The HIPAA safeguards in the Security Rule are split into standards and implementation specifications, and the specifications are labelled either Required or Addressable.
“Addressable” is the most expensive word in HIPAA. It does not mean optional, and organisations that read it that way discover the difference during an investigation.
What addressable HIPAA safeguards oblige you to do

45 CFR 164.306(d)(3) sets out a two-step obligation. Where a specification is addressable, a covered entity or business associate must:
- Assess whether it is a reasonable and appropriate safeguard in its environment, analysed with reference to the likely contribution to protecting electronic protected health information; and
- implement it if reasonable and appropriate — or, if not, document why it would not be reasonable and appropriate and implement an equivalent alternative measure if reasonable and appropriate.
So the honest reading of the addressable HIPAA safeguards is: implement it, or do the work to justify not implementing it and put something else in its place. Skipping an addressable specification with no assessment and no alternative is not a permitted outcome — it is an undocumented gap.
Where the word Required appears, there is no assessment and no alternative. You implement it.
The HIPAA safeguards flexibility is real, and bounded
Section 164.306(b) does grant genuine latitude: entities may use any security measures that allow them to reasonably and appropriately implement the standards. In deciding which measures to use, they must take into account:
- size, complexity and capabilities;
- technical infrastructure, hardware and software security capabilities;
- the costs of security measures; and
- the probability and criticality of potential risks to ePHI.
Cost is explicitly a permitted factor, which surprises people — but it sits alongside criticality and probability, not above them. A cost argument for skipping a control protecting a high-probability, high-impact risk does not survive the same paragraph that permits it.
The eight administrative HIPAA safeguards
Section 164.308 sets eight standards: security management process; assigned security responsibility; workforce security; information access management; security awareness and training; security incident procedures; contingency plan; and evaluation.
Beneath them sit ten required and eleven addressable implementation specifications — which is the clearest single illustration of why the required/addressable distinction matters. More than half the administrative detail is addressable, and therefore needs assessment and documentation rather than a yes or no.
The one to start with is risk analysis, which is Required: conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity and availability of ePHI held by the entity.
Note what it says — accurate and thorough, and covering ePHI held by the entity. A risk analysis scoped to one system while ePHI sits in three is neither. This is the finding that appears most often in enforcement, because every other safeguard decision depends on it.
The four physical HIPAA safeguards
Section 164.310 is shorter and more often skipped: facility access controls; workstation use; workstation security; and device and media controls.
Facility access controls requires policies and procedures limiting physical access to electronic information systems and the facilities housing them, while ensuring that properly authorised access is allowed — the standard is not simply “lock it down”. Its specifications are addressable and cover contingency operations, a facility security plan, access control and validation procedures, and maintenance records.
These are the HIPAA safeguards most affected by how people actually work now. Workstation use and workstation security were written for desks, and apply just as much to a laptop in a home office. Device and media controls reach disposal and reuse — which is where old drives and decommissioned equipment become breaches long after anyone thought about them.
Two things people forget about HIPAA safeguards
Business associates are directly covered. The text of both sections applies to “a covered entity or business associate”. If you process ePHI on someone else’s behalf, these safeguards are your obligation, not a contractual courtesy.
Maintenance is a standing duty. Section 164.306(e) requires entities to review and modify security measures as needed to continue providing reasonable and appropriate protection, and to update the documentation accordingly. An assessment performed once, three years ago, does not describe your current environment.
How HIPAA safeguards connect
| Area | Connection |
|---|---|
| HIPAA risk assessment | The required risk analysis every other safeguard decision depends on |
| Business associate agreements | The contractual layer over obligations business associates hold directly |
| ISO 27001 | Maps substantially onto the administrative and physical safeguards, and supplies the review cycle 164.306(e) expects |
| HITRUST | A prescriptive route to demonstrating the same safeguards, where a customer asks for certification |
Where to start with HIPAA safeguards
- Do the risk analysis properly and across all ePHI, because it is Required and everything else references it.
- List every addressable specification and record a decision against each — implemented, or justified with an alternative.
- Write the “not reasonable and appropriate” reasoning down at the time, not retrospectively.
- Name the equivalent alternative measure wherever you decline a specification.
- Revisit the physical safeguards for remote working, especially workstation security and device disposal.
- Set a review cadence, since 164.306(e) makes maintenance a continuing obligation.
This guide reflects 45 CFR part 164 subpart C as published on the eCFR, read at 16 August 2026. Proposed changes to the Security Rule have been under consideration — confirm the current text before relying on a specification.
The HIPAA Toolkit provides 160+ editable templates covering the risk analysis, the administrative and physical safeguard policies, the addressable specification decision records and the evidence an investigation asks for.