | Implementation | Tool / Control |
|---|---|---|
| Access control — unique user IDs | No shared accounts; every user has a named identity | Microsoft Entra ID / Active Directory |
| Access control — MFA | Multi-factor authentication on all systems touching ePHI | Microsoft Authenticator, Entra Conditional Access |
| Automatic logoff | Session timeout after inactivity on workstations and apps | Intune policy, GPO, application settings |
| Audit controls | Centralized logging of all access to ePHI systems | Adlumin SIEM, Microsoft Purview Audit |
| Integrity controls | Protections against improper alteration or destruction of ePHI | EDR (SentinelOne), file integrity monitoring |
| Transmission security | Encryption of ePHI in transit | TLS 1.2+, VPN for remote access |
| Encryption at rest | Disk and database encryption for all ePHI storage | BitLocker, Azure encryption, Datto encryption |
Administrative safeguards — what IT owns
While administrative safeguards are often considered a compliance or legal function, IT owns several of them directly:
- Annual risk analysis: A documented assessment of threats and vulnerabilities to ePHI. This is the #1 finding in OCR audits — organizations either skip it or do it once and never update it.
- Incident response plan: A documented procedure for identifying, containing, and reporting security incidents involving ePHI, including breach notification timelines (60 days to HHS for breaches affecting 500+ individuals).
- Contingency plan: Backup and disaster recovery procedures with tested RTOs. IDENETY uses Datto with documented restore SLAs.
- Business Associate Agreements (BAAs): Every vendor that touches ePHI — including your IT provider — must sign a BAA. IDENETY provides BAAs for all HIPAA clients.
Documentation is a control too
OCR auditors want evidence, not assertions. "We do encryption" is not sufficient — you need to show the BitLocker policy, the Intune compliance report, and the log proving it was enforced on every device. IDENETY maintains this documentation as part of the COMPLETE plan and produces it on demand for audits or due diligence requests.
Physical safeguards — quick wins
- Privacy screens on workstations in clinical areas where patients can see the screen.
- Automatic screen lock (5 minutes or less) enforced via Intune policy.
- Secure media disposal — NIST 800-88 wiping or physical destruction for decommissioned drives.
- Equipment inventory — every device that can access ePHI must be tracked.
See our HIPAA & Wireless Networks article for wireless-specific compliance requirements in healthcare facilities.
Contact our engineers to schedule a HIPAA technical safeguards assessment for your organization.
.png)