Addressable Was Never Optional (08/26/2026)
- › Counsel are warning that treating an addressable HIPAA specification as optional misreads the Security Rule, which requires a documented decision either way.
- › The DOJ's National Fraud Enforcement Division has published five priority areas.
- › ShinyHunters leaked 7.1 million records belonging to Baxter International.
- › Health systems are warning patients about phishing that impersonates the Epic MyChart portal.
- › The Defense Department has ordered 30 universities to audit foreign research collaborations.
Addressable is the most expensive word in the HIPAA Security Rule, because a generation of risk assessments has read it as optional. It never meant that. An addressable specification requires you to implement it, or document why it is not reasonable and appropriate and implement an equivalent measure, and the documentation is the part auditors ask for.
Top 5 Critical Compliance Alerts
1. Addressable Does Not Mean Optional
Counsel are pushing back on the widespread reading that an addressable implementation specification in the HIPAA Security Rule can simply be skipped. The rule is not a guideline, and the addressable designation describes flexibility in how you satisfy a requirement, with a documented rationale, not permission to ignore it. JD Supra
Operator Note: Pull your risk analysis and search it for the word addressable. If any row says addressable and the next column is blank, or says not applicable with no reasoning attached, that is the finding an investigator will reach first, because it is the cheapest one to prove. Encryption at rest is the specification this usually lands on, and “we decided not to” with no written analysis behind it is worse than not having decided at all.
2. The DOJ Names Five Fraud Enforcement Priorities
The Justice Department’s National Fraud Enforcement Division has announced five priority areas. A published list gives companies a view of where enforcement attention is going before it arrives. JD Supra
Operator Note: A published priority list is a planning document for you as much as for prosecutors. Map the five areas against your own revenue lines and see which ones touch you, then check whether the controls covering those lines were designed for fraud detection or only for accounting accuracy, because those are different things and most organizations only built the second.
3. ShinyHunters Leaks 7.1 Million Baxter International Records
The group has published 7.1 million records belonging to the medical products manufacturer. This is the second ShinyHunters story we have carried this week, after the Carhartt figures came in at roughly half what the group had claimed. HIPAA Journal
Operator Note: Verify the count before you brief anybody, because these groups routinely overstate and the correction lands after your executives have already heard the first number. Troy Hunt’s writeup on the Carhartt claims is the current best guide to doing that verification properly, and it applies to this one too.
4. Health Systems Warn Patients About MyChart Phishing
Multiple health systems are alerting patients to a phishing campaign impersonating the Epic MyChart patient portal. The campaign targets the patients directly, which puts the warning burden on the provider. HIPAA Journal
Operator Note: Patient portal phishing is unusually effective because the real portal also sends unexpected emails about results and appointments, so the legitimate pattern and the malicious one are indistinguishable to the recipient. The fix belongs to the health system rather than the patient: publish one canonical way to reach the portal, and repeat it in every message you send.
5. The DoD Orders 30 Universities to Audit Foreign Research Collaborations
The Defense Department has directed 30 universities to audit their foreign research collaborations. The order covers existing partnerships, not only new ones. JD Supra
Operator Note: Research security has been drifting from a disclosure obligation toward an auditable control, and this is a step further along that path. Any organization with a university research partnership should expect questions to arrive through that channel, because the audit will not stop at the institution’s own staff.
Additional Compliance Alerts
Regulatory Updates
- Advertising pixels are triggering health data obligations for medical aesthetic practices: The tracking pixel remains the most common way a practice becomes a covered data handler without noticing. JD Supra
- US-China sanctions and export controls are reshaping cross-border compliance risk: JD Supra
- Out-of-state collections can create significant exposure for banks: A quick compliance decision that carries a slow liability. JD Supra
Governance
- Board materials frequently fail to contribute value: Worth reading if you prepare the security section of a board pack. Corporate Compliance Insights
The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.
A leader defined by a 'bias for action,' Dusten specializes in physical security assessments that impact profitability and facility resilience.
View Profile →Media Inquiries
For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.