HIPAA, NIST SP 800-66, and HITRUST CSF Explained for Healthcare Businesses

Table of Contents

If your business creates, receives, stores, or transmits patient health information, one thing is true no matter what industry framework you’re also working toward: HIPAA compliance isn’t optional. But HIPAA itself doesn’t hand you a checklist. This guide breaks down what HIPAA actually requires, the NIST guide built specifically to help you implement it, and the certification most healthcare partners actually ask to see.

Because the HIPAA Security Rule describes objectives rather than step-by-step configurations, organizations must map their systems against broader cybersecurity control standards like NIST and ISO to build an audit-defensible baseline.

HIPAA is a law, not a control standard

The Health Insurance Portability and Accountability Act is a federal law, not a security framework you can be “certified” against. It applies to covered entities — healthcare providers, health plans, and healthcare clearinghouses — and their business associates, the vendors and contractors those covered entities rely on. It’s enforced by the HHS Office for Civil Rights, and violations carry real financial and legal consequences.

HIPAA’s Privacy Rule and Security Rule require organizations to protect patient data and give individuals certain rights over their own health information. But the law is deliberately written around outcomes rather than specific technical controls: it says safeguards must be “reasonable and appropriate,” without listing exactly which tools, settings, or procedures satisfy that bar. That’s useful for flexibility, but it leaves a real question for any business owner: reasonable and appropriate, according to whom?

NIST SP 800-66: the implementation roadmap

Healthcare professional protecting electronic health information with cybersecurity controls
NIST SP 800-66 provides practical guidance for protecting electronic health information.

NIST Special Publication 800-66 is the answer to that question. Now in its second revision — published in February 2024 and developed jointly with HHS — it’s NIST’s official cybersecurity resource guide for implementing the HIPAA Security Rule. Rather than leaving “reasonable and appropriate” open to interpretation, 800-66 walks through each Security Rule standard and maps it to concrete safeguards, including direct mappings to NIST SP 800-53 controls and the NIST Cybersecurity Framework.

In practice, this is what a business actually builds toward when it says it’s “HIPAA compliant.” It’s not a certification and nobody audits you against it directly — but it’s the closest thing to a technical checklist behind the law, and it’s what a knowledgeable IT or security partner should be building your safeguards around.

To satisfy NIST SP 800-66 safeguards for data at rest and data in transit, healthcare clinics must deploy dedicated data protection and encryption services across local servers and cloud databases.

HITRUST CSF: the certification that proves it

HIPAA is a legal requirement, and NIST SP 800-66 is how you meet it — but neither gives you something to hand a partner, payer, or customer as proof. That’s where HITRUST CSF comes in. It’s a certifiable framework that pulls from more than 50 authoritative sources — including HIPAA, ISO/IEC 27001, and NIST — into a single, harmonized control set.

Achieving recognized third-party validation also streamlines annual audits when evaluating whether your healthcare business is ready for cyber insurance.

Instead of separately proving compliance with HIPAA, ISO, and whatever else a given partner asks for, a business completes one HITRUST assessment and gets a certification that stands in for all of them. There are three tiers, matched to risk and assurance level:

Certification Best for Scope Validity
e1 (Essentials) Lower-risk organizations wanting baseline cyber hygiene proof 44 foundational controls 1 year
i1 (Implemented) Organizations needing moderate assurance 219 controls 1 year
r2 (Risk-based) Organizations facing the highest scrutiny — typically health systems, payers, and their larger vendors Comprehensive, risk-tailored control set 2 years, with a year-one interim check

It’s become the certification health systems and insurers most often require from their vendors, precisely because it saves everyone from re-proving the same underlying controls five different ways for five different partners.

How the three fit together

Put simply: HIPAA is the law that says you must protect patient data. NIST SP 800-66 is the roadmap for what “protecting it” actually looks like in practice. HITRUST CSF is how you prove it — formally and repeatably — to a partner who asks. A healthcare business doesn’t get to pick just one; the law applies regardless, 800-66 is the sensible way to build toward it, and HITRUST becomes relevant the moment a partner, payer, or contract requires documented proof rather than your word for it.

How BCS helps Austin healthcare businesses navigate HIPAA

Healthcare business professionals reviewing secure IT systems for HIPAA compliance
Secure IT systems help healthcare businesses protect sensitive data and support HIPAA compliance.

Business Communication Solutions works with healthcare providers, clinics, and their vendors across Austin and the surrounding area to build IT environments that hold up to HIPAA’s Security Rule — using NIST SP 800-66 as the practical blueprint, and preparing for HITRUST when a partner or payer requires it. For related reading, see our guide to cybersecurity control standards (NIST SP 800-53, ISO/IEC 27001, and CMMC) if you’re weighing multiple compliance requirements at once.

Not sure where your practice or business stands on HIPAA?
Get a straightforward review of your current safeguards against the HIPAA Security Rule — not a generic checklist. Contact BCS to schedule a conversation.

You can also check our cybersecurity services in Austin Tx.

FAQs

Q: What is the primary difference between HIPAA, NIST SP 800-66, and HITRUST CSF?

A: HIPAA is a federal law specifying legal obligations for protecting Protected Health Information (PHI) without dictating specific technical tools. NIST SP 800-66 Rev. 2 is the federal implementation guideline mapping the HIPAA Security Rule to actionable NIST SP 800-53 controls. HITRUST CSF is a third-party certifiable framework that translates multiple regulations (including HIPAA, NIST, and ISO) into an auditable certification.

Q: Is there an official government HIPAA certification?

A: No. The U.S. Department of Health and Human Services (HHS) does not certify software, vendors, or medical practices. Organizations use independent assessments against frameworks like HITRUST CSF to prove compliance to partners and auditors.

Q: Does NIST SP 800-66 apply to small medical practices?

A: Yes. While small practices are not mandated to implement every advanced control, NIST SP 800-66 provides scalable guidance tailored to small healthcare providers to help them meet the HIPAA Security Rule legally and affordably.

Q: What are the three HITRUST CSF assessment levels?

A: HITRUST offers three tiers: e1 (Essentials 1-year, verifying foundational hygiene), i1 (Implemented 1-year, validating threat-adaptive best practices), and r2 (Risk-based 2-year, representing comprehensive enterprise-grade validation).

Q: What constitutes a Business Associate Agreement (BAA) under HIPAA?

A: A BAA is a legally binding contract between a covered entity and a vendor (such as an IT provider or cloud host) that handles ePHI, mandating that the vendor implements HIPAA-compliant security safeguards.

Q: What technical safeguards does NIST SP 800-66 emphasize most?

A: It focuses heavily on access control, unique user identification, emergency access procedures, automatic logoff, end-to-end data encryption, audit log monitoring, and integrity controls.

Q: Can cloud storage like Google Drive or Dropbox be HIPAA compliant?

A: Only if the provider signs a BAA and the account is configured with strict access controls, multi-factor authentication (MFA), disabled public link sharing, and comprehensive audit logging.

Q: How often should an Austin healthcare business perform a HIPAA security risk assessment?

A: While HIPAA requires periodic reviews, industry standards and NIST SP 800-66 recommend conducting a thorough security risk analysis at least annually or whenever significant changes are made to your IT infrastructure.

 

Related Cybersecurity Reads: