
The Administrative Simplification section of HIPAA consists of a trioof regulations that address privacy, transactions and security. Implementationof the final Security Rule and its mandated security practices must be ineffect as of April 20, 2005, for most covered entities. Although the PrivacyRule requires the presence of "adequate safeguards" for ProtectedHealth Information (PHI), the Security Rule details more than 40 separateaudit points within the categories of technical, administrative and physicalsafeguards. While the Security regulation addresses what must be done, itdoes not provide a road map for how to do it.