
The HIPAA Security Rule Is Changing: What "Addressable" Going Away Means for You
For more than a decade, one word has quietly shaped how healthcare organizations approach HIPAA security: "addressable."
That word may be on its way out — and if it goes, the way you justify your security decisions goes with it. Here's what's actually being proposed, what it would change, and why the smartest move is to prepare now even though nothing is final yet.
What's on the table
In late December 2024, the HHS Office for Civil Rights (OCR) proposed the first major overhaul of the HIPAA Security Rule since 2013. The Notice of Proposed Rulemaking was published in the Federal Register in early January 2025, and it represents the most significant rewrite of ePHI protection requirements in roughly twenty years.
The single biggest structural change: the proposal would eliminate the distinction between "required" and "addressable" implementation specifications. Under the proposed rule, nearly all specifications would become firm requirements, with only limited, narrowly defined exceptions that must be justified and documented.
To be clear about the status, because it matters: this is a proposed rule, not a final one. OCR received nearly 5,000 public comments, much of it substantial pushback from healthcare organizations over cost and timeline. Final action has already slipped past its original target, and there is no confirmed date for if or when a final rule will issue. It could be finalized, modified, delayed further, or withdrawn.
So why write about it now? Because the direction is clear, the underlying controls are already where the threat environment and OCR enforcement are heading, and the preparation work is valuable no matter what the final rule looks like.
Why "addressable" mattered so much
Here's the part many organizations misunderstand — and it's worth getting right.
"Addressable" never meant "optional." Under the current rule, an addressable specification means you must either implement it, adopt an equivalent alternative, or document why neither is reasonable and appropriate for your environment. It was designed to give smaller or differently-resourced organizations flexibility in how they met a requirement.
In practice, though, many organizations treated "addressable" as a door to skip controls entirely — documenting their way around encryption, MFA, and similar safeguards. OCR has openly acknowledged that addressable specifications have been widely treated as optional in the real world.
The proposed rule closes that door. Size and operating context would still shape how you implement a control — but no longer whether it applies to you.
The controls that would become mandatory
Under the proposal, a set of safeguards that are currently addressable or have simply been industry best practice would become explicit requirements, including:
Multi-factor authentication for access to ePHI, with limited exceptions. This moves MFA from a risk-based decision to a baseline requirement across clinical systems, EHRs, remote access, email, and administrative platforms.
Encryption of ePHI at rest and in transit, with limited, documented exceptions. This closes one of the most consequential gaps in the current framework and reaches servers, databases, laptops, portable devices, backups, email, and cloud storage.
Vulnerability scanning at least every six months and penetration testing at least every twelve months — moving security testing from an occasional exercise to a defined cadence.
Network segmentation, a technology asset inventory, and a network map showing how ePHI actually flows through your environment.
Expanded documentation and business associate obligations — including tighter verification requirements that make business associates more directly accountable for their own compliance.
One clarification worth making, because it's a common misconception: the proposal does not create a 72-hour breach-notification deadline. The existing 60-day Breach Notification Rule is unchanged. What the proposal adds is a 72-hour data-restoration requirement for critical systems and a 24-hour contingency-plan notification — related to operational resilience, not breach reporting.
Why waiting for "final" is the wrong strategy
It's tempting to file this under "watch and see." That's understandable, given the uncertainty. But there are three reasons preparing now is the smarter play.
The controls aren't really new. MFA, encryption, segmentation, vulnerability scanning — these are already where OCR enforcement, cyber insurers, and modern threat realities point. Most auditors already expect to see them. The proposal codifies what leading organizations do anyway.
The compliance window is short. When the rule is finalized, organizations are expected to have roughly 180 days to comply. Building an asset inventory, mapping your network, deploying MFA everywhere, and closing encryption gaps across an entire environment is not a six-month job if you start from zero. The organizations that begin now will be ready; the ones that wait will scramble.
The work is valuable regardless of the outcome. A documented risk analysis, an accurate asset inventory, an MFA and encryption map — these strengthen your security posture and your current HIPAA compliance today, whether or not the proposed rule passes as written. There is no version of the future where this work is wasted.
What to do now
The practical starting point is a gap assessment against the proposed rule. Identify every place you've relied on an "addressable" determination to defer a control — that list is your roadmap. From there:
- Map where ePHI actually lives and moves (asset inventory and network map)
- Assess your encryption coverage at rest and in transit, and close the gaps
- Deploy MFA everywhere ePHI is accessed
- Establish vulnerability scanning and penetration testing cadences
- Audit and update your business associate agreements
- Document everything — decisions, analyses, and procedures
The bottom line
The proposed HIPAA Security Rule update would be the most significant change to how healthcare organizations protect ePHI in twenty years. It isn't final, and it may change. But the direction is unmistakable: the era of documenting your way around a control is ending, and the baseline for "reasonable" security is rising to meet the threats healthcare actually faces.
The organizations that treat this as a prompt to get their programs genuinely in order — rather than waiting for a deadline to force the issue — will be the ones standing on solid ground when the rule lands.
At Privaxi, this is the work we do: not handing you a report and walking away, but assessing where your program actually stands, engineering the controls, proving they work, and keeping you ready as the requirements evolve. If the coming changes have you wondering where your organization really stands, that's a conversation worth having now.
Related Articles
Secure Your Business's Future
Contact us today for a personalized consultation and see how we can tailor a security solution that fits your business needs perfectly.



