The HIPAA Privacy Rule protects the privacy of PHI in oral, written and electronic form. The HIPAA Security Rule focuses only on safeguarding the security of the electronic PHI, or EPHI. Safeguarding the EPHI is everyone's responsibility.
Pursuant to the HIPAA Security Rule, agencies will:
implement reasonable and appropriate administrative, technical, and physical safeguards that ensure the confidentiality, integrity and availability of the electronic PHI the entity collects, maintains, creates or transmits;
protect against reasonably foreseeable threats to the security or integrity of the information such as unauthorized access, alteration, deletion or transmission of the EPHI; and
protect against any reasonably anticipated uses or disclosures of the information that are not permitted or required by the Privacy Standards.