45 CFR § 164.308
Administrative safeguards
The Security Rule section that requires a risk analysis, and the most-cited deficiency in OCR enforcement.
Read the full official text on eCFRResearched and written by Larry Osakwe · Last verified August 4, 2026
Checked against 45 CFR 164.308 via eCFR. Not a lawyer, not a certified compliance professional, and not affiliated with HHS.
What 164.308 actually says
164.308 is the administrative half of the Security Rule. It requires a security management process, and the first implementation specification under it is the risk analysis, which is marked Required rather than Addressable. There is no version of compliance that omits it.
The wording matters. The rule asks for an assessment that is accurate and thorough, covering all electronic PHI you hold. Not a questionnaire about your EHR: every system that touches ePHI, including email, backups, imaging and devices.
The paragraphs above are our plain-English reading. The blocks below are quoted verbatim from the regulation.
The text that matters
Risk analysis (Required). Conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information held by the covered entity or business associate.
Standard: Assigned security responsibility. Identify the security official who is responsible for the development and implementation of the policies and procedures required by this subpart for the covered entity or business associate.
Information system activity review (Required). Implement procedures to regularly review records of information system activity, such as audit logs, access reports, and security incident tracking reports.
Quoted from 45 CFR § 164.308. US federal regulations are not subject to copyright. Retrieved from eCFR and last checked August 4, 2026.
What this section means you must hold
The regulation states obligations. This is the paperwork those obligations translate into, which is the part the regulation itself leaves you to work out.
| The obligation | What you produce for it |
|---|---|
| Conduct and document a risk analysis across every system holding ePHI | A written Security Risk Analysis, dated, with the systems listed |
| Name a security official in writing | A Security Official designation. In a solo practice this is you, and it still has to be written down. |
| Train the workforce and sanction violations | Written policies, a training log with names and dates, a sanctions policy |
Where practices get 164.308 wrong
Believing the EHR vendor did it. Your vendor can assess its own platform; it cannot assess your laptop, your email, your backup drive or your front desk. The second mistake is treating the risk analysis as one-time. It is the document OCR asks for first, and a five-year-old copy that predates your current systems answers the wrong question.
Other sections people look up
45 CFR § 160.103
Definitions
45 CFR § 164.504(e)
Uses and disclosures: Organizational requirements
45 CFR § 164.520
Notice of privacy practices for protected health information
45 CFR § 164.508
Uses and disclosures for which an authorization is required
Educational summaries of federal regulations, not legal advice and not a determination about any specific practice. Where our reading and the regulation differ, the regulation controls; the eCFR link above is authoritative.
Get every document, done for you
Preview the binder free. Your binder is built to order and delivered within 30 days, with a full refund anytime before then.
See the binder and pricing