addressable
Term · Cybersecurity · MLC-T-CYB-000090
1. To meet the addressable implementation specifications, a covered entity or business associate must (i) assess whether each implementation specification is a reasonable and appropriate safeguard in its environment, when analyzed with reference to the likely contribution to protecting the electronic protected health information; and (ii) as applicable to the covered entity or business associate - (A) Implement the implementation specification if reasonable and appropriate; or (B) if implementing the implementation specification is not reasonable and appropriate - (1) document why it would not be reasonable and appropriate to implement the implementation specification; and (2) implement an equivalent alternative measure if reasonable and appropriate.
2. Describing 21 of the HIPAA Security Rule’s 42 implementation specifications. To meet the addressable implementation specifications, a covered entity must (i) assess whether each implementation specification is a reasonable and appropriate safeguard in its environment, when analyzed with reference to the likely contribution to protecting the entity's electronic protected health information; and (ii) as applicable to the entity - (A) Implement the implementation specification if reasonable and appropriate; or (B) if implementing the implementation specification is not reasonable and appropriate - (1) document why it would not be reasonable and appropriate to implement the implementation specification; and (2) implement an equivalent alternative measure if reasonable and appropriate.
| Identifier | MLC-T-CYB-000090 |
|---|---|
| Field | Cybersecurity |
| References | NIST SP 800-66r2 from HIPAA Security Rule (§164.306(d)(3)); NIST SP 800-66 Rev. 1 [Superseded] from 45 C.F.R., Sec. 164.306(d)(3); NIST CSRC Glossary |
| See also | required |
Record as JSON
{
"id": "MLC-T-CYB-000090",
"term": "addressable",
"field": "Cybersecurity",
"definition": "1. To meet the addressable implementation specifications, a covered entity or business associate must (i) assess whether each implementation specification is a reasonable and appropriate safeguard in its environment, when analyzed with reference to the likely contribution to protecting the electronic protected health information; and (ii) as applicable to the covered entity or business associate - (A) Implement the implementation specification if reasonable and appropriate; or (B) if implementing the implementation specification is not reasonable and appropriate - (1) document why it would not be reasonable and appropriate to implement the implementation specification; and (2) implement an equivalent alternative measure if reasonable and appropriate.\n\n2. Describing 21 of the HIPAA Security Rule’s 42 implementation specifications. To meet the addressable implementation specifications, a covered entity must (i) assess whether each implementation specification is a reasonable and appropriate safeguard in its environment, when analyzed with reference to the likely contribution to protecting the entity's electronic protected health information; and (ii) as applicable to the entity - (A) Implement the implementation specification if reasonable and appropriate; or (B) if implementing the implementation specification is not reasonable and appropriate - (1) document why it would not be reasonable and appropriate to implement the implementation specification; and (2) implement an equivalent alternative measure if reasonable and appropriate.",
"see_also": [
"required"
],
"references": [
"NIST SP 800-66r2 from HIPAA Security Rule (§164.306(d)(3))",
"NIST SP 800-66 Rev. 1 [Superseded] from 45 C.F.R., Sec. 164.306(d)(3)",
"NIST CSRC Glossary"
],
"url": "https://mlchart.com/terminology/cybersecurity/addressable/"
}
Record 90 of 4,693 in Cybersecurity terminology (MLC-0102). Request the full dataset.