Addressable does not mean optional
The most expensive misunderstanding in the HIPAA Security Rule, what 45 CFR 164.306(d) actually requires you to do, and a full table of every implementation specification and how it is labelled.
Last verified: 2026-07-12
If you take one thing from this knowledge base, take this: in the HIPAA Security Rule, “addressable” does not mean optional.
It is the most common misunderstanding in small practice, and it is expensive, because the clinic that believes addressable means optional does nothing and documents nothing. That clinic has not made a defensible judgment call. It has simply failed to do the work, and the failure is invisible until an investigator asks.
Where the labels come from
The Security Rule sets standards, and under most standards it sets implementation specifications: the specific things you do to meet the standard. Each specification is labelled either required or addressable, and the label appears in parentheses right after its title in the regulation (45 CFR 164.306(d)(1)).
If a specification is required, you implement it. There is no analysis, no judgment, no alternative (45 CFR 164.306(d)(2)). Assigning every user a unique login is required (45 CFR 164.312(a)(2)(i)). Shared logins are not a risk decision you get to make.
What addressable actually obligates you to do
When a specification is addressable, 45 CFR 164.306(d)(3) gives you exactly one path, and it has steps.
First, you must assess whether the specification is a reasonable and appropriate safeguard in your environment, judged by how much it would actually contribute to protecting ePHI (45 CFR 164.306(d)(3)(i)).
Then one of two things happens.
If it is reasonable and appropriate, you implement it (45 CFR 164.306(d)(3)(ii)(A)).
If it is not reasonable and appropriate, you must do two things, and both of them (45 CFR 164.306(d)(3)(ii)(B)). You document why it would not be reasonable and appropriate to implement it. And you implement an equivalent alternative measure, if an equivalent alternative is itself reasonable and appropriate.
Read that again, because it is the whole point. The addressable path is not “skip it.” The addressable path is “assess it, then either do it, or write down why you are not doing it and do something else instead.” Doing nothing and writing nothing is not one of the options the rule offers.
Every implementation specification, and how it is labelled
Here is the whole map. Fourteen specifications are required across the three safeguard families. Twenty-two are addressable, which means twenty-two decisions you are expected to have made, and to be able to show.
| Implementation specification | Label | Citation |
|---|---|---|
| Administrative safeguards (45 CFR 164.308) | ||
| Risk analysis | Required | 164.308(a)(1)(ii)(A) |
| Risk management | Required | 164.308(a)(1)(ii)(B) |
| Sanction policy | Required | 164.308(a)(1)(ii)(C) |
| Information system activity review | Required | 164.308(a)(1)(ii)(D) |
| Authorization and/or supervision | Addressable | 164.308(a)(3)(ii)(A) |
| Workforce clearance procedure | Addressable | 164.308(a)(3)(ii)(B) |
| Termination procedures | Addressable | 164.308(a)(3)(ii)(C) |
| Isolating health care clearinghouse functions | Required | 164.308(a)(4)(ii)(A) |
| Access authorization | Addressable | 164.308(a)(4)(ii)(B) |
| Access establishment and modification | Addressable | 164.308(a)(4)(ii)(C) |
| Security reminders | Addressable | 164.308(a)(5)(ii)(A) |
| Protection from malicious software | Addressable | 164.308(a)(5)(ii)(B) |
| Log-in monitoring | Addressable | 164.308(a)(5)(ii)(C) |
| Password management | Addressable | 164.308(a)(5)(ii)(D) |
| Response and reporting | Required | 164.308(a)(6)(ii) |
| Data backup plan | Required | 164.308(a)(7)(ii)(A) |
| Disaster recovery plan | Required | 164.308(a)(7)(ii)(B) |
| Emergency mode operation plan | Required | 164.308(a)(7)(ii)(C) |
| Testing and revision procedures | Addressable | 164.308(a)(7)(ii)(D) |
| Applications and data criticality analysis | Addressable | 164.308(a)(7)(ii)(E) |
| Written contract or other arrangement | Required | 164.308(b)(3) |
| Physical safeguards (45 CFR 164.310) | ||
| Contingency operations | Addressable | 164.310(a)(2)(i) |
| Facility security plan | Addressable | 164.310(a)(2)(ii) |
| Access control and validation procedures | Addressable | 164.310(a)(2)(iii) |
| Maintenance records | Addressable | 164.310(a)(2)(iv) |
| Disposal | Required | 164.310(d)(2)(i) |
| Media re-use | Required | 164.310(d)(2)(ii) |
| Accountability | Addressable | 164.310(d)(2)(iii) |
| Data backup and storage | Addressable | 164.310(d)(2)(iv) |
| Technical safeguards (45 CFR 164.312) | ||
| Unique user identification | Required | 164.312(a)(2)(i) |
| Emergency access procedure | Required | 164.312(a)(2)(ii) |
| Automatic logoff | Addressable | 164.312(a)(2)(iii) |
| Encryption and decryption | Addressable | 164.312(a)(2)(iv) |
| Mechanism to authenticate electronic protected health information | Addressable | 164.312(c)(2) |
| Integrity controls | Addressable | 164.312(e)(2)(i) |
| Encryption | Addressable | 164.312(e)(2)(ii) |
Two things the table does not show, and both of them catch people
First, six standards have no implementation specifications at all. There is nothing under them to label, so nothing appears above. They are not optional. They are the standard itself, and you must meet them: assigned security responsibility (45 CFR 164.308(a)(2)), evaluation (45 CFR 164.308(a)(8)), workstation use (45 CFR 164.310(b)), workstation security (45 CFR 164.310(c)), audit controls (45 CFR 164.312(b)), and person or entity authentication (45 CFR 164.312(d)). No specification does not mean no obligation.
Second, the table covers the three safeguard families. The Security Rule also carries specifications under organizational requirements (45 CFR 164.314) and under policies, procedures, and documentation (45 CFR 164.316). Every one of those is required. There is no addressable path in either.
The judgment is yours, and it is on the record
The rule is genuinely flexible about how you get there. You may use any security measures that let you meet the standards reasonably and appropriately (45 CFR 164.306(b)(1)), and in choosing, you must take into account your size, complexity, and capabilities; your technical infrastructure, hardware, and software security capabilities; the costs of the measures; and the probability and criticality of the potential risks to ePHI (45 CFR 164.306(b)(2)).
A twelve-person ABA clinic is not held to a hospital’s answer. It is held to a real answer.
And the answer has to exist in writing. Documentation required by the Security Rule must be kept in written or electronic form (45 CFR 164.316(b)(1)), retained for six years from creation or from the date it was last in effect, whichever is later (45 CFR 164.316(b)(2)(i)), and reviewed and updated as your operations change (45 CFR 164.316(b)(2)(iii)). Your security measures themselves must be reviewed and modified as needed to keep protection reasonable and appropriate (45 CFR 164.306(e)).
An addressable decision made in someone’s head, three years ago, that nobody wrote down, is indistinguishable from having never made the decision at all.
What this looks like in an ABA clinic
Encryption of ePHI at rest is addressable (45 CFR 164.312(a)(2)(iv)). So you assess it. If your RBTs carry tablets into family homes, encryption is cheap, it is built into the devices you already own, and the risk it mitigates is a device walking out of a living room. It is going to be reasonable and appropriate, and the honest conclusion is that you implement it.
“An addressable decision made in someone's head, three years ago, that nobody wrote down, is indistinguishable from having never made the decision at all.”
Automatic logoff is addressable (45 CFR 164.312(a)(2)(iii)). Same process, and the same likely answer, because the alternative is an unlocked session in a room with a family in it.
The point is not that addressable specifications always end in yes. The point is that they always end in a decision, and the decision is on the record.
What may change
In January 2025 HHS proposed the first substantial rewrite of the Security Rule in over two decades (90 FR 800, published January 6, 2025). Among many other changes, the proposal would eliminate the addressable category entirely and make every implementation specification required.
This is a proposal. It is not law. No final rule has been issued, the comment period closed in March 2025, and the federal regulatory agenda now shows final action pushed to July 2027. It may be finalized, narrowed, delayed again, or withdrawn.
What matters today is that OCR is enforcing the rule that exists. Under that rule, addressable still means assess, decide, document, and act. It has never meant ignore.
The short version
- Every Security Rule implementation specification is labelled required or addressable, and addressable has never meant optional.
- The addressable path is: assess it, then implement it, or document why not and implement an equivalent alternative. Doing nothing and writing nothing is not on the list.
- 14 specifications are required, 22 are addressable; the full table on this page maps every one.
- Six standards have no specifications at all; they are obligations in themselves.
- The 2025 proposed rule would eliminate the addressable category entirely, but it is a proposal, not law.
This article is educational information about the HIPAA regulations, not legal advice. It describes what the rules say; it does not tell you what to do about your specific situation, and reading it does not create an attorney-client or consultant-client relationship. Regulations change, and enforcement positions change with them. For advice on your clinic, talk to a qualified professional.
Sources
- Security standards: General rules45 CFR 164.306https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C/section-164.306
- Administrative safeguards45 CFR 164.308https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C/section-164.308
- Physical safeguards45 CFR 164.310https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C/section-164.310
- Technical safeguards45 CFR 164.312https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C/section-164.312
- Policies and procedures and documentation requirements45 CFR 164.316https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C/section-164.316
- HIPAA Security Rule to Strengthen the Cybersecurity of Electronic Protected Health Information (proposed rule, not in force)90 FR 800, January 6, 2025https://www.federalregister.gov/documents/2025/01/06/2024-30983/hipaa-security-rule-to-strengthen-the-cybersecurity-of-electronic-protected-health-information
Twenty-two decisions, and a record of each one.
Every addressable specification is a decision you are expected to have made, documented, and kept current. Most clinics have made none of them on paper. WiseUpHIPAA works out what applies to your clinic, holds the decisions and the evidence behind them, and shows you honestly where you actually stand, including the parts that are not done yet.