HIPAA Security Rule 2025: what Tennessee practices must demonstrate before OCR comes calling.
OCR enforcement is accelerating. Most small practices are missing the required risk analysis. Here's what compliance actually requires.
OCR (Office for Civil Rights) enforcement of the HIPAA Security Rule has accelerated significantly in 2024 and 2025, with record penalties levied against covered entities for failures that have existed for years. The common thread in most enforcement actions is not a spectacular breach — it's basic Security Rule requirements that organizations either didn't know about or treated as optional. For Tennessee healthcare practices, the risk is real and immediate.
What the HIPAA Security Rule actually requires
The HIPAA Security Rule requires covered entities and business associates to implement administrative, physical, and technical safeguards to protect electronic protected health information (ePHI). The technical safeguards section (45 CFR §164.312) specifies:
- Access controls: Unique user identification, emergency access procedures, automatic logoff, and encryption/decryption of ePHI
- Audit controls: Hardware, software, and procedural mechanisms to record and examine activity in systems that contain ePHI
- Integrity controls: Measures to ensure ePHI is not improperly altered or destroyed
- Person or entity authentication: Procedures to verify that users requesting access to ePHI are who they claim to be
- Transmission security: Measures to guard against unauthorized access to ePHI transmitted over electronic communications networks
Beyond technical safeguards, the Security Rule requires a documented and comprehensive risk analysis — an assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI in the organization's possession. This risk analysis is not optional, and its absence is one of the most common findings in OCR investigations.
The required risk analysis — most practices don't have one
The HIPAA Security Rule explicitly requires covered entities to conduct an accurate and thorough assessment of potential risks and vulnerabilities to ePHI (45 CFR §164.308(a)(1)(ii)(A)). This is a written document — not a mental exercise — that identifies all systems containing ePHI, evaluates threats and vulnerabilities to those systems, assesses existing controls, and determines the likelihood and magnitude of potential harm.
OCR audits consistently find that the majority of small healthcare practices have never conducted a formal risk analysis. This alone is grounds for a finding, regardless of whether a breach has occurred. SignalPoint's compliance advisory service produces the required risk analysis documentation, updated annually.
What a HIPAA breach actually triggers
When a breach of unsecured ePHI is discovered, HIPAA requires notification to affected individuals within 60 days, and to HHS (and prominently in local media for breaches of 500 or more individuals in a state). The breach notification rule requires a documented breach assessment — determining whether the incident constitutes a reportable breach based on four factors: nature and extent of the ePHI involved, who used or accessed it, whether it was actually acquired or viewed, and the extent to which the risk has been mitigated.
SignalPoint's incident response service for healthcare clients includes HIPAA breach assessment — working through the four-factor test with your legal counsel to determine notification obligations and timeline.