Who must comply with the HIPAA Security Rule?

Covered entities and business associates must protect ePHI.

Start playing free

  1. Only paper record vendors
  2. Covered entities and business associates ✔
  3. Only state health departments

Why: The Security Rule applies to covered entities and business associates with respect to electronic protected health information. Business associates are directly responsible under HIPAA.

Huh, didn't know that: Business associates include billing companies, cloud EHR vendors, and others that handle ePHI.

The dad joke
Why did the business associate bring a ladder? To reach the high security standards.
Like this card?
Play the game

References

Answer: Covered entities and business associates. The Security Rule applies to covered entities and business associates with respect to electronic protected health information. Business associates are directly responsible under HIPAA.

  1. 45 CFR 164.302 Applicability www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C/section-164.302
    A covered entity or business associate must comply with the applicable standards ... with respect to electronic protected health information
    Checked 2026-10-10.

Think this answer is wrong? Tap "Challenge this answer" on the card in the game and tell us why.

Test yourself in the game