A four-provider orthopedic group leases the second floor of a medical office building. The landlord's cleaning crew has a master key. The IT contractor has the server closet code. A shredding vendor rolls a locked bin out the back door every Thursday. None of those three parties is on the group's vendor list, and none of them appears in any written procedure. That gap is a HIPAA physical safeguards failure, and it exists in a large share of small practices right now.

This article walks through 45 CFR §164.310 — the physical safeguards section of the Security Rule — from the operator's chair. Who owns each control, what the workflow looks like on a normal Tuesday, and what documentation you hand to an investigator or auditor who asks.

What HIPAA Physical Safeguards Actually Cover

HIPAA physical safeguards are the Security Rule requirements that protect electronic protected health information (ePHI) from unauthorized physical access, tampering, theft, and environmental damage. There are four standards:

  • Facility Access Controls (§164.310(a)) — limiting and validating physical entry to buildings and rooms where ePHI systems live. Four addressable implementation specifications: contingency operations, facility security plan, access control and validation procedures, and maintenance records.
  • Workstation Use (§164.310(b)) — required. Written policy on the functions performed at workstations and the physical surroundings appropriate for them.
  • Workstation Security (§164.310(c)) — required. Physical protections restricting workstation access to authorized users.
  • Device and Media Controls (§164.310(d)) — governing hardware and electronic media moving in, out of, and within your facility. Disposal and media re-use are required; accountability and data backup and storage are addressable.

They apply to every covered entity and business associate, regardless of size. A solo practice with two laptops has the same four standards to satisfy as a hospital system — the scale of the response differs, not the obligation. HHS publishes its Security Rule guidance material at hhs.gov.

Facility Access Controls: Four Specs, Zero of Them Optional

All four implementation specifications under this standard are labeled "addressable." That word causes more compliance damage than any other in the Security Rule. It does not mean optional. It means you assess whether the specification is reasonable and appropriate for your environment, implement it if it is, and — if it isn't — document why and implement an equivalent alternative.

Contingency Operations

If your building loses power, floods, or is closed by fire marshal order, who is authorized to enter and restore data? Name them. A one-page procedure listing two named staff, the alarm code holder, the backup restoration sequence, and the after-hours contact for your IT vendor satisfies this. Attach it to your disaster recovery plan so the two documents don't drift apart.

Facility Security Plan

This is the written map of how you physically protect the space. Door locks and rekeying schedule, alarm system and who holds codes, camera coverage and retention period, badge or key inventory, server closet controls, after-hours procedures. For a leased suite, it also covers what the landlord controls and what you control — because the lease often gives building management access you didn't consciously grant.

Practical test: walk your suite at 7:15 p.m. after the last staff member leaves. Photograph anything an unescorted person could reach. That walk, repeated quarterly and dated, becomes your evidence.

Access Control and Validation Procedures

How do you verify that the person in the hallway belongs there? For most practices the answer is a combination of visitor sign-in, escort rules for non-staff in clinical areas, and badge or visual identification. Write down the rule for equipment vendors and pharmaceutical reps specifically — they show up unannounced and staff wave them through.

Tie this to termination. When a medical assistant leaves on a Friday, the key, badge, and alarm code come back before they walk out. Your offboarding checklist should have a physical column, not just an accounts column.

Maintenance Records

Document repairs and modifications to physical security components — locks rekeyed, doors replaced, camera systems serviced, alarm panels upgraded. A dated log with vendor name, work performed, and who authorized it is enough. This is the specification practices skip most often, and it's the cheapest one to satisfy.

Workstation Use and Workstation Security Are Both Required

These two standards have no implementation specifications, which means the standard itself is the obligation. You must have them.

Workstation Use is a policy question: what functions are performed on each class of device, and in what physical surroundings? Your front-desk terminal sits in a lobby with sightlines from the waiting area. Your billing workstation sits in a closed office. A provider laptop travels home. Each of those gets a different rule — screen privacy filter and auto-lock at 60 seconds for the lobby terminal, full-disk encryption and a no-family-use rule for the laptop.

Workstation Security is the physical implementation: cable locks, positioning monitors away from public sightlines, locking offices with unattended machines, and prohibiting ePHI-capable devices in unsecured shared spaces. Reception is where this breaks. If a patient standing at the check-in window can read the previous patient's chart on a reflected screen, you have a documented finding waiting to happen.

NIST's implementation guidance for the Security Rule, SP 800-66 Revision 2, maps each standard to concrete controls and is the most useful free reference for translating regulatory language into a task list.

Device and Media Controls: Where Practices Generate Breach Reports

Look at the HHS breach portal and filter by "Theft" or "Loss." You'll see the same fact patterns repeating: a laptop taken from a vehicle, an unaccounted-for backup drive, a copier returned at lease end with an unwiped hard drive, boxes of records left behind in a vacated suite. Every one of those is a device and media controls failure.

Disposal and Media Re-Use (Both Required)

Before any device leaves your control — sold, donated, returned to a leasing company, recycled, or handed to a new employee — the ePHI on it must be rendered unreadable. Deleting files and emptying the trash does not accomplish this. Use cryptographic erase on encrypted drives, overwrite tools, or physical destruction, following NIST SP 800-88 Rev. 1 for sanitization methods.

The list of media that counts is longer than most administrators assume: workstation and server drives, laptops, tablets, phones with clinical apps or email, USB drives, external backup drives, CDs from imaging referrals, and the internal storage in multifunction copiers, fax machines, and check-in kiosks. Copiers in particular have burned practices at lease turnover.

Keep a certificate of destruction or a signed internal sanitization record for each unit, with serial number, method, date, and the name of the person who performed it. That record is the evidence. Without it, you cannot prove a lost device was clean.

Accountability: Maintain a Movement Log

Addressable, and for most practices unambiguously reasonable to implement. Maintain a record of hardware and media moves, and the person responsible for each. In practice this is an asset inventory spreadsheet with columns for device type, serial number, assigned user, physical location, encryption status, and disposition date.

Reconcile it twice a year. The reconciliation itself — dated, initialed, with discrepancies noted and resolved — is what demonstrates the control operates rather than merely exists.

Data Backup and Storage

Before you move equipment, create a retrievable exact copy of the ePHI on it when that's reasonable. Also govern where backup media physically live. If a nightly backup drive rides home in someone's bag, that's a storage decision with a physical safeguards dimension: encryption, chain of custody, and a documented rationale.

Where Physical Safeguards Turn Into Vendor Paperwork

Every physical control above eventually touches someone who isn't your employee. Document shredding companies. Offsite media storage. IT contractors with server closet access. Copier maintenance technicians who service drives. Cloud backup providers holding your images. Answering services. Each of those relationships needs a written analysis of whether the vendor creates, receives, maintains, or transmits ePHI on your behalf — and if so, an executed business associate agreement before access begins.

The distinction that trips people up: a janitorial crew that incidentally passes locked areas is generally not a business associate, but a records-storage vendor holding boxes of charts is, and a shredding company that takes custody of PHI is. When you find an unpapered vendor mid-review — which you will — you can generate a signature-ready business associate agreement through a six-step wizard and export it as PDF or DOCX the same afternoon. One-time purchase, no subscription, which matters when you're closing three vendor gaps at once and don't want a recurring line item for paperwork you'll sign twice a year.

What "Addressable" Means When OCR Asks

For each addressable specification, your file needs one of three things: evidence you implemented it, evidence you implemented a documented equivalent alternative, or a written determination that the specification is not reasonable and appropriate for your environment, with the reasoning and the compensating measures you rely on instead.

What you cannot have is silence. A blank field next to "maintenance records" in your risk analysis is not a decision — it's an unaddressed requirement, and it's the easiest finding in the world for an investigator to write up.

Note also that HHS issued a proposed rule in January 2025 to strengthen the Security Rule, which among other changes would remove the addressable/required distinction. As of this writing it remains a proposal, not a final rule. Practices that already document their addressable decisions rigorously will have far less work to do if it finalizes.

A 90-Day Build Plan

  1. Days 1–15. Build the asset inventory. Every device that stores, processes, or displays ePHI, with serial number, location, assigned user, and encryption status. This is the foundation for three of the four standards.
  2. Days 16–30. Walk the facility after hours. Photograph and log every physical gap: unlocked server closet, lobby-visible monitor, propped back door, unsecured records room, unattended fax.
  3. Days 31–50. Write the facility security plan, contingency operations procedure, access control and validation procedure, and workstation use policy. Four documents, none longer than three pages.
  4. Days 51–65. Fix the physical gaps. Cable locks, privacy filters, rekeying, monitor repositioning, door hardware. Log every change in the maintenance record.
  5. Days 66–80. Reconcile the vendor list against the inventory. Execute missing BAAs. Collect certificates of destruction for anything disposed of in the past year.
  6. Days 81–90. Train staff on the new procedures, capture attendance with signatures, and update the risk analysis to reflect the remediated findings.

The Evidence File an Investigator Will Ask For

Assume a laptop goes missing and you file a breach notification. The follow-up request will ask for documents, not descriptions. Have these ready in one folder:

  • Current risk analysis addressing all four physical safeguards standards, with dates
  • Facility security plan and contingency operations procedure, with revision history
  • Workstation use and workstation security policies, with staff acknowledgment signatures
  • Asset inventory with encryption status per device, plus the last two reconciliations
  • Certificates of destruction and internal sanitization records
  • Key, badge, and alarm code issuance log, with terminations reflected
  • Maintenance records for locks, alarms, and camera systems
  • Executed BAAs for every vendor with physical or logical access to ePHI
  • Dated quarterly walkthrough logs with findings and closure dates

Encryption status deserves its own emphasis. A lost device with properly implemented encryption may fall under the breach notification safe harbor; the same device unencrypted is a reportable breach with notification costs, portal posting, and likely an investigation. The inventory column that records it is the cheapest insurance in your compliance program.

Start With the Two Documents You're Missing

Most practices already do 60 percent of this informally. The doors lock, the server closet is closed, the shred bin is used. What's missing is the written policy and the dated record proving the practice operates as described. Close that gap and your physical safeguards posture improves overnight without buying anything.

If your risk analysis and policy set need rebuilding from scratch, automated risk analysis and the full HIPAA document set will get you a defensible baseline faster than a blank template. And when the vendor reconciliation turns up contractors working without paperwork, draft and export the BAA before they're back in your server closet next week.