HIPAA Risk Assessment Toolby Agent Trust Cloud

Required vs addressable safeguards

Addressable is the most misread word in HIPAA. It never means optional.

What the rule says

Under 45 CFR 164.306: general rules, including addressable specifications, paragraph (d), for each addressable specification you must assess whether it is reasonable and appropriate in your environment, then either:

  1. implement it; or
  2. if it isn't reasonable and appropriate, document why, and implement an equivalent alternative measure if one is reasonable and appropriate.

Required specifications must be implemented. Either way, the underlying standard must be met. That's why the free tool offers "Alternative documented" only for addressable items.

How to document an addressable decision

SpecificationDecisionReasonAlternativeReviewed
164.312(a)(2)(iv) Encryption and decryptionImplemented on laptops and backups; not on the ultrasound cart PCVendor-locked operating system, encryption unsupportedCart PC kept in a locked room, no local ePHI storage, network-segmentedYearly and at replacement

Cost alone is rarely a convincing reason when a free option exists (most laptops ship with disk encryption). Keep the decision with your risk analysis.

The count

Following the Appendix A to Subpart C of Part 164: Security Standards Matrix (eCFR) and section 164.316, the safeguards contain 46 implementation specifications and standards (24 required, 22 addressable). Our checklist marks each one.

Proposed change: HHS's January 2025 proposed rule (Federal Register, 6 January 2025: HIPAA Security Rule proposed rule (90 FR 898)) would remove the distinction and make nearly all specifications required, with limited exceptions. It is not final. Track it on our rule status page.

Find your gaps and build a risk register in about 15 minutes: Start the free HIPAA risk assessment

Questions

Can I skip an addressable specification?

Only after assessing it and documenting why it isn't reasonable and appropriate for you, and then implementing an equivalent alternative if one is reasonable and appropriate. The standard itself still has to be met (45 CFR 164.306(d)).

Is encryption required under HIPAA?

Encryption of ePHI at rest (164.312(a)(2)(iv)) and in transit (164.312(e)(2)(ii)) are addressable today, which means you must implement them or document why not and what equivalent measure you use. The January 2025 proposed rule would make encryption required, with limited exceptions, if finalized.

Not legal advice. This is a free self-assessment aid, not an audit, a certification or legal advice, and it isn't affiliated with or endorsed by HHS. A quick check is not a full risk analysis: HHS expects an accurate and thorough assessment of the risks to all the ePHI you hold.

Sources