08/17/2026
“Addressable” does not mean “optional.”
That distinction is important under the HIPAA Security Rule today, and it could become even more significant under the proposed changes.
The current Security Rule allows healthcare organizations some risk-based flexibility when implementing certain “addressable” safeguards. But that flexibility comes with responsibility: organizations still need to evaluate the safeguard, make a reasonable and appropriate decision, and document it.
The proposed Security Rule would change that framework by eliminating the distinction between “required” and “addressable” implementation specifications and making most specifications mandatory, with limited exceptions.
In Article 2 of our HIPAA Security Readiness series, we break down:
✔ What “addressable” actually means today
✔ How the proposed rule would change the standard
✔ Why older security decisions deserve another look
✔ Four practical actions healthcare organizations can take now
The proposed rule isn't final. The current Security Rule is.
Read Article 2 and follow the complete 12-month series:
🔗 https://zurl.co/lZLNu
/* ========================================================= SOLID HIPAA SECURITY READINESS LANDING PAGE Brand colors: Burnt Orange: Black: #101820 Cool Gray: ========================================================= */ .solid-hipaa-page, .solid-hipaa-page * { box-sizing: border-box;...