Two provisions of the HIPAA Administrative Simplification Act of 2001 - patient privacy and uniform electronic transaction standards - require health care organizations to adopt data security measures in order assure data privacy and integrity. Whether or not the HIPAA Security Rule is finalized by the deadlines for compliance with the Privacy Rule and the Electronic Security Transactions, health care organizations will need to implement data security procedures, since data privacy and integrity cannot be assured without adequate data security. This publication provides a comprehensive overview of the proposed Security Rule and describes the types of security "best practices" that health care organizations should implement to guarantee data security and integrity.