Addressable does not mean optional

The most expensive misunderstanding in the HIPAA Security Rule, what 45 CFR 164.306(d) actually requires you to do, and a full table of every implementation specification and how it is labelled.

Last verified: 2026-07-12

If you take one thing from this knowledge base, take this: in the HIPAA Security Rule, “addressable” does not mean optional.

It is the most common misunderstanding in small practice, and it is expensive, because the clinic that believes addressable means optional does nothing and documents nothing. That clinic has not made a defensible judgment call. It has simply failed to do the work, and the failure is invisible until an investigator asks.

Where the labels come from

The Security Rule sets standards, and under most standards it sets implementation specifications: the specific things you do to meet the standard. Each specification is labelled either required or addressable, and the label appears in parentheses right after its title in the regulation (45 CFR 164.306(d)(1)).

If a specification is required, you implement it. There is no analysis, no judgment, no alternative (45 CFR 164.306(d)(2)). Assigning every user a unique login is required (45 CFR 164.312(a)(2)(i)). Shared logins are not a risk decision you get to make.

What addressable actually obligates you to do

When a specification is addressable, 45 CFR 164.306(d)(3) gives you exactly one path, and it has steps.

First, you must assess whether the specification is a reasonable and appropriate safeguard in your environment, judged by how much it would actually contribute to protecting ePHI (45 CFR 164.306(d)(3)(i)).

Then one of two things happens.

If it is reasonable and appropriate, you implement it (45 CFR 164.306(d)(3)(ii)(A)).

If it is not reasonable and appropriate, you must do two things, and both of them (45 CFR 164.306(d)(3)(ii)(B)). You document why it would not be reasonable and appropriate to implement it. And you implement an equivalent alternative measure, if an equivalent alternative is itself reasonable and appropriate.

Read that again, because it is the whole point. The addressable path is not “skip it.” The addressable path is “assess it, then either do it, or write down why you are not doing it and do something else instead.” Doing nothing and writing nothing is not one of the options the rule offers.

Every implementation specification, and how it is labelled

Here is the whole map. Fourteen specifications are required across the three safeguard families. Twenty-two are addressable, which means twenty-two decisions you are expected to have made, and to be able to show.

Implementation specificationLabelCitation
Administrative safeguards (45 CFR 164.308)
Risk analysisRequired164.308(a)(1)(ii)(A)
Risk managementRequired164.308(a)(1)(ii)(B)
Sanction policyRequired164.308(a)(1)(ii)(C)
Information system activity reviewRequired164.308(a)(1)(ii)(D)
Authorization and/or supervisionAddressable164.308(a)(3)(ii)(A)
Workforce clearance procedureAddressable164.308(a)(3)(ii)(B)
Termination proceduresAddressable164.308(a)(3)(ii)(C)
Isolating health care clearinghouse functionsRequired164.308(a)(4)(ii)(A)
Access authorizationAddressable164.308(a)(4)(ii)(B)
Access establishment and modificationAddressable164.308(a)(4)(ii)(C)
Security remindersAddressable164.308(a)(5)(ii)(A)
Protection from malicious softwareAddressable164.308(a)(5)(ii)(B)
Log-in monitoringAddressable164.308(a)(5)(ii)(C)
Password managementAddressable164.308(a)(5)(ii)(D)
Response and reportingRequired164.308(a)(6)(ii)
Data backup planRequired164.308(a)(7)(ii)(A)
Disaster recovery planRequired164.308(a)(7)(ii)(B)
Emergency mode operation planRequired164.308(a)(7)(ii)(C)
Testing and revision proceduresAddressable164.308(a)(7)(ii)(D)
Applications and data criticality analysisAddressable164.308(a)(7)(ii)(E)
Written contract or other arrangementRequired164.308(b)(3)
Physical safeguards (45 CFR 164.310)
Contingency operationsAddressable164.310(a)(2)(i)
Facility security planAddressable164.310(a)(2)(ii)
Access control and validation proceduresAddressable164.310(a)(2)(iii)
Maintenance recordsAddressable164.310(a)(2)(iv)
DisposalRequired164.310(d)(2)(i)
Media re-useRequired164.310(d)(2)(ii)
AccountabilityAddressable164.310(d)(2)(iii)
Data backup and storageAddressable164.310(d)(2)(iv)
Technical safeguards (45 CFR 164.312)
Unique user identificationRequired164.312(a)(2)(i)
Emergency access procedureRequired164.312(a)(2)(ii)
Automatic logoffAddressable164.312(a)(2)(iii)
Encryption and decryptionAddressable164.312(a)(2)(iv)
Mechanism to authenticate electronic protected health informationAddressable164.312(c)(2)
Integrity controlsAddressable164.312(e)(2)(i)
EncryptionAddressable164.312(e)(2)(ii)

Two things the table does not show, and both of them catch people

First, six standards have no implementation specifications at all. There is nothing under them to label, so nothing appears above. They are not optional. They are the standard itself, and you must meet them: assigned security responsibility (45 CFR 164.308(a)(2)), evaluation (45 CFR 164.308(a)(8)), workstation use (45 CFR 164.310(b)), workstation security (45 CFR 164.310(c)), audit controls (45 CFR 164.312(b)), and person or entity authentication (45 CFR 164.312(d)). No specification does not mean no obligation.

Second, the table covers the three safeguard families. The Security Rule also carries specifications under organizational requirements (45 CFR 164.314) and under policies, procedures, and documentation (45 CFR 164.316). Every one of those is required. There is no addressable path in either.

The judgment is yours, and it is on the record

The rule is genuinely flexible about how you get there. You may use any security measures that let you meet the standards reasonably and appropriately (45 CFR 164.306(b)(1)), and in choosing, you must take into account your size, complexity, and capabilities; your technical infrastructure, hardware, and software security capabilities; the costs of the measures; and the probability and criticality of the potential risks to ePHI (45 CFR 164.306(b)(2)).

A twelve-person ABA clinic is not held to a hospital’s answer. It is held to a real answer.

And the answer has to exist in writing. Documentation required by the Security Rule must be kept in written or electronic form (45 CFR 164.316(b)(1)), retained for six years from creation or from the date it was last in effect, whichever is later (45 CFR 164.316(b)(2)(i)), and reviewed and updated as your operations change (45 CFR 164.316(b)(2)(iii)). Your security measures themselves must be reviewed and modified as needed to keep protection reasonable and appropriate (45 CFR 164.306(e)).

An addressable decision made in someone’s head, three years ago, that nobody wrote down, is indistinguishable from having never made the decision at all.

What this looks like in an ABA clinic

Encryption of ePHI at rest is addressable (45 CFR 164.312(a)(2)(iv)). So you assess it. If your RBTs carry tablets into family homes, encryption is cheap, it is built into the devices you already own, and the risk it mitigates is a device walking out of a living room. It is going to be reasonable and appropriate, and the honest conclusion is that you implement it.

“An addressable decision made in someone's head, three years ago, that nobody wrote down, is indistinguishable from having never made the decision at all.”

Automatic logoff is addressable (45 CFR 164.312(a)(2)(iii)). Same process, and the same likely answer, because the alternative is an unlocked session in a room with a family in it.

The point is not that addressable specifications always end in yes. The point is that they always end in a decision, and the decision is on the record.

What may change

In January 2025 HHS proposed the first substantial rewrite of the Security Rule in over two decades (90 FR 800, published January 6, 2025). Among many other changes, the proposal would eliminate the addressable category entirely and make every implementation specification required.

This is a proposal. It is not law. No final rule has been issued, the comment period closed in March 2025, and the federal regulatory agenda now shows final action pushed to July 2027. It may be finalized, narrowed, delayed again, or withdrawn.

What matters today is that OCR is enforcing the rule that exists. Under that rule, addressable still means assess, decide, document, and act. It has never meant ignore.

The short version

  • Every Security Rule implementation specification is labelled required or addressable, and addressable has never meant optional.
  • The addressable path is: assess it, then implement it, or document why not and implement an equivalent alternative. Doing nothing and writing nothing is not on the list.
  • 14 specifications are required, 22 are addressable; the full table on this page maps every one.
  • Six standards have no specifications at all; they are obligations in themselves.
  • The 2025 proposed rule would eliminate the addressable category entirely, but it is a proposal, not law.

This article is educational information about the HIPAA regulations, not legal advice. It describes what the rules say; it does not tell you what to do about your specific situation, and reading it does not create an attorney-client or consultant-client relationship. Regulations change, and enforcement positions change with them. For advice on your clinic, talk to a qualified professional.

Sources

Twenty-two decisions, and a record of each one.

Every addressable specification is a decision you are expected to have made, documented, and kept current. Most clinics have made none of them on paper. WiseUpHIPAA works out what applies to your clinic, holds the decisions and the evidence behind them, and shows you honestly where you actually stand, including the parts that are not done yet.