Saved · this browser
Chapter 9 · §164.312

Your Systems

Most of this chapter is just checking with your software vendors. You’re not building anything — your EHR (the software where you keep patient records) already handles the technical parts, like scrambling records and keeping access records. Your job is to confirm each one is there, turned on where it should be, and to jot down what you found.

No EHR? This chapter still fits your practice.

For paper-and-email practices, the §164.312 questions still apply — your email provider, cloud folder, and backup approach handle the same areas your EHR would. The questions will help you confirm what each service provides, document what you find, and note where you need a written procedure (such as emergency access).

Why this chapter exists, in plain English

§164.312 — the Technical Safeguards. The earlier chapters were mostly about things you do: who you have BAAs with, how you handle devices, how you respond to incidents, how you keep the paperwork. This chapter is about things your systems do — specifically, your EHR and any other software that touches patient information.

For a solo or small practice, this is mostly a vendor-verification chapter: you ask your EHR vendor a short list of questions, and you document what they tell you.

Seven topics, one per part of §164.312. Four of them are flagged addressable, which is the rule’s way of saying: if a step doesn’t fit your practice, you can do something else that works just as well instead — as long as you write it down. If more than one system holds patient information (say a separate billing or scheduling tool), run through the questions once for each — your vendors’ answers may differ.

What do you use to keep your patient records?

Pick the main one you use. We’ll use this to fill in the right details for you.

01

The seven safeguards

7 questions
§164.312(a)(2)(i) + (d)

Unique accounts and how you log in:

your own login, not one everyone shares

Two questions here. First: does everyone who sees patient information have their own login to your EHR (the software where you keep patient records) — not one login everyone shares? Second: does signing in take more than just a password? The strongest setup adds a second step — a code texted to your phone, or a tap in an app, often called multi-factor (MFA). Use it wherever your vendor offers it.

For a solo practice that’s just one login — yours. A small office has a few. Either way the goal is the same: that second sign-in step is turned on, and everyone actually uses it.

§164.312(a)(2)(ii)

Emergency access procedure:

how patient records still reach the right people when something goes wrong

“Something goes wrong” for a solo or small practice usually means: a device is lost or stolen, your vendor has an outage, an account gets locked, or you’re out sick and someone covering for you needs patient records. The rule wants you to have written down what happens then.

There are two sides to this. The vendor side: your EHR’s emergency admin access, their support line, and the recovery steps they’ve written down. The practice side: who covers for you, how they get to records, and how they prove to your vendor that they’re allowed to.

§164.312(a)(2)(iii) (addressable)

Auto-logoff:

what happens when you walk away from a logged-in screen

Two layers: the EHR itself (most healthcare vendors log you out after about 15 minutes of sitting idle), and the lock on your device underneath it (covered in Chapter 2). Both count — if the EHR stays open but your device locks after five minutes, someone who walks up to your screen sees the lock screen, not the chart.

Look for your EHR’s auto-logout setting in its admin settings (it’s sometimes called “idle timeout” or “session length”).

§164.312(a)(2)(iv) (addressable)

Keeping stored records scrambled:

so a stolen laptop or phone is useless to a thief

This one is about your vendor keeping the records they store for you scrambled — so if someone broke into their systems, the files would be unreadable. It’s different from locking your own laptop or phone ( FileVault or BitLocker, back in Chapter 2). Your EHR vendor should keep their stored copies and backups scrambled; you’ll find this confirmed in their BAA or their security report.

On paper this one is optional, but in practice it’s expected — when records leak, unscrambled storage is one of the first things flagged. Treat it as a must.

§164.312(b)

Your system’s access records:

the record your system keeps of who opened what, and when

Your EHR and email already keep a record of who signed in and what they opened — you don’t have to set anything up. The job here is small: every so often, open that record and glance for anything you don’t recognize, like a sign-in from a place you’ve never been or a burst of failed password tries.

You’re not signing up to stare at these records every month. The point is just that they don’t get ignored. Picking a date once a year to look through them — and jotting down that you did — is enough for a solo or small practice. That yearly look belongs on the review calendar you set in Chapter 7.

§164.312(c) (addressable)

Protecting records from changes:

making sure records can’t be changed or wiped by mistake

The idea here is simple: your records shouldn’t be able to be changed or wiped without anyone noticing. You can’t quietly go in and alter a record — and that’s really all this needs to say. Your EHR handles it for you, usually by keeping older versions of every entry.

Your one job at the practice level: don’t let your EHR be your only copy. That ties straight back to the backup plan in Chapter 6.

§164.312(e) (addressable)

Keeping records safe as they’re sent:

how patient info stays protected on its way out of your practice

This is about keeping patient info safe while it travels — when it leaves your EHR, your email, or a vendor’s website. The good news: modern websites do this for you automatically. The sign is the little padlock in your browser’s address bar (the address starts with “https”). A few things to check: does your EHR show that padlock everywhere? Is patient email going through a protected channel you have a BAA for (Chapter 1)? And if you log into any vendor websites, do they show the padlock too?

Security-monitoring software (optional)

Optional — you don’t need this to finish the chapter. If your IT person (or the outside IT company some practices hire) has set up security-monitoring software on your devices — often called EDR — noting it here fills in that row of the summary you can hand your insurance company. Some insurers (like CRC Group or Travelers) ask for it before they’ll offer higher coverage.

Is security-monitoring software (EDR) set up on your devices?

A couple of extra checks (optional)

Optional — you don’t need these to finish the chapter. These two answers fill in two more rows of the summary you can hand your insurance company — and both are things insurers ask about and the proposed 2026 HIPAA rule update would expect.

Carriers ask this

Do you install security updates within 30 days of when they come out?

Is your work WiFi separate from the WiFi guests and patients use?

02

Where you stand

Not quite there yet

Answer all seven questions to see where you stand.

Can you help us make this better?

How easy is HIPAAPath to use so far?
HardEasy

Please don’t include patient information — this goes to us by email.