Addressable Implementation Specification
Also known as: Addressable specification, Addressable requirement
An addressable implementation specification is a HIPAA Security Rule safeguard you must assess and implement when reasonable and appropriate, documenting any other choice.
An addressable implementation specification is a detailed rule in the HIPAA Security Rule that is marked "Addressable." It lets a covered entity or business associate decide if that exact measure fits its setting. It does not allow skipping the assessment or the standard it supports. HHS has long said these specifications are not optional.
Required versus addressable
Many Security Rule standards include implementation specifications. Under 45 CFR § 164.306(d)(1), each one is labeled required or addressable. A required one must be put in place. Risk analysis at § 164.308(a)(1)(ii)(A) is one example. Unique user identification at § 164.312(a)(2)(i) is another.
Some standards list no specifications. HHS said in the 2003 final rule that such a standard then acts as its own specification and is required. Audit controls at § 164.312(b) work this way.
How to assess an addressable implementation specification
Under 45 CFR § 164.306(d)(3), each addressable implementation specification calls for these steps:
- Assess. Decide if the measure is reasonable and appropriate in your setting. Weigh how much it would help protect ePHI.
- Implement it if it fits. If the answer is yes, you must use it.
- Document it if it does not. Write down why it does not fit. Then use an equivalent alternative measure if that is reasonable and appropriate.
The 2003 final rule also allows one narrow path. You may use neither the measure nor an alternative only if you can still meet the standard. You must then write down the choice, the reason, and how you meet the standard.
Your risk analysis should drive each choice. HHS named factors such as that analysis, your plan to reduce risk, the safeguards you already have, and cost. Cost counts, but HHS said it does not excuse an entity from adequate security. Our HIPAA risk analysis guide covers the nine elements OCR looks for.
Common addressable specifications
- Automatic logoff, § 164.312(a)(2)(iii), ends a session after a set idle time. HIPAA names no timeout length, as our guide to HIPAA automatic logoff requirements explains.
- Encryption and decryption, § 164.312(a)(2)(iv), falls under access control. A second encryption item, § 164.312(e)(2)(ii), falls under transmission security. See encryption at rest and in transit.
- Log-in monitoring, § 164.308(a)(5)(ii)(C), means watching log-in attempts and reporting anything odd. Rate limiting can help.
- Password management, § 164.308(a)(5)(ii)(D), covers how passwords are made, changed, and kept safe. Secrets management brings the same care to app logins.
Our guide to HIPAA's administrative, physical, and technical safeguards shows which specifications in each group are required or addressable.
A healthcare example
Imagine a clinic that keeps patient intake forms in its portal database. The team assesses encryption at rest. Its host offers database encryption at low added cost. The measure fits, so the clinic must turn it on. In its 2025 proposed rule, HHS wrote that encryption generally would be reasonable and appropriate for regulated entities.
Keep the decision on record
Under 45 CFR § 164.316(b)(1), an assessment the rule says to document needs a written record. It may be electronic. Keep it for six years from when it was created or last in effect, whichever is later, under § 164.316(b)(2)(i). Review it from time to time. Update it when changes affect ePHI security, under § 164.316(b)(2)(iii). For each addressable implementation specification, a useful record lists the factors weighed, the choice, and any alternative.
The proposed rule would drop the label
On January 6, 2025, HHS proposed a Security Rule update at 90 FR 898 (RIN 0945-AA22). It would end the split between required and addressable. All specifications would become required, with specific, limited exceptions. HHS wrote that, in OCR's enforcement work, "addressable" is misunderstood to be optional. This is a proposal, not law. As of October 9, 2026, the Federal Register shows no final rule. The Unified Agenda targets July 2027. Our new HIPAA Security Rule tracker follows its status.
Sources: 45 CFR § 164.306, § 164.308, § 164.312, and § 164.316 at law.cornell.edu; HHS FAQ on addressable and required specifications; the 2003 Security Rule final rule, 68 FR 8334; the Security Rule NPRM, 90 FR 898; and the Unified Agenda entry for RIN 0945-AA22.