The End of “Addressable” Safeguards? Training Staff for the Proposed HIPAA Security Rule

Categories: Compliance News & Regulatory Updates, HIPAA Privacy & SecurityPublished On: July 20th, 202611.1 min read

Editor’s update—July 20, 2026: The HIPAA Security Rule changes discussed below have not been finalized. HHS continues to identify the regulation as a proposed rule, and the current HIPAA Security Rule remains in effect. The federal Unified Agenda currently lists the rulemaking as a long-term action with a target of July 2027 for final action.

For more than two decades, healthcare organizations have built their HIPAA security programs around an important distinction: some implementation specifications are “required,” while others are “addressable.”

The proposed HIPAA Security Rule would largely eliminate that distinction. Instead, every implementation specification would become required, subject only to specific and limited exceptions. That change would affect much more than information technology departments. It would reshape HIPAA Security Rule training for clinical staff, administrators, managers, contractors, executives, and anyone else whose work can affect electronic protected health information, or ePHI.

Although the final rule has been delayed, healthcare organizations should not treat the delay as permission to postpone workforce preparation. The existing Security Rule already requires appropriate security awareness and training, and recent OCR enforcement activity continues to emphasize regular, organization-specific training tied to employees’ actual job duties.

What Does “Addressable” Mean Under the Current HIPAA Security Rule?

One of the most persistent HIPAA misconceptions is that an addressable safeguard is optional.

It is not.

Under the current Security Rule, an organization must evaluate whether each addressable implementation specification is reasonable and appropriate in its environment. If it is, the organization must implement it. If it is not, the organization must document its reasoning and, when reasonable and appropriate, adopt an equivalent alternative measure that accomplishes the same purpose.

This framework was intended to give regulated entities flexibility. A small physician practice, a regional health system, a health plan, and a national business associate may face different risks and possess different technical capabilities. The current rule allows each organization to consider factors such as its size, infrastructure, existing safeguards, risk analysis, and implementation costs.

The problem is that “addressable” has too often been interpreted as “we can decide not to do it.” Inadequate documentation, incomplete risk analysis, weak encryption, inconsistent access controls, and informal cybersecurity practices have continued to appear in OCR investigations.

What Would the Proposed Security Rule Change?

The proposal would remove the formal distinction between required and addressable implementation specifications. All applicable implementation specifications would become required, except where the regulation establishes a specific and limited exception.

That does not necessarily mean every healthcare organization would have to use identical software or configure every system in precisely the same way. The proposal would retain some flexibility in how an organization selects reasonable and appropriate security measures based on its size, complexity, capabilities, technical infrastructure, costs, risks, and need for operational resilience. The difference is that organizations would have substantially less discretion to decline an implementation specification altogether.

Among other changes, the proposal would require or strengthen:

  • Encryption of ePHI at rest and in transit, subject to limited exceptions.
  • Multi-factor authentication across relevant electronic information systems.
  • Written technology asset inventories and network maps.
  • More detailed written risk analyses.
  • Network segmentation.
  • Vulnerability scanning at least every six months.
  • Penetration testing at least once every 12 months.
  • Annual compliance audits.
  • Written incident-response and contingency plans.
  • Regular testing of security policies, procedures, and technical controls.
  • Greater documentation and verification from business associates.

Technology may implement many of these safeguards, but workforce behavior will determine whether they work.

Why Workforce Training Becomes Even More Important

A security control is only effective when employees understand what it does, how they are expected to use it, and what they must do when something goes wrong.

Multi-factor authentication provides little protection if employees approve fraudulent login prompts. Encryption cannot protect information that an employee sends through an unauthorized personal account. Network monitoring cannot stop a breach if suspicious activity is ignored or reported too late. An incident-response plan will not work if employees do not know who to contact.

The proposed rule therefore treats security awareness training as an ongoing operational requirement—not a one-time presentation employees complete during orientation.

Under the proposed language, regulated entities would have to provide security awareness training:

  1. To every workforce member by the applicable compliance date and at least once every 12 months thereafter.
  2. To each new workforce member no later than 30 days after the individual first receives access to relevant electronic information systems.
  3. To affected workforce members no later than 30 days after a material change to applicable security policies or procedures.
  4. Through ongoing reminders and notifications addressing employees’ security responsibilities and relevant emerging threats.
  5. With documentation showing that required training and reminders were provided.

This proposed structure creates a much clearer training cycle: initial education, annual training, change-based training, ongoing reinforcement, and documented completion.

What Staff Training Should Cover

The proposal identifies several subjects that would have to be addressed. Training would need to cover relevant written policies and procedures, detecting and reporting security incidents, malicious software, social engineering, password protection, system-access procedures, and restrictions on password sharing.

A practical training program should translate those requirements into decisions employees make during an ordinary workday.

1. Role-Specific Security Responsibilities

Employees should understand which systems, records, devices, and locations they are permitted to access. Training should explain how the organization’s security policies apply to the learner’s actual duties rather than presenting the same abstract material to every role.

A receptionist may need focused instruction on patient portals, email attachments, identity verification, and workstation privacy. Clinical employees may need additional instruction on mobile devices, electronic health records, medical equipment, secure messaging, and remote access. IT administrators need more detailed education on privileged accounts, monitoring, patching, backups, and incident escalation.

2. Phishing and Social Engineering

Employees should learn how attackers manipulate people through urgency, authority, fear, curiosity, or familiarity.

Training should include realistic examples involving:

  • Requests to reset passwords.
  • Unexpected multi-factor authentication prompts.
  • Messages appearing to come from senior leadership.
  • Fake invoices and payment instructions.
  • Requests for patient files or employee information.
  • Malicious links and attachments.
  • Telephone and text-message impersonation.
  • Vendors requesting unexpected access.

Employees should also know how to verify a suspicious request without replying directly to the sender or using the contact information included in the questionable message.

3. Passwords, Authentication, and Access Controls

The proposed rule would require training on safeguarding passwords, using unique passwords of sufficient strength, and complying with restrictions on password sharing. It would also establish broad multi-factor authentication requirements.

Employees should understand why they may never:

  • Share credentials with coworkers.
  • Approve an authentication request they did not initiate.
  • reuse organizational passwords on personal accounts.
  • Leave an active workstation unattended.
  • Circumvent access restrictions for convenience.
  • Continue using access rights that are no longer necessary for their role.

Managers should receive additional training on promptly reporting transfers, terminations, extended leave, and changes in job responsibilities that require access to be modified or removed.

4. Security-Incident Recognition and Reporting

Employees do not need to determine conclusively that a breach occurred before reporting a concern. They need to recognize warning signs and know how to escalate them.

Reportable events may include:

  • A lost or stolen laptop, phone, badge, or storage device.
  • An email sent to the wrong recipient.
  • A suspicious login alert.
  • Unexpected software behavior.
  • A ransomware message.
  • An employee accessing records without a business reason.
  • A vendor reporting a system outage or cyberattack.
  • A document containing ePHI uploaded to an unauthorized platform.
  • Accidental disclosure of credentials.
  • An unexpected change to a patient record.

Training should identify the organization’s reporting channel, required information, after-hours process, and expectation of immediate reporting.

5. Secure Use of Devices and Electronic Communications

Workforce training should address how employees may access, transmit, store, print, download, photograph, or dispose of ePHI.

This includes clear rules for:

  • Personal devices.
  • Remote and hybrid work.
  • Public and home Wi-Fi.
  • Portable media.
  • Text messaging.
  • Email.
  • Cloud-storage platforms.
  • Artificial intelligence tools.
  • Screenshots and photographs.
  • Printing and physical document handling.

Employees should be able to distinguish an approved organizational system from a convenient but unauthorized alternative.

6. Downtime and Contingency Procedures

The proposed rule would strengthen contingency planning and require written procedures for restoring certain systems and data. Staff training should therefore explain what employees must do when normal systems are unavailable.

Employees need practical answers to questions such as:

  • How will patient care continue during an outage?
  • Where are approved downtime forms located?
  • How should information created during downtime be secured?
  • Who may activate emergency procedures?
  • How will information be entered into the electronic system after restoration?
  • What communication methods are approved when email or internal messaging is unavailable?

Contingency training should be tested through exercises rather than left entirely in a policy manual.

One Course Will Not Be Enough for Every Employee

A comprehensive HIPAA Privacy and Security course remains an important foundation, but the proposed approach favors training that is tailored to an employee’s responsibilities.

A mature program may include:

  • Foundational HIPAA Privacy and Security training for new employees.
  • Annual HIPAA Security awareness training for the entire workforce.
  • Cybersecurity awareness training focused on phishing, malware, passwords, and social engineering.
  • Manager training on access changes, terminations, incident reporting, and escalation.
  • Specialized technical training for IT and security personnel.
  • Short reminders or microlearning modules throughout the year.
  • Policy-change training when procedures or systems materially change.
  • Scenario-based exercises for incident response and system downtime.

The goal is not merely to prove that employees opened a course. The organization should be able to show that employees were trained on the risks, policies, systems, and reporting procedures that apply to their jobs.

Why Prepare Now If the Final Rule Is Not Expected Until 2027?

The rulemaking timeline may have changed, but the underlying compliance and cybersecurity risks have not.

OCR continues to enforce the current Security Rule. In April 2026, OCR announced four ransomware-related settlements totaling more than $1.1 million and recommended that regulated entities provide regular HIPAA training specific to the organization and each workforce member’s job duties. A February 2026 phishing-related settlement also required annual workforce training on the organization’s written HIPAA policies and procedures.

Many of the proposal’s training principles are therefore sensible steps under the current rule:

  • Train employees regularly.
  • Tie training to actual job duties.
  • Document completion.
  • Reinforce training throughout the year.
  • Update training when policies, systems, or threats change.
  • Teach employees exactly how to report an incident.

Organizations that begin now will be better positioned regardless of when a final rule is published or how its provisions change.

A Practical Workforce-Readiness Plan

Healthcare organizations can begin with five actions.

Step 1: Review Current Training

Identify who receives HIPAA Security training, when they receive it, what it covers, and how completion is documented.

Step 2: Compare Training to Written Policies

Confirm that the course reflects the organization’s actual password, access, remote-work, device, email, incident-reporting, and downtime procedures.

Step 3: Divide Employees by Role

Create training groups for general workforce members, managers, clinical staff, executives, IT personnel, and employees with privileged or remote access.

Step 4: Add Ongoing Reinforcement

Use short reminders, phishing exercises, newsletters, manager discussions, or microlearning activities between annual courses.

Step 5: Preserve Evidence

Maintain course assignments, completion dates, assessment results, certificates, reminder records, course versions, and copies of the policies covered during training.

Build a Training Program That Is Ready for What Comes Next

The proposed end of addressable implementation specifications signals a broader change in HIPAA compliance: cybersecurity practices must be implemented, understood, tested, and documented.

Evolve e-Learning Solutions offers HIPAA Privacy and Security training and Cyber Security Awareness training designed to help healthcare employees understand how to protect patient information, recognize threats, and respond appropriately. Courses can be delivered through Evolve’s learning management system or integrated into an organization’s existing LMS, with completion tracking and certificates available for compliance documentation.

Organizations can also combine HIPAA, cybersecurity, OSHA, Medicare, and other compliance courses in a custom bundle based on their workforce and regulatory needs.

Request a free course preview or speak with Evolve about building a role-based HIPAA and cybersecurity training program for your organization.

Frequently Asked Questions

Has the new HIPAA Security Rule been finalized?

No. As of July 20, 2026, the proposed HIPAA Security Rule has not been finalized. The current Security Rule remains in effect, and the federal Unified Agenda lists July 2027 as the target for final action.

Does “addressable” mean that a HIPAA safeguard is optional?

No. Under the current rule, an organization must determine whether an addressable specification is reasonable and appropriate. The organization must implement it when appropriate or document its decision and implement an equivalent alternative measure when reasonable and appropriate.

Would the proposed rule make every safeguard mandatory?

The proposal would remove the distinction between required and addressable implementation specifications and make all applicable specifications required, subject to specific and limited exceptions. Organizations would retain some flexibility in selecting reasonable and appropriate methods of implementation.

How often would employees need HIPAA Security training?

Under the proposal, workforce members would receive training by the compliance date and at least once every 12 months thereafter. New workforce members would generally be trained within 30 days of obtaining system access, and affected employees would receive additional training within 30 days of a material policy or procedure change.

Should organizations wait for the final rule before updating training?

No. The existing Security Rule remains enforceable, and OCR continues to recommend regular, role-specific HIPAA training. Organizations can improve present compliance while preparing for the direction of the proposed rule.

Share this article

Follow us

A quick overview of the topics covered in this article.

Contact us

Contact us today to learn how Evolve e-Learning can support your team.

Latest articles