Section node
Administrative safeguards
45 CFR 164.308
- What this page is
- Section node, 45 CFR 164.308
- Checked against the official source
- 2026-08-15Current
- Responsible publisher
- ExploreWorld Legal, editorial deskLiability position
Short answer
What does 45 CFR 164.308 require, and where does it carry an outcome in the rule tree?
45 CFR 164.308 is the paragraph the HIPAA decision agent rests on for this question. Risk analysis, workforce access, training and incident procedures. The block was read against the publisher on 2026-08-15 and carries 4 outcomes in the agent's rule tree. The reference can be cited as it stands, with a link to the official text and a content hash.
45 CFR 164.308Checked against the publisher 2026-08-15Official text
A source reference, not legal advice.
- Jurisdiction
- 45 CFR Part 164, Subpart C
- Section node
- administrative
- Read
- 2026-08-15
- Hash
- sha256:a5a8065d8660800c
Outcomes resting on this section
The rules below point to this section in their outcome. The verdict is a machine classification, not a judgment on an individual matter.
hipaa-breach
The breach notification requirement applies
45 CFR 164.408 requires notice to Health and Human Services without unreasonable delay and no later than 60 days after discovery when at least 500 individuals are affected. Notice to the individual is governed by 45 CFR 164.404.
risk, Requirement applies
hipaa-ba
The business associate agreement is absent
45 CFR 164.308(b)(1) requires a written contract before a business associate creates, receives, maintains or transmits electronic protected health information on behalf of a covered entity. The content is governed by 45 CFR 164.314(a).
prohibited, Requirement applies
hipaa-risk
The risk analysis is absent
45 CFR 164.308(a)(1)(ii)(A) requires an accurate assessment of the risks and vulnerabilities to the confidentiality, integrity and availability of electronic protected health information. The measures follow from 45 CFR 164.308(a)(1)(ii)(B).
risk, Requirement applies
hipaa-covered
The security rule safeguards apply
45 CFR 164.306(a) requires administrative, physical and technical safeguards for electronic protected health information. The individual requirements are in 45 CFR 164.308, 164.310 and 164.312, and documentation in 45 CFR 164.316.
risk, Requirement applies
Section nodes
- Physical safeguards45 CFR 164.310
- Technical safeguards45 CFR 164.312
- Business associate contracts45 CFR 164.314
The verdict is a machine classification of the outcome, not legal advice and not a compliance decision.
Verifiable trust signals
- Six fixed blocks, one source per line
- No sentence written by a language model
- Engine version and read date on every answer
- No customer data, no documents, no advice
- Model card and audit published under the EU AI Act