SESK: Stuff Everyone Should Know · sesk.info/hipaa-password-management-addressable
Under the Security Rule, how are password procedures classified?
Password management is addressable, not automatically required.
- Required, with changes every 90 days
- Not covered by the Security Rule
- Addressable ✔
Why: Password management is addressable. Covered entities must assess it and implement it if reasonable and appropriate or document why not.
Huh, didn't know that: If used, password policies should cover creation, changes, and safeguarding.
Why did the password go to therapy? It felt too easily guessed.
Like this card?
References
Answer: Addressable. Password management is addressable. Covered entities must assess it and implement it if reasonable and appropriate or document why not.
- 45 CFR 164.308(a)(5)(ii)(D) www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C/section-164.308
Password management (Addressable). Procedures for creating, changing, and safeguarding passwords.
Checked 2026-10-10.
Think this answer is wrong? Tap "Challenge this answer" on the card in the game and tell us why.
More stuff everyone should know
That's stuff everyone should know.