
One common misconception about the HIPAA Security Rule is that an “addressable” safeguard is optional. That is not the case.
Under the current Security Rule, when an implementation specification is designated as addressable, an organization must determine whether that safeguard is reasonable and appropriate for its environment. If it is not, the organization must document why and, when reasonable and appropriate, implement an equivalent alternative measure.
The proposed HIPAA Security Rule changes could significantly reduce that flexibility. HHS has proposed eliminating the distinction between “required” and “addressable” implementation specifications, making the specifications required with limited exceptions.
Why Is HHS Proposing This Change?
During the recent NIST/HHS Safeguarding Health Information: Building Assurance Through HIPAA Security conference, one of the points discussed was that the Security Rule was originally designed with flexibility so organizations could adapt as technology evolved.
Technology has certainly evolved. Many safeguards that may have once been difficult, costly, or impractical to implement are now considered fundamental security practices.
Encryption is a good example.
Years ago, encryption could be expensive or difficult to implement, particularly for a small healthcare organization. Depending on the organization’s circumstances, there may have been other reasonable and appropriate ways to protect electronic protected health information (ePHI).
Today, encryption is widely available and often built directly into the technology healthcare organizations already use. What may have once required additional technology and resources has increasingly become a baseline safeguard for protecting sensitive information.
The same evolution is happening across other areas of cybersecurity. As technology becomes more accessible and threats become more sophisticated, expectations for protecting ePHI are changing with them.
What Does This Mean for Your Organization?
The proposed HIPAA Security Rule has not been finalized, so the current Security Rule requirements remain in effect.
However, healthcare organizations do not have to wait for a final rule to start preparing.
Now is a good time to review the safeguards your organization currently treats as addressable. Understand which safeguards have been implemented, where alternative measures are being used, and whether those decisions still make sense based on today’s technology and cybersecurity risks.
This review can also help identify areas that may require additional planning, budgeting, or support from your IT team or managed service provider.
Even if the final rule differs from the current proposal, evaluating these safeguards today can help strengthen the protection of ePHI and put your organization in a better position to adapt as HIPAA requirements evolve.
Preparing now means having more time to make thoughtful decisions instead of waiting until a compliance deadline is approaching.

Leave a Reply