SESK: Stuff Everyone Should Know · sesk.info/hipaa-security-rule-scope
Who must comply with the HIPAA Security Rule?
Covered entities and business associates must protect ePHI.
- Only paper record vendors
- Covered entities and business associates ✔
- Only state health departments
Why: The Security Rule applies to covered entities and business associates with respect to electronic protected health information. Business associates are directly responsible under HIPAA.
Huh, didn't know that: Business associates include billing companies, cloud EHR vendors, and others that handle ePHI.
Why did the business associate bring a ladder? To reach the high security standards.
Like this card?
References
Answer: Covered entities and business associates. The Security Rule applies to covered entities and business associates with respect to electronic protected health information. Business associates are directly responsible under HIPAA.
- 45 CFR 164.302 Applicability www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C/section-164.302
A covered entity or business associate must comply with the applicable standards ... with respect to electronic protected health information
Checked 2026-10-10.
Think this answer is wrong? Tap "Challenge this answer" on the card in the game and tell us why.
More stuff everyone should know
That's stuff everyone should know.