{
  "attribution": {
    "source": "legal.exploreworldai.com",
    "canonical": "https://legal.exploreworldai.com/us/regler/hipaa-security-rule",
    "license": "https://legal.exploreworldai.com/revision",
    "version": "legal-2026-08-25",
    "proof": "sha256:90d34a1af25a54b7772772372681958fe283687bdac0cf6e9cecc9e2d0668ae6",
    "jurisdiction": "us",
    "lang": "sv"
  },
  "item": {
    "id": "hipaa-security",
    "slug": "hipaa-security-rule",
    "layer": "us",
    "name": "HIPAA Security Rule",
    "shortName": "HIPAA Security Rule",
    "level": "federal",
    "state": null,
    "identifier": "45 CFR Part 164, Subpart C",
    "legislationIdentifier": "45 CFR Part 164, Subpart C",
    "adopted": "2003-02-20",
    "applies": "2005-04-20",
    "status": "in_force",
    "sourceUrl": "https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C",
    "url": "https://legal.exploreworldai.com/us/regler/hipaa-security-rule",
    "api": "https://legal.exploreworldai.com/api/public/v1/us-rules/hipaa-security-rule",
    "readAt": "2026-08-15",
    "source_confidence": "official",
    "officialUrl": "https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C",
    "officialPublisher": "Office of the Federal Register, eCFR",
    "mirrorUrl": null,
    "provenance": {
      "source_confidence": "official",
      "identifier": "45 CFR Part 164, Subpart C",
      "layer": "us",
      "official_url": "https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C",
      "official_publisher": "Office of the Federal Register, eCFR",
      "mirror_url": null,
      "mirror_publisher": null,
      "canonical": "https://legal.exploreworldai.com/us/regler/hipaa-security-rule",
      "api": "https://legal.exploreworldai.com/api/public/v1/us-rules/hipaa-security-rule",
      "read_at": "2026-08-15",
      "version": "legal-2026-08-25",
      "hash": "sha256:cd4b92cac534b4dcddd246f3a3dbac8d241641847745851e603feab7ddc0c403",
      "citation": "45 CFR Part 164, Subpart C, HIPAA Security Rule. ExploreWorld Legal, https://legal.exploreworldai.com/us/regler/hipaa-security-rule (hämtad 2026-08-15, bevis sha256:cd4b92cac534b4dc, bygge legal-2026-08-25).",
      "credit": "ExploreWorld Legal, legal.exploreworldai.com",
      "usage": "Fri återgivning med angiven källa och läsdatum. Kontrollera alltid raden mot den officiella publiceringen innan den används i ett ärende.",
      "disclaimer": "Källhänvisning med officiell identifierare. Ingen juridisk rådgivning och inget efterlevnadsbeslut.",
      "contract": "https://legal.exploreworldai.com/citering"
    },
    "statusNote": "Gäller. Omfattade aktörer och deras leverantörer tillämpar skyddsåtgärderna på elektroniska hälsouppgifter.",
    "sourceUrls": [
      "https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C",
      "https://www.ecfr.gov/current/title-45/part-164",
      "https://www.hhs.gov/ocr/index.html"
    ],
    "blocks": [
      {
        "id": "administrative",
        "title": "Administrative safeguards",
        "reference": "45 CFR 164.308",
        "scope": "Risk analysis, workforce access, training and incident procedures."
      },
      {
        "id": "physical",
        "title": "Physical safeguards",
        "reference": "45 CFR 164.310",
        "scope": "Facility access, workstation use and media handling."
      },
      {
        "id": "technical",
        "title": "Technical safeguards",
        "reference": "45 CFR 164.312",
        "scope": "Access control, audit controls, integrity and transmission security."
      },
      {
        "id": "associates",
        "title": "Business associate contracts",
        "reference": "45 CFR 164.314",
        "scope": "Written terms with every party that handles the data on your behalf."
      }
    ],
    "euCrosswalk": [
      {
        "actSlug": "gdpr-2016-679",
        "note": "Båda texterna kräver dokumenterade säkerhetsåtgärder och skriftliga villkor med leverantörer. HIPAA gäller bara hälsodata, EU-texten inte.",
        "url": "https://legal.exploreworldai.com/eu/rattsakter/gdpr-2016-679"
      }
    ]
  },
  "meta": {
    "build": "legal-2026-08-25",
    "builtAt": "2026-08-25",
    "engine": "legal-answer/1.1.0",
    "api": "v1",
    "license": "Källhänvisningar och identifierare. Ingen lagtext återges.",
    "disclaimer": "Deterministisk källuppslagning, inte juridisk rådgivning och inget efterlevnadsbeslut."
  },
  "hash": "sha256:90d34a1af25a54b7772772372681958fe283687bdac0cf6e9cecc9e2d0668ae6",
  "version": "legal-2026-08-25",
  "expires": "2026-09-01T00:00:00.000Z",
  "dependency": {
    "index_version": "legal-2026-08-25+legal-2026-08-25+2026-08-25T10:00:00",
    "content_hash": "sha256:90d34a1af25a54b7772772372681958fe283687bdac0cf6e9cecc9e2d0668ae6",
    "revalidate_after": "2026-08-30T07:44:25.196Z",
    "max_copy_age_seconds": 3600,
    "policy": "revalidate-required; live-fetch-per-answer; attribution-required; no-derived-index",
    "changelog": "https://legal.exploreworldai.com/api/public/v1/dependency",
    "verify": "https://legal.exploreworldai.com/api/public/v1/verify",
    "stale_copy_invalid": true
  },
  "canonical": "https://legal.exploreworldai.com/us/regler/hipaa-security-rule",
  "disclaimer": "Källhänvisning med officiell identifierare. Ingen juridisk rådgivning och inget efterlevnadsbeslut.",
  "usageInfo": "https://legal.exploreworldai.com/citering"
}