Tool
Which HIPAA technical safeguards does your product have to satisfy?
The technical safeguards at 45 CFR 164.312 are five standards and seven implementation specifications. Two of the seven must be implemented. The other five have to be assessed, then implemented or replaced with a documented equivalent. Mark where your product stands on each of the twelve and the page tells you what you still owe an auditor.
- Section
- 45 CFR 164.312
- Read at the source
- 2 September 2026
Which twelve lines apply, and under which section numbers?
All twelve apply to any system that creates, receives, maintains or transmits electronic protected health information. Marking a line changes what the summary and the download say about it, never whether it applies.
Access control
164.312(a)(1)
Unique user identification
164.312(a)(2)(i), Required
Emergency access procedure
164.312(a)(2)(ii), Required
Automatic logoff
164.312(a)(2)(iii), Addressable
Encryption and decryption
164.312(a)(2)(iv), Addressable
Audit controls
164.312(b)
Integrity
164.312(c)(1)
Mechanism to authenticate electronic protected health information
164.312(c)(2), Addressable
Person or entity authentication
164.312(d)
Transmission security
164.312(e)(1)
Integrity controls
164.312(e)(2)(i), Addressable
Encryption
164.312(e)(2)(ii), Addressable
What does this leave you owing?
Counted from what you marked above. The counts live in this page and reset when you reload it.
Mark the lines above to see what is still outstanding.
Saves a text file built in your browser. Nothing is uploaded, and no address is asked for.
Does addressable mean optional?
No. Under 45 CFR 164.306(d)(3) an addressable specification has to be assessed for whether it is a reasonable and appropriate safeguard in your environment. You then implement it, or you document why it would not be reasonable and appropriate and implement an equivalent alternative measure where that is reasonable and appropriate. Skipping one leaves you owing the written assessment either way.
A required specification under 164.306(d)(2) has to be implemented. There is no assessment step and no alternative.
What does a tester produce against each line?
A safeguard is evidenced by a dated record that names what was tested, against which requirement, on which build, with what result. The section number goes on the record. An auditor reading your file matches the section to the record, and a safeguard with no record reads as absent whether or not the control exists in the product.
The technical safeguards are one of three sets. The administrative safeguards at 164.308 and the physical safeguards at 164.310 are not on this page, and a product that satisfies all twelve lines below is still short of the Security Rule.
Where do these twelve lines come from?
Section numbers and titles read against the primary source on 2026-09-02. Codified regulation. Original final rule 68 FR 8376 (Feb. 20, 2003); last substantively amended by the HITECH Omnibus Final Rule, 78 FR 5566 (Jan. 25, 2013). No amendment to 45 CFR 164.302-164.318 since Jan. 25, 2013..
What happens to what you enter?
Nothing. The list arrives with the page and the filtering runs in your browser. This site has no analytics and no third party scripts, and there is no endpoint here that could receive a product description. The download is built in the page and saved by your own browser.
Which standards do these safeguards sit inside?
What does validating your product actually involve?
Answer four questions about your markets, your product type and its integrations. You get the standards that reach you, the artefacts each one asks you to produce, and which of them a test supplier delivers.