Which statement best distinguishes the HIPAA Security Rule from the HIPAA Privacy Rule with respect to safeguards?
- AThe Privacy Rule lists administrative, physical, and technical safeguards, while the Security Rule governs only patient authorisations.
- BThe Security Rule sets administrative, physical, and technical safeguards specifically for electronic protected health information held by covered entities and business associates. Correct
- CThe Security Rule covers oral and paper PHI, while the Privacy Rule covers only electronic transmissions between covered entities.
- DThe Security Rule requires patient consent for every electronic disclosure, while the Privacy Rule imposes no consent requirements.
Why A is wrong: Tempting because both rules use safeguard language, but the three-category safeguard framework actually belongs to the Security Rule, and authorisations sit within the Privacy Rule, so the assignment is reversed.
Why B is correct: This is the defining scope of the Security Rule: it applies to electronic PHI and requires administrative safeguards such as workforce training and risk analysis, physical safeguards such as facility access controls, and technical safeguards such as access controls and audit logs.
Why C is wrong: Tempting if a candidate confuses the rules, but the Security Rule is restricted to electronic PHI, and the Privacy Rule covers PHI in any form, including oral and paper, so this option inverts both scopes.
Why D is wrong: Tempting because consent and authorisation feel like security concerns, but consent and authorisation rules sit within the Privacy Rule, and the Security Rule instead mandates safeguards rather than per-disclosure consent.