Below are the administrative and physical safeguards as outlined in the Federal Register. These requirements are items that must generally be addressed internally, even if you are outsourcing your email.
| Standard: ADMINISTRATIVE SAFEGUARDS | Sections | Implementation Specification | Required or Addressable |
| Security Management Process | 164.308(a)(1) | Risk Analysis | R |
| Risk Management | R | ||
| Sanction Policy | R | ||
| Information System Activity Review | R | ||
| Assigned Security Responsibility | 164.308(a)(2) | R | |
| Workforce Security | 164.308(a)(3) | Authorization and/or Supervision | A |
| Workforce Clearance Procedures | R | ||
| Termination Procedures | A | ||
| Information Access Management | 164.308(a)(4) | Isolating Health Care Clearinghouse Function | R |
| Access Authorization | A | ||
| Access Establishment and Modification | A | ||
| Security Awareness and Training | 164.310(a)(5) | Security Reminders | A |
| Protection from Malicious Software | A | ||
| Log-in Monitoring | A | ||
| Password Management | A | ||
| Security Incident Procedures | 164.308(a)(6) | Response and Reporting | R |
| Contingency Plan | 164.308(a)(7) | Data Backup Plan | R |
| Disaster Recovery Plan | R | ||
| Emergency Mode Operation Plan | R | ||
| Testing and Revision Procedure | A | ||
| Applications and Data Criticality Analysis | A | ||
| Evaluation | 164.308(a)(8) | R | |
| Business Associates Contracts and Other Arrangement. | 164.308(b)(1) | Written Contract or Other Arrangement | R |
| Standard: PHYSICAL SAFEGUARDS | Sections | Implementation Specification | Required or Addressable |
| Facility Access Controls | 164.310(a)(1) | Contingency Operations | A |
| Facility Security Plan | A | ||
| Access Control and Validation Procedures | A | ||
| Maintenance Records | A | ||
| Audit Controls | 164.312(b) | R | |
| Integrity | 164.312(c)(1) | Mechanism to Authenticate EPHI | A |
| Workstation Use | 164.310(b) | R | |
| Workstation Security | 164.310(c) | R | |
| Device and Media Controls | 164.310(d) | Disposal | R |
| Media Re-use | R | ||
| Accountability | A | ||
| Data Backup and Storage | A |

This innocuous acronym stands for Health Insurance Portability and Accountability Act. This is a federal statute that was enacted in 1996 to attempt to protect the medical records of citizens. The Act itself is massive, and covers many aspects of medical care and the handling of records and information. The two that are relevant to our needs are the privacy rule and the security rule. Both of which will be covered in depth later. There are other rules provided under the act and they are the Enforcement Rule, the Transactions and Code Sets Rule and the Unique Identifiers rule.