Skip to content

Addressable Implementation Specification

Definition

A HIPAA Security Rule specification that organisations must assess for reasonableness and appropriateness. If reasonable and appropriate, it must be implemented; if not, the organisation must document the rationale and implement an equivalent alternative. Addressable is not synonymous with optional.

Framework
HIPAA Security Rule
Requirement
Assess reasonableness and appropriateness
If reasonable
Must be implemented
If not
Document rationale, implement an equivalent alternative
Common misconception
Not synonymous with optional

Common questions

What is the difference between an addressable and a required specification under HIPAA?+

A required specification must be implemented exactly as written with no alternative, while an addressable specification allows the organisation to implement an equivalent alternative control, provided it documents why the standard approach was not reasonable or appropriate for its environment.

What happens if an organisation simply skips an addressable specification without documentation?+

That is a compliance failure; addressable status requires a documented risk-based decision, and skipping the specification with no assessment or rationale on file leaves the organisation unable to demonstrate compliance during an audit.

Related terms

Business Associate
A person or entity that performs services for a HIPAA covered entity that involve creating, receiving, maintaining, or transmitting protected health information...
Cardholder Data Environment (CDE)
The people, processes, and technology that store, process, or transmit cardholder data or sensitive authentication data. PCI-DSS requirements apply to the CDE...
Covered Entity
Under HIPAA, a healthcare provider that transmits health information electronically, a health plan, or a healthcare clearinghouse. Covered entities are directly subject...
Protected Health Information (PHI)
Individually identifiable health information held or transmitted by a covered entity or its business associate, in any form or medium. PHI includes...
Qualified Security Assessor (QSA)
An individual certified by the PCI Security Standards Council to perform on-site PCI-DSS assessments for merchants and service providers that cannot self-certify....

Explained in

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.