What does 'addressable' actually mean in the HIPAA Security Rule?

In the HIPAA Security Rule, "addressable" means a covered entity or business associate must assess whether an implementation specification is reasonable and appropriate for its environment. If not, the entity must document why it is not, and implement an equivalent alternative measure if reasonable and appropriate, or document why no alternative is reasonable and appropriate. This requires a thorough risk analysis and documented decision-making, ensuring the security of electronic protected health information (ePHI).

For practitioners, "addressable" specifications are not optional; rather, they mandate a structured decision-making process. Organisations must conduct a comprehensive risk analysis to determine if the specified safeguard is a reasonable and appropriate control for their specific circumstances, considering factors such as the entity's size, complexity, technical infrastructure, and the costs of implementation. This assessment should guide whether to implement the specification as written, implement an equivalent alternative, or determine that no alternative is reasonable and appropriate to protect electronic protected health information (ePHI).

A common pitfall is treating addressable specifications as merely suggestions, leading to non-compliance. The critical element is the robust documentation of the decision-making process. This documentation must clearly articulate the rationale for any decision not to implement an addressable specification directly, including the results of the risk analysis, the evaluation of technical feasibility, and the justification for adopting an alternative or for deeming no alternative necessary or appropriate. Failure to maintain such evidence can result in findings during an audit or investigation by the Department of Health and Human Services (HHS).

Sources

  • 45 CFR § 164.306(b)(2)(iv) - Implementation specifications
  • 45 CFR § 164.306(b)(2)(v) - Implementation specifications

Related