Required vs addressable safeguards
Addressable is the most misread word in HIPAA. It never means optional.
What the rule says
Under 45 CFR 164.306: general rules, including addressable specifications, paragraph (d), for each addressable specification you must assess whether it is reasonable and appropriate in your environment, then either:
- implement it; or
- if it isn't reasonable and appropriate, document why, and implement an equivalent alternative measure if one is reasonable and appropriate.
Required specifications must be implemented. Either way, the underlying standard must be met. That's why the free tool offers "Alternative documented" only for addressable items.
How to document an addressable decision
| Specification | Decision | Reason | Alternative | Reviewed |
|---|---|---|---|---|
| 164.312(a)(2)(iv) Encryption and decryption | Implemented on laptops and backups; not on the ultrasound cart PC | Vendor-locked operating system, encryption unsupported | Cart PC kept in a locked room, no local ePHI storage, network-segmented | Yearly and at replacement |
Cost alone is rarely a convincing reason when a free option exists (most laptops ship with disk encryption). Keep the decision with your risk analysis.
The count
Following the Appendix A to Subpart C of Part 164: Security Standards Matrix (eCFR) and section 164.316, the safeguards contain 46 implementation specifications and standards (24 required, 22 addressable). Our checklist marks each one.
Proposed change: HHS's January 2025 proposed rule (Federal Register, 6 January 2025: HIPAA Security Rule proposed rule (90 FR 898)) would remove the distinction and make nearly all specifications required, with limited exceptions. It is not final. Track it on our rule status page.
Find your gaps and build a risk register in about 15 minutes: Start the free HIPAA risk assessment
Questions
Can I skip an addressable specification?
Only after assessing it and documenting why it isn't reasonable and appropriate for you, and then implementing an equivalent alternative if one is reasonable and appropriate. The standard itself still has to be met (45 CFR 164.306(d)).
Is encryption required under HIPAA?
Encryption of ePHI at rest (164.312(a)(2)(iv)) and in transit (164.312(e)(2)(ii)) are addressable today, which means you must implement them or document why not and what equivalent measure you use. The January 2025 proposed rule would make encryption required, with limited exceptions, if finalized.
Not legal advice. This is a free self-assessment aid, not an audit, a certification or legal advice, and it isn't affiliated with or endorsed by HHS. A quick check is not a full risk analysis: HHS expects an accurate and thorough assessment of the risks to all the ePHI you hold.