{"data":{"id":"us/45-cfr-164.304","jurisdiction":"us","citation":"45 CFR 164.304","heading":"Definitions.","body":"As used in this subpart, the following terms have the following meanings:\nAccess means the ability or the means necessary to read, write, modify, or communicate data/information or otherwise use any system resource. (This definition applies to “access” as used in this subpart, not as used in subparts D or E of this part.)\nAdministrative safeguards are administrative actions, and policies and procedures, to manage the selection, development, implementation, and maintenance of security measures to protect electronic protected health information and to manage the conduct of the covered entity's or business associate's workforce in relation to the protection of that information.\nAuthentication means the corroboration that a person is the one claimed.\nAvailability means the property that data or information is accessible and useable upon demand by an authorized person.\nConfidentiality means the property that data or information is not made available or disclosed to unauthorized persons or processes.\nEncryption means the use of an algorithmic process to transform data into a form in which there is a low probability of assigning meaning without use of a confidential process or key.\nFacility means the physical premises and the interior and exterior of a building(s).\nInformation system means an interconnected set of information resources under the same direct management control that shares common functionality. A system normally includes hardware, software, information, data, applications, communications, and people.\nIntegrity means the property that data or information have not been altered or destroyed in an unauthorized manner.\nMalicious software means software, for example, a virus, designed to damage or disrupt a system.\nPassword means confidential authentication information composed of a string of characters.\nPhysical safeguards are physical measures, policies, and procedures to protect a covered entity's or business associate's electronic information systems and related buildings and equipment, from natural and environmental hazards, and unauthorized intrusion.\nSecurity or Security measures encompass all of the administrative, physical, and technical safeguards in an information system.\nSecurity incident means the attempted or successful unauthorized access, use, disclosure, modification, or destruction of information or interference with system operations in an information system.\nTechnical safeguards means the technology and the policy and procedures for its use that protect electronic protected health information and control access to it.\nUser means a person or entity with authorized access.\nWorkstation means an electronic computing device, for example, a laptop or desktop computer, or any other device that performs similar functions, and electronic media stored in its immediate environment.","path":["Title 45—Public Welfare","SUBTITLE A—Department of Health and Human Services","SUBCHAPTER C—ADMINISTRATIVE DATA STANDARDS AND RELATED REQUIREMENTS","PART 164—SECURITY AND PRIVACY","Subpart C—Security Standards for the Protection of Electronic Protected Health Information"],"source_url":"https://www.ecfr.gov/api/versioner/v1/full/2026-08-25/title-45.xml","current_through":"2026-08-25","vintage":"","retrieved_at":"2026-08-27T02:26:21Z","sha256":"5ce87efb6100e3e791b324b716a24ceb9103c70e449e8b5374b80b05164f1cb5","source_id":"us-cfr","stale":true,"prev":"us/45-cfr-164.302","next":"us/45-cfr-164.306"},"notice":"GroundRules: Original legal text. Not legal advice."}
