Protect electronic PHI
Regulated entities must apply reasonable and appropriate safeguards to the confidentiality, integrity, and availability of ePHI throughout their environment.
Bring current HIPAA Security Rule safeguards into continuous managed operation while preparing for incidents and breaches involving ePHI.
View the control mappingWhere we contribute
The HIPAA Security Rule applies to the complete environment in which a covered entity or business associate creates, receives, maintains, or transmits electronic protected health information. Network Box can operate and document substantial technical and operational safeguards, but no product, BAA, or managed service makes an organization automatically HIPAA compliant or certified.
Current rule status
Reviewed September 2, 2026HHS proposed a substantial Security Rule modernization in December 2024, but it remains a Notice of Proposed Rulemaking. The proposal is useful for readiness planning; it is not the present enforceable compliance standard.
Read the HHS Security Rule proposal status ↗Regulatory foundation
The current Security Rule, HITECH amendments, Breach Notification Rule, and actual service data flows determine the responsibilities of covered entities, business associates, MSPs, and other providers.
Regulated entities must apply reasonable and appropriate safeguards to the confidentiality, integrity, and availability of ePHI throughout their environment.
HITECH extended significant Security Rule duties and breach-notification obligations to business associates and certain downstream subcontractors.
An addressable specification requires a documented reasonableness analysis, implementation when reasonable and appropriate, or a documented equivalent alternative when appropriate.
HHS does not certify products as HIPAA compliant. Compliance depends on the regulated entity's complete program, environment, people, contracts, and operation of safeguards.
Control mapping
The matrix follows the current administrative, physical, technical, organizational, policy, and documentation requirements. Each row separates managed-security contributions from the duties retained by the covered entity or business associate.
| Framework area | Network Box contribution | Relevant services | Coverage |
|---|---|---|---|
| Technical risk inputs and continuously operated controls support an organization-wide security management process. | Partial | ||
Detailed mapping2 mapping notes Implement policies and procedures to prevent, detect, contain, and correct security violations, including risk analysis, risk management, sanctions, and information-system activity review. Network Box contributionPartialNetwork Box provides vulnerability findings, threat and event information, incident history, managed controls, activity monitoring, and evidence for the service scope. Regulated entity responsibilityClient responsibilityPerform the complete ePHI risk analysis, document risk treatment, impose workforce sanctions, review all necessary system activity, and reduce identified risks across the full environment. | |||
| Recurring technical assessment identifies threats and weaknesses but is not, by itself, a HIPAA risk analysis. | Supporting | ||
Detailed mapping2 mapping notes Conduct an accurate and thorough assessment of potential risks and vulnerabilities to the confidentiality, integrity, and availability of all ePHI. Network Box contributionSupportingNetwork Box supplies vulnerability results, observed attacks, telemetry, architecture observations, and incident analysis for systems visible to the service. Regulated entity responsibilityClient responsibilityIdentify every ePHI location and flow, include technical and nontechnical risks, assess likelihood and impact, document methodology and conclusions, and update the analysis after material change. | |||
| Managed safeguards and remediation guidance help reduce identified technical risks within scope. | Partial | ||
Detailed mapping2 mapping notes Implement security measures sufficient to reduce risks and vulnerabilities to a reasonable and appropriate level. Network Box contributionPartialNetwork Box operates preventive, detective, and responsive safeguards, updates managed protections, reports changing risks, and recommends technical remediation. Regulated entity responsibilityClient responsibilitySelect, approve, document, implement, and monitor risk treatments for the complete environment, including systems and risks outside Network Box management. | |||
| Centralized logging and SOC analysis support regular review of information-system activity. | Strong | ||
Detailed mapping2 mapping notes Implement procedures to regularly review records of information-system activity, including audit logs, access reports, and security-incident tracking reports. Network Box contributionStrongNetwork Box centralizes connected logs, correlates events, investigates suspicious activity, tracks incidents, monitors source health, and produces dashboards and reports. Regulated entity responsibilityClient responsibilityDefine required systems and events, connect every relevant source, protect and retain logs, assign review cadence and responsibility, document reviews, and correct identified issues. | |||
| Defined contacts, escalation paths, and operating reports support the designated security official. | Supporting | ||
Detailed mapping2 mapping notes Identify the security official responsible for developing and implementing Security Rule policies and procedures. Network Box contributionSupportingNetwork Box provides defined service responsibilities, named operational contacts, escalation paths, evidence, and reporting to support that official. Regulated entity responsibilityClient responsibilityDesignate the accountable security official and retain authority for the regulated entity's complete program; outsourcing technical operations does not transfer this duty. | |||
| Access restrictions, logging, and alerts can help prevent or detect inappropriate access within the managed scope. | Supporting | ||
Detailed mapping2 mapping notes Ensure workforce members have appropriate authorization and supervision and prevent unauthorized workforce access to ePHI. Network Box contributionSupportingNetwork Box can restrict access to managed services and segments, log administrative activity, and alert on suspicious access behavior. Regulated entity responsibilityClient responsibilityOwn authorization, clearance, supervision, transfers, termination, sanctions, HR coordination, physical access, application permissions, and identity lifecycle. | |||
| Network policy, segmentation, secure connectivity, and telemetry help enforce approved access paths. | Partial | ||
Detailed mapping2 mapping notes Implement policies and procedures for authorizing access to ePHI only when appropriate to a person's or entity's role. Network Box contributionPartialManaged firewalls, segmentation, VPN, gateways, supported identity integration, and monitoring restrict network connectivity within scope. Regulated entity responsibilityClient responsibilityDefine role-based policy, authorize access, apply minimum-necessary principles, govern application and data permissions, review rights, and promptly modify or revoke access. | |||
| Education, phishing simulations, and metrics build safer workforce behavior when subscribed. | Strong | ||
Detailed mapping2 mapping notes Implement a security-awareness and training program for all workforce members, including management, appropriate to risks and responsibilities. Network Box contributionStrongNetwork Box can deliver awareness content, phishing simulations, reminders, campaign administration, participation records, and susceptibility metrics. Regulated entity responsibilityClient responsibilityAssign training, tailor it to roles and risks, ensure timely completion, address failures and exceptions, train new and changed roles, and retain required records. | |||
| Continuous detection, investigation, escalation, and containment support the regulated entity's response procedures. | Strong | ||
Detailed mapping2 mapping notes Identify and respond to suspected or known security incidents, mitigate harmful effects where practicable, and document incidents and outcomes. Network Box contributionStrongThe SOC detects, validates, prioritizes, investigates, documents, and escalates incidents and coordinates available containment and remediation actions. Regulated entity responsibilityClient responsibilityOwn and test the enterprise response plan, decision authority, ePHI and breach analysis, evidence preservation, recovery, legal and privacy coordination, patient safety, and notifications. | |||
| Monitoring, protected configurations, recovery procedures, and resilient options support continuity of managed security functions. | Supporting | ||
Detailed mapping2 mapping notes Maintain data backup, disaster-recovery, and emergency-mode operations plans and address testing, revision, and criticality analysis as applicable. Network Box contributionSupportingNetwork Box can monitor service health, protect relevant managed configurations, restore managed security functions, support incidents, and provide contracted resilient architectures. Regulated entity responsibilityClient responsibilityMaintain retrievable ePHI backups, identify critical clinical and business processes, define recovery objectives, protect backup systems, plan emergency operations, and regularly test and revise plans. | |||
| Operational records and reviews help evaluate whether managed safeguards are functioning and where improvement is needed. | Partial | ||
Detailed mapping2 mapping notes Perform periodic technical and nontechnical evaluations and repeat them in response to environmental or operational changes affecting ePHI security. Network Box contributionPartialNetwork Box supplies service reviews, configurations, monitoring records, incidents, findings, trends, and technical recommendations for the managed scope. Regulated entity responsibilityClient responsibilityDefine evaluation scope, frequency, independence, and depth; cover all Security Rule requirements and the complete environment; document conclusions; and remediate deficiencies. | |||
| Service, data-handling, security, incident, subcontractor, and assurance information can support accurate arrangements. | Partial | ||
Detailed mapping2 mapping notes Obtain satisfactory assurances through a compliant contract or other arrangement when a business associate creates, receives, maintains, or transmits ePHI. Network Box contributionPartialNetwork Box can describe service scope, data handling, security responsibilities, incident processes, service levels, subcontractors, and available assurance information. Regulated entity responsibilityClient responsibilityDetermine business-associate status, execute a compliant BAA before PHI is handled, ensure terms match actual operations, flow duties to subcontractors, monitor performance, and address violations. | |||
| Service and assurance information may support evaluation of facilities used to deliver managed services. | Supporting | ||
Detailed mapping2 mapping notes Limit physical access to electronic information systems and facilities while ensuring properly authorized access and addressing contingency, validation, maintenance, and facility-security procedures. Network Box contributionSupportingNetwork Box can provide available information about facilities used for its services, while remote monitoring and segmentation may reduce some consequences of unauthorized physical access. Regulated entity responsibilityClient responsibilityControl physical access at healthcare and administrative facilities, maintain required procedures and records, validate authorization, support contingency operations, and govern maintenance. | |||
| Web, endpoint, and network controls can enforce or observe selected technical aspects of acceptable use. | Supporting | ||
Detailed mapping2 mapping notes Specify the proper functions, manner of use, and physical surroundings of workstations that can access ePHI. Network Box contributionSupportingNetwork Box can filter risky activity, monitor connected workstations, detect malicious behavior, and enforce network-use restrictions within scope. Regulated entity responsibilityClient responsibilityDefine and enforce workstation-use policy for clinical, administrative, remote, shared, and public environments, including positioning, unattended use, and local handling of ePHI. | |||
| Endpoint detection and network enforcement help protect and isolate subscribed workstations. | Partial | ||
Detailed mapping2 mapping notes Implement physical safeguards that restrict access to workstations capable of accessing ePHI to authorized users. Network Box contributionPartialWithin scope, Network Box detects suspicious endpoint activity, restricts communications, monitors access, and can assist with isolation of compromised systems. Regulated entity responsibilityClient responsibilityPhysically secure laptops, clinical stations, shared workstations, remote devices, and unattended systems and ensure only authorized personnel can use them. | |||
| Managed-service data-handling information supports oversight of security records inside the contracted scope. | Supporting | ||
Detailed mapping2 mapping notes Govern receipt, movement, removal, disposal, and reuse of hardware and electronic media containing ePHI and maintain accountability and retrievable copies where applicable. Network Box contributionSupportingNetwork Box restricts access to security information in its managed scope and can document relevant handling practices for the service. Regulated entity responsibilityClient responsibilityInventory and control all ePHI devices and media, authorize movement, sanitize before reuse or disposal, maintain accountability, and create retrievable copies before movement when required. | |||
| Managed enforcement, segmentation, VPN, gateway policy, and supported authentication restrict access paths. | Partial | ||
Detailed mapping2 mapping notes Implement technical policies and procedures that allow access to systems containing ePHI only by authorized persons or software programs. Network Box contributionPartialNetwork Box firewalls, segmentation, VPN, SD-WAN policy, secure gateways, WAF, and identity integrations help control network and remote access within scope. Regulated entity responsibilityClient responsibilityAssign unique identities, govern application and data permissions, implement emergency access and automatic logoff where appropriate, and manage privileged and service accounts across all ePHI systems. | |||
| Centralized records, correlation, searches, analyst review, and reporting support examination of ePHI-system activity. | Strong | ||
Detailed mapping2 mapping notes Implement hardware, software, or procedural mechanisms that record and examine activity in information systems containing or using ePHI. Network Box contributionStrongNetwork Box collects connected telemetry, correlates events, investigates suspicious behavior, identifies interrupted sources, and provides searches, dashboards, and reports. Regulated entity responsibilityClient responsibilityEnsure every relevant system generates required events, preserve user and clinical context, protect and retain logs, define review procedures, and validate coverage across the complete ePHI environment. | |||
| Layered prevention and monitoring detect malicious alteration, exploitation, or destruction affecting systems and communications. | Partial | ||
Detailed mapping2 mapping notes Implement policies and procedures that protect ePHI from improper alteration or destruction and electronic mechanisms to corroborate integrity when required. Network Box contributionPartialNetwork Box threat prevention, email and web security, WAF, SIEM, MDR/XDR, and managed network controls identify attacks and suspicious changes within visibility. Regulated entity responsibilityClient responsibilityProtect integrity within applications, databases, interfaces, medical devices, storage, and backups; validate clinical and transaction data; and remediate altered or compromised information. | |||
| VPN authentication, supported MFA and directories, restricted administration, and telemetry protect managed access. | Partial | ||
Detailed mapping2 mapping notes Implement procedures to verify that a person or entity seeking access to ePHI is the one claimed. Network Box contributionPartialNetwork Box supports authentication for VPN and managed services, compatible MFA/TOTP and directory integrations, controlled administration, and authentication logging. Regulated entity responsibilityClient responsibilityAuthenticate workforce members, patients, partners, systems, devices, applications, APIs, and service accounts and govern credential lifecycle, recovery, federation, and privileged access. | |||
| Secure connectivity, traffic policy, segmentation, and monitoring protect ePHI moving through managed paths. | Strong | ||
Detailed mapping2 mapping notes Implement technical measures that guard against unauthorized access to ePHI transmitted over electronic communications networks, including integrity and encryption where appropriate. Network Box contributionStrongNetwork Box VPN, managed gateways, secure connectivity, segmentation, web and email protections, and monitoring protect data in transit across configured network paths. Regulated entity responsibilityClient responsibilityIdentify every ePHI transmission path, protect application, message, file, API, device, and third-party exchanges, manage certificates and keys, and validate the end-to-end implementation. | |||
| Accurate service and responsibility information supports BAAs and other required organizational arrangements. | Partial | ||
Detailed mapping2 mapping notes Ensure business-associate and group-health-plan arrangements contain required terms and establish appropriate safeguards and reporting responsibilities. Network Box contributionPartialNetwork Box can document its services, data handling, security duties, incident processes, subcontractors, and available controls where it acts as a business associate or subcontractor. Regulated entity responsibilityClient responsibilityDetermine which organizational requirements apply, execute and maintain compliant arrangements, ensure terms match service reality, and flow restrictions and safeguards downstream. | |||
| Managed-service procedures, configurations, escalation paths, and reports support technical portions of written policy. | Supporting | ||
Detailed mapping2 mapping notes Implement reasonable and appropriate policies and procedures to comply with the Security Rule and account for changing operational and environmental conditions. Network Box contributionSupportingNetwork Box can provide service processes, control information, configurations, escalation procedures, and reports for managed safeguards. Regulated entity responsibilityClient responsibilityOwn comprehensive policies and procedures for the regulated environment, approve and communicate them, align them to the risk analysis, and update them when technology, threats, or responsibilities change. | |||
| Configuration, investigation, vulnerability, incident, and service records evidence managed activities. | Partial | ||
Detailed mapping2 mapping notes Maintain required policies, procedures, actions, activities, and assessments in written form, make them available to responsible personnel, update them, and retain required documentation for six years. Network Box contributionPartialNetwork Box can supply configuration records, reports, investigations, vulnerability findings, change history, incident information, and service documentation for the agreed scope and retention. Regulated entity responsibilityClient responsibilityMaintain the authoritative compliance record, tie evidence to policies and risk decisions, control access, ensure required availability, document changes, and retain it for the applicable period. | |||
These mappings are illustrative and depend on deployment, configuration, service scope, the client environment, and evidence requirements. Strong, Partial, and Supporting describe Network Box's potential contribution, not a compliance conclusion.
Encryption and scope
Encryption is addressable under the current Security Rule, which still requires a documented reasonableness-and-appropriateness decision. VPN and secure transport can protect managed paths, but the regulated entity must validate ePHI protection at rest and in every application, message, file transfer, API, device, backup, and third-party exchange. This includes the methods and key management needed for any breach safe harbor.
Incident and breach readiness
Network Box can provide rapid technical facts and response support. The regulated entity must determine whether PHI was involved, apply the required breach analysis, and complete every applicable notification.
Attempted or successful unauthorized access, use, disclosure, alteration, destruction, or interference must be identified, addressed, mitigated where practicable, and documented.
Ransomware affecting ePHI systems is a security incident and requires investigation of access, acquisition, modification, encryption, exfiltration, integrity, and availability.
An impermissible use or disclosure is generally presumed to be a breach unless an exception applies or the required assessment supports a low probability of compromise.
For applicable breaches, the current rule uses outside notification limits of 60 calendar days; larger breaches have prompt HHS and potentially media-notice requirements.
A business associate must notify the covered entity without unreasonable delay and within the regulatory outside limit, while a BAA may require much faster initial reporting.
Named contacts, event timelines, affected assets, PHI context, indicators, containment actions, preservation steps, and continuing updates should be planned before an incident.
Assessment evidence
Available evidence depends on deployed services, configured log sources, agreed scope, format, and retention period.
Coverage key
Network Box can directly deliver and operate a substantial part of this technical outcome when the relevant services are in scope.
Network Box contributes meaningful controls, but the requirement also depends on the client's systems, configuration, people, or processes.
Network Box provides useful security operations or evidence, but does not satisfy the requirement by itself.
This area primarily remains with the MSP and client, their assessors, or other qualified parties.
Shared responsibility
The covered entity or business associate owns applicability, its complete ePHI inventory and risk analysis, governance, workforce and physical safeguards, identity and data controls, contingency planning, documentation, business-associate oversight, breach determinations, notifications, and every system or process outside the managed-service scope.
HIPAA / HITECH FAQ
Bring current HIPAA Security Rule safeguards into continuous managed operation while preparing for incidents and breaches involving ePHI.
Network Box USA can operate managed technical safeguards, monitor the subscribed environment, investigate and escalate security activity, maintain managed configurations, and produce service evidence that may support applicable HIPAA / HITECH requirements.
No. A managed security service can contribute controls, operations, and evidence, but it cannot guarantee compliance or replace the organization's governance, complete scope, legal interpretation, assessment, or formal certification and attestation work.
Use the mapping as a scoping and evidence-planning aid. Each row explains the requirement, the potential Network Box contribution, available evidence, the coverage level, and the work that remains with the organization.
Depending on the deployed services and agreed retention, evidence may include managed configurations, logs, alerts, incident records, vulnerability findings, change records, service reports, and recurring operational reviews. The assessor determines whether evidence is sufficient.
The covered entity or business associate owns applicability, its complete ePHI inventory and risk analysis, governance, workforce and physical safeguards, identity and data controls, contingency planning, documentation, business-associate oversight, breach determinations, notifications, and every system or process outside the managed-service scope.
The information in this Compliance Center is provided for general informational purposes and does not constitute legal, regulatory, audit, or certification advice. Requirements vary by organization, jurisdiction, contract, data, and system scope. Network Box services can support selected technical and operational safeguards but do not by themselves establish compliance, certification, or attestation. Each organization remains responsible for determining its obligations, defining scope, implementing governance and non-technical controls, and obtaining advice or assessment from qualified legal, compliance, audit, or certification professionals.
Security stack review