Addressable Specifications
In the HIPAA Security Rule, an addressable specification is a safeguard that a covered entity or business associate must actively evaluate for its own situation rather than simply skip. Addressable does not mean optional; the organization must decide whether the measure is reasonable and appropriate for its environment, and if it is not, implement an equivalent alternative or document why no measure is needed. This flexibility exists because organizations vary in size, resources, and risk. Readers should note that proposed regulatory changes could alter or eliminate this category, so current regulatory text should be verified.
Under the HIPAA Security Rule, implementation specifications are classified as either 'required' or 'addressable.' An addressable implementation specification obligates a regulated entity to assess whether the specified safeguard is a reasonable and appropriate means of protecting electronic protected health information (ePHI) given its risk analysis, size, complexity, and capabilities. Based on that assessment, the entity must either (a) implement the specification as written, (b) implement a reasonable and appropriate equivalent alternative measure, or (c) if neither is reasonable and appropriate, document that determination and, where applicable, why no measure is needed. Each of these outcomes and the supporting rationale must generally be documented. Addressable status applies only to certain implementation specifications, not to the overarching standards themselves, which remain mandatory. This concept is specific to the Security Rule (ePHI) and does not extend to the Privacy Rule. Practitioners should be aware that proposed rulemaking has contemplated removing the addressable category and making all applicable specifications required; the classification of any given specification should be confirmed against the current version of the Security Rule at 45 CFR Part 164.
Why it matters
The addressable category is one of the most misunderstood concepts in the HIPAA Security Rule, and that misunderstanding creates real compliance risk. Because the word "addressable" sounds discretionary, some organizations wrongly treat these specifications as optional and skip them without analysis. In reality, an addressable specification still demands an active decision: the regulated entity must evaluate whether the safeguard is reasonable and appropriate for its environment and either implement it, adopt an equivalent alternative, or document why no measure is needed. Failing to perform and document that evaluation is itself a compliance gap that HHS OCR can identify during an investigation or audit, regardless of whether a breach occurred.
The distinction matters most when an organization must demonstrate the basis for its security decisions after the fact. A well-reasoned, documented determination tied to a current risk analysis is generally the difference between a defensible position and an apparent failure to address a required standard. Because addressable specifications sit beneath overarching standards that remain mandatory, choosing not to implement a specific safeguard never excuses the entity from meeting the underlying standard it supports.
The category is also in flux. Proposed rulemaking has contemplated eliminating the addressable classification entirely and making all applicable implementation specifications required. If that change is finalized, the flexibility described here would no longer apply, and organizations that have relied on documented alternatives may need to reassess their controls. Readers should confirm the current status of any specification and of the addressable category itself against the current version of the Security Rule rather than assuming today's framework will persist.
Who it's relevant to
Inside Addressable Specifications
Common questions
Answers to the questions practitioners most commonly ask about Addressable Specifications.