top of page
Search

The End of "Addressable": Why the 2025 HIPAA Security Rule Turns Compliance Into an Engineering Discipline

For more than two decades, the HIPAA Security Rule gave healthcare organizations a quiet escape hatch. It was called "addressable." If a safeguard was labeled addressable rather than required, an organization could implement it, implement an equivalent alternative, or document why it was not reasonable and appropriate and move on. In practice, that flexibility became a loophole. Encryption was addressable. Multi-factor authentication lived in the gray space. Entire security programs were built on a foundation of defensible paperwork rather than deployed controls. That era is ending.


The HHS Office for Civil Rights published its Notice of Proposed Rulemaking to overhaul the Security Rule on January 6, 2025. The comment period closed on March 7 after more than 4,000 stakeholders weighed in. OCR is targeting finalization for mid-2026, followed by a 60-day effective period and a 180-day compliance window. That is roughly 240 days from publication to the day auditors expect your controls to be real, deployed, and evidenced. The single most consequential change in the entire proposal is deceptively simple: the distinction between "required" and "addressable" goes away. Everything becomes required.


I want to be direct about what that means, because I have spent my career on both sides of this exact problem.



Why This Is Not Just Another Regulatory Update


Healthcare has absorbed a lot of regulatory change. The 21st Century Cures Act, information blocking rules, price transparency requirements, the shift to value-based care. Compliance teams are fatigued, and the natural instinct is to file the Security Rule NPRM in the same bucket as everything else and wait for the final version. That instinct is a mistake, and here is why.


Every prior wave of HIPAA activity could be satisfied, at least defensively, with documentation. A risk analysis on file. A policy binder. A signed Business Associate Agreement. The proposed Security Rule breaks that pattern. It does not ask whether you have a policy about encryption. It requires encryption of electronic protected health information at rest and in transit. It does not ask whether you considered multi-factor authentication. It requires MFA across access points to ePHI. It requires a written asset inventory and a network map of every system that touches ePHI, refreshed regularly. It requires vulnerability scanning every six months, penetration testing every year, and disaster recovery capability that can restore critical systems within 72 hours. And it requires a formal audit of your compliance, every twelve months.


Read that list again through the eyes of an auditor. Not one of those requirements is satisfied by a document. Every one of them requires an artifact that proves the control is operating: a configuration, a scan report, a test result, a restoration log. The Security Rule is being rewritten from a documentation standard into an engineering and evidence standard. Compliance stops being something you describe and becomes something you have to demonstrate.



I Have Built These Programs, and I Have Audited Them


I do not write this as an observer. During my years as CISO and CIO at the National Committee for Quality Assurance, I designed and operated a certified ISO/IEC 27001 information security management program that passed external surveillance audits for more than a decade with zero non-conformities. Building a program that survives that kind of sustained scrutiny teaches you something that no policy template can: the gap between a control that exists on paper and a control that produces evidence under examination is enormous, and it is exactly where organizations fail.


I also spent time on the other side of the table. As a HITRUST evaluator working with DirectTrust and EHNAC, I assessed healthcare organizations' security programs against rigorous control frameworks. I have reviewed the evidence packages. I have seen the difference between an organization that can produce a clean, timestamped artifact for every control and one that scrambles to reconstruct proof after the fact. The proposed Security Rule is going to force every covered entity and business associate into that assessment posture, whether they are ready or not.


That work is grounded in the discipline behind the credentials I hold, the CISSP and the CISM, but credentials are the floor, not the differentiator. The differentiator is what my team and I do repeatedly: at MTC Group we have taken multiple healthcare organizations through initial SOC 2 Type 1 and Type 2 examinations and carried several through repeat Type 2 renewals. That is the point most compliance conversations miss. Passing an examination once is an event. Sustaining a program that passes year after year is a discipline, and it is the same discipline the new HIPAA Security Rule is about to demand. Having built programs that withstand audits, conducted the audits themselves, and run the recurring examination cycle for real organizations is the lens I bring to this rule. And it tells me that most healthcare organizations are not two years away from readiness. They are two to three years behind, and the clock has already started.




Healthcare information security

The Core Problem Most Organizations Have Not Confronted


The organizations most exposed by this change are not the ones with no security program. They are the ones with a mature-looking program built on the addressable escape hatch. These are organizations with thick policy binders, annual risk assessments, and a compliance officer who can speak fluently about the Security Rule. On paper, they look ready. Underneath, encryption is partial, MFA has carve-outs for legacy systems, the asset inventory lives in a spreadsheet that was last accurate two reorganizations ago, and no one has run a penetration test in three years because it was never strictly required.


When "addressable" disappears, those carve-outs become findings. The spreadsheet becomes a gap. The three-year-old pen test becomes a compliance failure. And under the enforcement posture OCR has signaled, findings like these are no longer background risk. They are the specific deficiencies that turn a breach investigation into a willful neglect determination, with civil monetary penalties that scale accordingly.


The strategic error is treating this as a documentation refresh that legal and compliance can handle. It is not. It is an operational transformation that requires security engineering, evidence automation, and program governance working together. The organizations that recognize that now will spend the next 240 days building. The ones that do not will spend them explaining.



What Leaders Should Do First


The first move is not to wait for the final rule. The core requirements, mandatory encryption, MFA, asset inventory, continuous testing, and annual audit, are not controversial and are not going to be negotiated away. Building toward them now carries no downside even if specifics shift, and waiting carries enormous downside if they do not.


Second, commission an honest gap assessment measured against the proposed requirements, not against your current policy set. The question is not whether your policies are compliant. It is whether, for each mandated control, you could produce the evidence an auditor will demand tomorrow. Most organizations have never asked the question that way, and the answer reshapes every security investment decision that follows.


Third, treat this as a board-level program with a named owner and a real timeline, not a compliance task added to an already overloaded team. The 240-day path from finalization to enforcement is not a lot of runway for the depth of change this rule requires.



The Bottom Line


The end of "addressable" is the most important shift in HIPAA security in twenty years, because it changes what compliance fundamentally is. It stops being a story you tell and becomes a system you have to prove. The organizations that thrive under the new rule will be the ones whose leadership understood the difference early and built accordingly.


At MTC Group, this is precisely the work we do: helping healthcare organizations build HIPAA security programs that are engineered to produce evidence and defensible under real audit conditions, drawing on direct experience both building certified programs and evaluating them from the assessor's chair. If you cannot say with confidence today that every mandated control in the proposed rule would survive an auditor's examination, that is the conversation worth having now, while there is still time to build rather than explain.


You do not have to start with a paid engagement to find out where you stand. My free "Big Rocks" Information Security Risk Assessment, also linked from the MTC Group homepage, is a 10-question, five-minute survey that surfaces the highest-impact risk areas the proposed rule puts squarely in scope, so you can see your biggest gaps before an auditor does. It costs nothing. To go deeper with a formal gap assessment against the proposed HIPAA Security Rule, reach out at rick@mtcgroupllc.com.




Sources & Further Reading


  1. HIPAA Security Rule NPRM overview, U.S. Department of Health & Human Services, Office for Civil Rights

  1. HIPAA Security Rule, HHS Office for Civil Rights

  1. ISO/IEC 27001 Information Security Management, International Organization for Standardization

 
 
 

Comments


bottom of page