Legal & compliance centre

HLD Group

HIPAA administrative & technical safeguards

Safeguards for protected health information as business associate.

Last updated: 24 July 2026

Version 1.1 · Review cycle: 365 days · View all frameworks

1. Purpose

This policy defines the administrative, physical, and technical safeguards HLD Group applies to protected health information when we act as a business associate to covered entities or other business associates. It gives effect to our obligations under the HIPAA Security and Privacy Rules and the HITECH Act.

2. Scope

This policy applies to all protected health information (PHI), including electronic PHI (ePHI), that HLD Group creates, receives, maintains, or transmits on behalf of a covered entity, and to all personnel, systems, and subcontractors that handle it.

3. Definitions

  • Protected health information (PHI) — individually identifiable health information held or transmitted in any form
  • Electronic PHI (ePHI) — PHI in electronic form
  • Covered entity — a health plan, health care clearinghouse, or health care provider that transmits health information electronically
  • Business associate — a person or entity that performs functions involving PHI on behalf of a covered entity
  • Business associate agreement (BAA) — the contract that binds a business associate to HIPAA obligations
  • Minimum necessary — the principle of using or disclosing only the PHI needed for the purpose
  • HIPAA Privacy Rule, 45 CFR Part 160 and Part 164 Subparts A and E
  • HIPAA Security Rule, 45 CFR Part 164 Subpart C, for ePHI
  • HIPAA Breach Notification Rule, 45 CFR Part 164 Subpart D
  • HITECH Act provisions extending direct liability and breach obligations to business associates
  • The terms of each applicable business associate agreement

5. Administrative safeguards

  • A security management process including risk analysis and risk management for ePHI
  • Assigned security responsibility to a named individual
  • Workforce security, access management, and termination procedures
  • Security awareness and training for personnel handling PHI
  • A security incident response procedure, and contingency planning for ePHI
  • Periodic evaluation of safeguards against the Security Rule
  • Business associate agreements in place with subcontractors that handle PHI

6. Physical safeguards

  • Facility access controls limiting physical access to systems holding ePHI
  • Workstation use and security controls
  • Device and media controls governing receipt, movement, reuse, and disposal of media holding ePHI

7. Technical safeguards

  • Access control with unique user identification and automatic logoff
  • Encryption of ePHI at rest and in transit as an addressable implementation specification we implement
  • Audit controls recording activity in systems holding ePHI
  • Integrity controls preventing improper alteration or destruction of ePHI
  • Authentication of persons and entities seeking access to ePHI

8. Minimum necessary and permitted uses

PHI is used and disclosed only as permitted by the applicable business associate agreement and the Privacy Rule, and limited to the minimum necessary to accomplish the intended purpose. PHI is not used for any purpose beyond the services contracted, and is returned or destroyed at the end of the engagement where required.

9. Breach notification

A breach of unsecured PHI is handled under the Breach Notification Policy, including notification to the affected covered entity without unreasonable delay and no later than 60 days after discovery, as required by the Breach Notification Rule, so that the covered entity can meet its own notification obligations.

10. Roles, exceptions, and review

A designated HIPAA security official owns this policy under the CISO. Safeguards required by the Security Rule or a BAA cannot be waived internally. This policy is reviewed at least annually and on any change to applicable requirements.

Related frameworks

For contractual attestations or audit packs, contact [email protected].