Research · 12 min read
What a Required Safeguard Is, and What an Addressable One Is
The federal security standards for electronic health records mark each item either required or addressable, and there are more addressable ones than required ones. Addressable is not a synonym for optional, and encryption appears twice on the wrong side of that line.
Key takeaways
- Every implementation specification in the federal security standards is marked either required or addressable, and the marker is printed in parentheses after its title.
- Addressable is not optional: an organization must assess the item, then implement it, or document why it is not reasonable and appropriate and implement an equivalent alternative if one is.
- Across the administrative, physical and technical safeguard sections there are seventeen standards, thirteen required specifications and twenty-two addressable ones.
- Encryption appears twice in the technical safeguards section and both entries are addressable, one for stored information and one for information in transit.
- The required items include risk analysis, risk management, a sanction policy, an activity review, three contingency-planning items, incident response, disposal and media re-use.
- Six of the seventeen standards carry no implementation specifications at all, among them audit controls, person or entity authentication, and the periodic evaluation duty.
- All of it applies only to the categories the subpart's applicability sentence names, and only with respect to electronic protected health information of a covered entity.
Answer first: one word in parentheses decides how hard a duty is
The federal security standards for electronic health records are built as a list. Each entry on it carries a bracketed word, and the word is either required or addressable.
The regulation says so in plain terms. Implementation specifications are required or addressable, and if one is required the word appears in parentheses after its title, while an addressable one is marked the same way with the other word.
People read addressable as optional. The regulation does not, and the difference is the most useful thing on this page.
Before any of it applies there is a threshold. The subpart's applicability section says a covered entity or business associate must comply with the applicable standards, implementation specifications, and requirements of the subpart with respect to electronic protected health information of a covered entity.
Required means what it sounds like
When a standard includes required implementation specifications, a covered entity or business associate must implement them.
There is no assessment step and no alternative route. The item is on the list, and the duty is to do it.
That is the whole of the required branch, which is why so much of the interesting reading is in the other one.
Addressable is a three-step obligation, not a permission
Where a standard includes addressable implementation specifications, the regulation sets out what an organization must do, and it is a sequence rather than a choice.
First, assess whether each implementation specification is a reasonable and appropriate safeguard in its environment, when analyzed with reference to the likely contribution to protecting electronic protected health information.
Then, as applicable, implement the specification if it is reasonable and appropriate.
If implementing it is not reasonable and appropriate, two things follow together. Document why it would not be reasonable and appropriate to implement it. And implement an equivalent alternative measure if that is reasonable and appropriate.
So the addressable route ends in one of three places: the specification is implemented, or an equivalent alternative is, or a written explanation exists for why neither was suitable. Doing nothing quietly is not among them.
⚖ It is still a judgment made by the organization about itself, and the document that records it is internal. The obligation is real and the output is not published.
How the list actually splits
Counting the markers across the three safeguard sections is worth doing, because the balance is not what most summaries suggest.
Across the administrative safeguards paragraph, the physical safeguards section and the technical safeguards section there are seventeen standards.
Those seventeen carry thirteen required implementation specifications and twenty-two addressable ones.
The addressable items outnumber the required ones by a wide margin. That is a count of those three sections rather than a claim about federal law generally, and it is the shape of the rulebook a reader is trying to judge a company against.
The administrative half, and what is required in it
The administrative safeguards paragraph is the longest of the three and carries eight standards.
Four required items sit under the first one, a security management process meant to prevent, detect, contain and correct security violations. A risk analysis. A risk management step. A sanction policy applied to workforce members who fail to follow the security policies. And an information system activity review, described as regularly reviewing records such as audit logs, access reports and security incident tracking reports.
A second standard requires the organization to identify the security official responsible for developing and implementing the policies and procedures the subpart requires. That is a named person rather than a document.
Three more required items sit under contingency planning: a data backup plan, a disaster recovery plan and an emergency mode operation plan. The standard above them is written for an emergency or other occurrence that damages systems holding the information, and it gives its own examples — fire, vandalism, system failure and natural disaster.
Security incident procedures carry one required item, response and reporting. It asks the organization to identify and respond to suspected or known incidents, mitigate their harmful effects to the extent practicable, and document the incidents and their outcomes.
⭐ And the ones people assume are mandatory frequently are not. Workforce clearance, termination procedures, access authorization, security reminders, protection from malicious software, log-in monitoring and password management are all marked addressable.
The physical half, and the two required items in it
The physical safeguards section runs to four standards and is written about buildings, equipment and hardware rather than about software.
Its facility access controls standard carries four items and every one is addressable. They are contingency operations, a facility security plan, access control and validation procedures, and maintenance records documenting repairs and modifications to physical components related to security.
Two standards govern workstations. One is about the proper functions to be performed and the physical attributes of the surroundings; the other asks for physical safeguards restricting workstation access to authorized users.
The two required items in this section are both about the end of a record's life rather than its use. Disposal asks for policies and procedures addressing the final disposition of the information and of the hardware or electronic media holding it. Media re-use asks for procedures removing the information from electronic media before those media are made available for re-use.
That is a quiet but genuine consumer point. What happens to a decommissioned drive is a required item, while who is allowed to walk into the room is an addressable one.
The technical half, and where encryption actually sits
The technical safeguards section is the shortest of the three and carries five standards.
Two required items sit under access control. Unique user identification asks for a unique name or number identifying and tracking user identity. An emergency access procedure asks for a way of obtaining necessary information during an emergency.
Three standards in this section carry no implementation specifications at all, and they are stated as bare duties. Audit controls asks for hardware, software or procedural mechanisms that record and examine activity in systems containing or using the information. Person or entity authentication asks for procedures verifying that whoever seeks access is the one claimed.
⭐⭐ Encryption appears twice in this section, and both times it is marked addressable. Under access control, encryption and decryption asks for a mechanism to encrypt and decrypt the information. Under transmission security, encryption asks for a mechanism to encrypt the information whenever deemed appropriate.
Automatic logoff, which terminates a session after a predetermined time of inactivity, is addressable too. So is the mechanism to corroborate that the information has not been altered or destroyed in an unauthorized manner.
None of that means encryption carries no weight. The notification duties in the neighboring subpart run only to information that is unsecured, and a companion article explains what that word does. The point here is narrower and it is about this rulebook: on the face of these standards, encryption is on the assess-document-or-substitute branch rather than the must-do one.
Six standards carry no implementation specification at all
Reading the three sections against each other turns up a third category that neither of the two bracketed words describes.
Six of the seventeen standards have no implementation specifications underneath them. Assigned security responsibility and evaluation in the administrative paragraph. Workstation use and workstation security in the physical section. Audit controls and person or entity authentication in the technical one.
Those are duties stated once, in a sentence, with nothing below them to grade. The evaluation standard is the broadest of them: a periodic technical and nontechnical evaluation establishing the extent to which an organization's security policies and procedures meet the subpart's requirements.
It is worth noticing which duties are written that way. Two of the six are about knowing who is at a keyboard and whether anyone checked the logs.
What a reader can actually look at
Whether a document names a security official or a privacy contact, since one of these standards asks for a person to be identified rather than for a policy to exist.
Whether the language describes assessment and review, since the addressable branch and the evaluation standard both turn on work that recurs rather than on a one-time build.
Whether a company claiming encryption says what it encrypts. The two encryption items in the technical section cover stored information and transmitted information separately, and a claim about one is not a claim about the other.
Whether the entity named in a privacy document is the entity that holds the medical record, since the applicability sentence attaches to organizations rather than to brands.
And whether security language is being used where sharing language belongs. The security standards describe protection from unauthorized access; they say nothing about disclosures a company makes deliberately.
What this does not decide
It does not say whether any particular company is inside the category the applicability sentence names. That is a legal conclusion about a specific business.
It does not say that any company has implemented, or failed to implement, any specification. No such claim is made and none is implied.
It does not say that an addressable item is safe to skip. The regulation's own branch ends in implementation, an equivalent alternative, or a written explanation.
It does not describe the breach subpart's definitions or duties, which companion articles cover, and it describes no state statute.
And it is not legal advice. It reports what four sections of one federal subpart say, and counts the markers printed in three of them.
Sources
- 45 CFR 164.306, "Security standards: General rules"Paragraph (d)(1), stating that implementation specifications are required or addressable and that the applicable word appears in parentheses after the title of the specification. Paragraph (d)(2), requiring implementation where a standard includes required specifications. Paragraph (d)(3), the addressable sequence: assess whether each specification is a reasonable and appropriate safeguard in its environment when analyzed with reference to the likely contribution to protecting electronic protected health information; implement it if reasonable and appropriate; or, if not, document why it would not be reasonable and appropriate and implement an equivalent alternative measure if reasonable and appropriate. Paragraph (c), naming the sections whose standards must be complied with. ⚠ Paragraph (a)'s general requirements and paragraph (b)'s flexibility factors are the spine of a companion article and are not described here.
- 45 CFR 164.308, "Administrative safeguards"Paragraph (a) only, and specifically its eight standards and their markers. The security management process standard and its four required specifications: risk analysis, risk management, sanction policy applied to workforce members who fail to comply with the security policies and procedures, and information system activity review described as regularly reviewing records of information system activity such as audit logs, access reports and security incident tracking reports. The assigned security responsibility standard, requiring identification of the security official responsible for the development and implementation of the policies and procedures the subpart requires, and carrying no implementation specifications. The addressable specifications under workforce security, information access management and security awareness and training, including authorization and supervision, workforce clearance, termination procedures, access authorization, access establishment and modification, security reminders, protection from malicious software, log-in monitoring and password management. The security incident procedures standard and its required response and reporting specification. The contingency plan standard, its stated examples of fire, vandalism, system failure and natural disaster, and its three required specifications: data backup plan, disaster recovery plan and emergency mode operation plan. The evaluation standard, requiring a periodic technical and nontechnical evaluation establishing the extent to which the organization's security policies and procedures meet the subpart's requirements, and carrying no implementation specifications. ⚠ Paragraph (b), the business associate provisions, is the spine of a companion article and is not described here.
- 45 CFR 164.310, "Physical safeguards"The four standards and their markers. Facility access controls and its four addressable specifications: contingency operations, facility security plan, access control and validation procedures, and maintenance records documenting repairs and modifications to the physical components of a facility related to security. The workstation use standard, covering the proper functions to be performed, the manner of performance and the physical attributes of the surroundings, and the workstation security standard requiring physical safeguards restricting access to authorized users, neither of which carries implementation specifications. Device and media controls and its two required specifications, disposal addressing the final disposition of the information and of the hardware or electronic media on which it is stored, and media re-use requiring removal of the information from electronic media before they are made available for re-use, together with its two addressable specifications, accountability and data backup and storage.
- 45 CFR 164.312, "Technical safeguards"The five standards and their markers. Access control and its two required specifications, unique user identification assigning a unique name or number for identifying and tracking user identity, and an emergency access procedure for obtaining necessary electronic protected health information during an emergency; and its two addressable ones, automatic logoff terminating an electronic session after a predetermined time of inactivity, and encryption and decryption requiring a mechanism to encrypt and decrypt the information. The audit controls standard, requiring hardware, software or procedural mechanisms that record and examine activity in information systems containing or using the information, and carrying no implementation specifications. The integrity standard and its addressable specification, a mechanism to corroborate that the information has not been altered or destroyed in an unauthorized manner. The person or entity authentication standard, requiring procedures to verify that a person or entity seeking access is the one claimed, and carrying no implementation specifications. The transmission security standard and its two addressable specifications, integrity controls and encryption, the latter requiring a mechanism to encrypt the information whenever deemed appropriate.
- 45 CFR 164.302, "Applicability"The whole of the section, quoted in the body and again in an FAQ: a covered entity or business associate must comply with the applicable standards, implementation specifications, and requirements of this subpart with respect to electronic protected health information of a covered entity. It is the only sentence in the subpart that states who carries the duty, and its closing words limit that duty by whose information is involved.
Frequently asked questions
Does addressable mean optional?
No, and the regulation spells out the alternative. Where a standard includes addressable implementation specifications, an organization must assess whether each one is a reasonable and appropriate safeguard in its environment, analyzed with reference to the likely contribution to protecting the information. It must then implement the specification if that is reasonable and appropriate. If it is not, the organization must document why, and implement an equivalent alternative measure if that is reasonable and appropriate. Three endings are available. Silently skipping the item is not one of them.
Is encryption required?
Encryption appears twice in the technical safeguards section, and both entries are marked addressable rather than required. One sits under access control and asks for a mechanism to encrypt and decrypt the information. The other sits under transmission security and asks for a mechanism to encrypt it whenever deemed appropriate. Being addressable still triggers the assess, implement, or document-and-substitute sequence. And the word carries weight elsewhere: the notification duties in the neighboring subpart run only to unsecured information, which a companion article covers.
How many of these items are actually mandatory?
Across the administrative safeguards paragraph, the physical safeguards section and the technical safeguards section there are seventeen standards, carrying thirteen required implementation specifications and twenty-two addressable ones. That is a count of those three sections and nothing wider. The required items cluster in a few places. Under security management there are risk analysis, risk management, a sanction policy and an activity review. The rest are three contingency-planning items, incident response and reporting, disposal and media re-use, and unique user identification and emergency access.
Does the rule require a company to have a named person in charge of security?
One of the administrative standards asks for exactly that. It requires the organization to identify the security official who is responsible for the development and implementation of the policies and procedures the subpart requires. It carries no implementation specifications underneath it, so it is a single duty stated in a sentence. Whether any given company has done so, and whether that company is inside the category the subpart binds, are separate questions, and neither is settled here.
What happens to old hard drives and devices?
That is one of the two required items in the physical safeguards section, which is notable given how much else there is addressable. Disposal asks for policies and procedures addressing the final disposition of the information and of the hardware or electronic media on which it is stored. Media re-use asks for procedures removing the information from electronic media before those media are made available for re-use. Two further items in the same standard, accountability for the movement of hardware and a backup copy before equipment is moved, are addressable.
Does this rule reach every company that holds my medical information?
It does not, and the subpart's applicability section is the shortest place to see it. That section states that a covered entity or business associate must comply with the applicable standards, implementation specifications, and requirements of the subpart with respect to electronic protected health information of a covered entity. The duty attaches to named categories of organization, and it runs to one kind of information rather than to everything a company holds. Which category a given business falls into is a legal question about that business.