Final answer:
Covered entities under HIPAA are required to review their security rule standards and decide if each security safeguard is required or if an equivalent method can be used.
Step-by-step explanation:
Under HIPAA, covered entities are required to review their security rule standards and implementation specifications for each security safeguard and determine if it is required or “equivalent” measures can be used. The HIPAA Security Rule establishes national standards for the protection of electronic protected health information (ePHI) that is created, received, used, or maintained by covered entities. These standards include administrative, physical, and technical safeguards that covered entities must implement to ensure the confidentiality, integrity, and availability of ePHI.