Under the Security Rule, how are password procedures classified?

Password management is addressable, not automatically required.

Start playing free

  1. Required, with changes every 90 days
  2. Not covered by the Security Rule
  3. Addressable ✔

Why: Password management is addressable. Covered entities must assess it and implement it if reasonable and appropriate or document why not.

Huh, didn't know that: If used, password policies should cover creation, changes, and safeguarding.

The dad joke
Why did the password go to therapy? It felt too easily guessed.
Like this card?
Play the game

References

Answer: Addressable. Password management is addressable. Covered entities must assess it and implement it if reasonable and appropriate or document why not.

  1. 45 CFR 164.308(a)(5)(ii)(D) www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C/section-164.308
    Password management (Addressable). Procedures for creating, changing, and safeguarding passwords.
    Checked 2026-10-10.

Think this answer is wrong? Tap "Challenge this answer" on the card in the game and tell us why.

Test yourself in the game