Patient portals vs. email: Comparing security, costs and implementation
Patient portals were designed to provide patients with 24/7 access to their health information, appointment scheduling, prescription refills, and...
2 min read
Kirsten Peremore
August 28, 2024
Addressable and required implementations are two categories of security measures outlined in the Security Rule. Understanding the distinction between addressable and required implementations helps organizations focus on addressing the risks first.
HHS guidance provides that, “If an implementation specification is described as “required,” the specification must be implemented.” These measures are necessary for compliance with the Security Rule. Required implementations include:
The same HHS guidance states that “The concept of "addressable implementation specifications" was developed to provide covered entities additional flexibility with respect to compliance with the security standards.”
Organizations must evaluate whether implementing an addressable measure is reasonable and appropriate in their environment. If it is, they must implement it. If it is not, they must document the rationale for not implementing it and implement an equivalent alternative measure if reasonable and appropriate.
Addressable implementations include:
Related: What is the HIPAA Security Rule?
Related: Understanding and implementing HIPAA rules
The concept of "reasonable and appropriate" allows organizations to tailor their implementation approach based on their unique circumstances, capabilities, and risk profiles. It requires organizations to conduct a thorough risk analysis and consider factors such as cost, feasibility, industry standards, and best practices. The concept emphasizes a balanced and practical approach to implementing security measures.
Related: HIPAA Compliant Email: The Definitive Guide
The Health Insurance Portability and Accountability Act is designed to protect patient privacy.
It establishes the standards for the protection of ePHI.
Any PHI created, stored, transmitted or received electronically.
Patient portals were designed to provide patients with 24/7 access to their health information, appointment scheduling, prescription refills, and...
At our March Zoom social mixer, the conversation focused on new Paubox features, AI implementation strategies for HIPAA compliance, and practical...
Organizations often underestimate the resources, time, and organizational change required to successfully complete the HITRUST certification process....
Every Friday we bring you the most important news from Paubox. Our aim is to make you smarter, faster.