HIPAA Physical Safeguards: What the Security Rule Requires
The Security Rule’s physical safeguard requirements are frequently overlooked but directly tied to some of the most common sources of reportable breaches.
When healthcare organizations think about HIPAA security, they tend to focus on network security, access controls, and encryption. Physical safeguards receive less attention, which is one reason they show up in enforcement actions more often than their profile might suggest. Stolen laptops, unattended workstations displaying patient information, and unauthorized physical access to server rooms are consistent sources of reportable breaches and OCR enforcement findings.
The HIPAA Security Rule’s physical safeguard requirements are found at 45 CFR 164.310 and apply to both covered entities and business associates. They address four distinct areas: facility access controls, workstation use, workstation security, and device and media controls. This article explains what each standard requires, which implementation specifications are required versus addressable, and where organizations commonly fall short.
Facility Access Controls
The Facility Access Controls standard at 45 CFR 164.310(a)(1) requires covered entities and business associates to implement policies and procedures to limit physical access to their electronic information systems and the facilities in which they are housed, while ensuring that properly authorized access is allowed.
There are four implementation specifications under this standard, all of which are addressable rather than required. Addressable means that your organization must assess each specification and either implement it or document why it is not reasonable and appropriate for your environment and what equivalent alternative safeguard you have in place instead.
Contingency Operations. Procedures that allow facility access in support of restoration of lost data under the disaster recovery plan and emergency mode operations plan in the event of an emergency.
Facility Security Plan. Policies and procedures to safeguard the facility and the equipment therein from unauthorized physical access, tampering, and theft. This includes physical security measures such as locks, access badges, alarm systems, and visitor sign-in procedures.
Access Control and Validation Procedures. Procedures to control and validate a person’s access to facilities based on their role or function, including visitor control and control of access to software programs for testing and revision.
Maintenance Records. Policies and procedures to document repairs and modifications to the physical components of a facility related to security, such as hardware, walls, doors, and locks. This specification is frequently overlooked but ensures that physical changes to the facility that could affect security are tracked.
Workstation Use
The Workstation Use standard at 45 CFR 164.310(b) requires covered entities and business associates to implement policies and procedures that specify the proper functions to be performed, the manner in which those functions are to be performed, and the physical attributes of the surroundings of a specific workstation or class of workstation that can access ePHI.
This is a required standard with no implementation specifications, meaning organizations have flexibility in how they implement it but must do so. A Workstation Use policy typically addresses what types of work are permitted and prohibited on workstations that access ePHI, the physical positioning of workstations to prevent unauthorized viewing of screens, policies regarding unattended workstations, and any restrictions on portable devices used to access ePHI.
Remote work arrangements have made workstation use policies significantly more complex. A workforce member working from home who accesses ePHI from a kitchen table visible to household members presents physical safeguard concerns that a workstation policy needs to address. Organizations that established workstation use policies before remote work became common should review whether those policies still reflect current operating conditions.
Workstation Security
The Workstation Security standard at 45 CFR 164.310(c) requires physical safeguards for all workstations that access ePHI to restrict access to authorized users. This is also a required standard.
Workstation security measures typically include physical locks on desktop workstations in high-traffic areas, cable locks for laptops when they are not in use, screen privacy filters for workstations visible to patients or visitors, and clean desk policies that restrict what can be left visible on or around a workstation when not in active use.
One practical distinction between workstation use and workstation security is scope. Workstation use governs how employees use workstations. Workstation security governs the physical controls placed on those workstations to prevent unauthorized access. Both standards need to be addressed in your documentation, but they address different dimensions of the same problem.
Device and Media Controls
The Device and Media Controls standard at 45 CFR 164.310(d)(1) requires covered entities and business associates to implement policies and procedures that govern the receipt and removal of hardware and electronic media that contain ePHI into and out of a facility, and the movement of these items within the facility.
There are four implementation specifications under this standard. Two are required and two are addressable.
Disposal (required). Policies and procedures to address the final disposition of ePHI and the hardware or electronic media on which it is stored. Organizations must have documented procedures for ensuring that ePHI is rendered inaccessible before hardware or media is disposed of, donated, or transferred. Drive wiping, degaussing, and physical destruction are common approaches. Disposal without documented procedures is one of the most common sources of avoidable breaches.
Media Re-Use (required). Procedures for removal of ePHI from electronic media before it is made available for reuse. If a workstation hard drive or mobile device that previously contained ePHI is going to be reassigned to another user or purpose, the ePHI must be removed according to documented procedures before that happens.
Accountability (addressable). Maintaining a record of the movements of hardware and electronic media and any person responsible for such movements. Many organizations implement an asset tracking system to satisfy this specification, particularly for laptops and mobile devices that leave the facility.
Data Backup and Storage (addressable). Creating a retrievable, exact copy of ePHI, when needed, before movement of equipment. This specification addresses the risk of data loss when devices are moved and complements the broader contingency planning requirements under the administrative safeguards.
Where Organizations Commonly Fall Short
Undocumented disposal practices. Many organizations have informal practices around disposing of old hardware, but informal is not sufficient. Without a written policy and documented disposal records, the organization cannot demonstrate to OCR that ePHI was handled appropriately when a device left the facility. The absence of documentation is treated as the absence of a control.
Workstation policies that do not address remote work. Organizations that established their workstation policies before remote and hybrid work became common may have policies that describe an office-based environment that no longer reflects current operations. Policies need to be updated to address the physical safeguard expectations that apply when workforce members access ePHI from home or other off-site locations.
No facility security plan. Smaller organizations often rely on general-purpose physical security measures without a written plan that ties those measures to their HIPAA obligations. A brief documented plan that describes the physical security controls in place at each facility where ePHI systems are housed satisfies the requirement and provides a baseline for reviewing whether controls are adequate.
Treating laptop loss as an IT problem rather than a compliance problem. When a laptop containing ePHI is lost or stolen, the device and media controls documentation is the first thing OCR will ask to see. Was the device tracked? Was it encrypted? Was there a documented policy governing how laptops containing ePHI were to be handled? Organizations that treat device loss as purely an equipment replacement issue and fail to document their response and prevention framework expose themselves to enforcement risk that goes well beyond the value of the hardware.
Document Your Physical Safeguards
The HIPAA Essentials Library Security Bundle includes professionally written, editable policy templates covering all four physical safeguard standards: Facility Access Controls, Workstation Use, Workstation Security, and Device and Media Controls. Each template is aligned to the Security Rule’s specific implementation specifications and includes customization guidance for your organization’s environment.
For complete Security Rule coverage including the Risk Analysis Worksheet and all administrative and technical safeguard policies, the Security Bundle provides everything in a single package. All templates are delivered as editable Microsoft Word documents, available immediately after purchase.
✅ Need the policies to back up your physical safeguards program? Our Security Bundle includes all required Security Rule policies — including Workstation Security, Access Control, and the Information Security Policy that establishes your physical safeguards framework — all pre-drafted in Microsoft Word and ready to adapt for your facility.