HIPAA Says Encryption Is “Addressable.” That Doesn’t Mean Optional.
Does “addressable” mean encryption is optional?
No. Addressable means you must implement the safeguard, implement an equivalent alternative, or document why neither is reasonable for your practice. There is no option that permits skipping it. Encryption is also the only safeguard carrying the breach-notification safe harbour, which makes it materially different from the other addressable items.
Somewhere in every HIPAA conversation, someone points out that encryption is listed as addressable rather than required, and the room relaxes slightly.
It shouldn’t. “Addressable” is one of the most misread words in the Security Rule, and the misreading is expensive.
What addressable actually means
The Security Rule splits safeguards into required and addressable. Required means you do it. Addressable means you assess whether it is reasonable and appropriate for your practice, and then do one of three things:
- Implement it, or
- Implement an equivalent alternative that achieves the same protection, or
- Document why neither is reasonable for your circumstances — and record what you do instead.
Notice what is absent from that list. There is no option that reads “decide it is optional and move on.” Every path ends in either a control or a written justification. The flexibility is in how you protect the data, not whether.
And the practical reality for a small practice is that encryption is cheap, built into the operating system you already own, and difficult to argue against. Explaining to an investigator why full-disk encryption was not reasonable on a laptop that leaves the building is not a comfortable conversation.
The reason it matters more than the other addressable items
Encryption has a status nothing else in the rule has: the breach notification safe harbour.
If PHI is encrypted to the standard HHS specifies and the keys were not compromised, the data is not considered “unsecured.” A lost laptop is then a lost laptop. Without encryption, the same laptop is a reportable breach — notification to every affected individual, notification to HHS, and if it crosses five hundred people, notification to the media.
That is the whole argument. One control, correctly applied, turns an incident into an inconvenience.
Where practices actually leave data unencrypted
In our experience it is rarely the server. It is the edges:
- Laptops that go home. BitLocker exists on Windows Pro and is not enabled by default. Check, don’t assume.
- USB sticks. Someone exports a report to take to a meeting.
- Email. Sending a chart to a referring physician in a plain message. Microsoft 365 can encrypt these, but it has to be configured.
- Backups. Often encrypted in transit, sometimes not at rest, and almost never verified by anyone.
- The old machine in the storeroom. Decommissioned, still has a drive in it, still has data on it.
Every one of those is fixable in an afternoon, and every one of them is the sort of thing that gets discovered after the fact rather than before.
What to do this week
- Find out which machines are encrypted. Not which should be — which are. On Windows, that is one command or one settings screen per device.
- Turn it on where it isn’t. On modern hardware the performance cost is effectively nil.
- Store the recovery keys somewhere you can actually find them. An encrypted drive whose key is lost is indistinguishable from a destroyed drive.
- Write down what you decided. If you concluded something is not reasonable for your practice, that documented decision is the compliance. Undocumented, it is just an omission.
If you would like someone to check which of your machines are actually encrypted rather than assumed to be, we can do that. It takes about twenty minutes and you get a straight answer either way.
General information about a regulation, not legal advice.




