Auditen
Home / Frameworks / HIPAA / Physical safeguards
HIPAA · 164.310

Physical safeguards

Physical safeguards require organizations to limit physical access to facilities and equipment that house electronic protected health information (ePHI). The goal is to prevent unauthorized individuals from physically entering secure areas or stealing hardware containing patient data.

What it means

While technical safeguards focus on digital barriers like firewalls, physical safeguards address the "real world" layer of security. This ensures that an intruder cannot simply walk into a server room and remove a hard drive or sit at an unattended workstation to view sensitive records.

The scope extends from the perimeter of your office building down to individual devices. It includes the management of facility access, the positioning of monitors in public areas, and the lifecycle of hardware—from procurement to final destruction.

Because these requirements are "addressable," organizations must implement them if they are reasonable and appropriate for their environment. If a specific requirement is not implemented, the organization must document why it was not reasonable and what alternative measure was put in place to achieve the same goal.

How to meet it

Evidence an auditor asks for

  • Access logs showing who has entered secure areas (e.g., electronic badge reports or manual visitor sign-in sheets).
  • A current asset inventory listing all hardware that stores or transmits ePHI.
  • Written policies and procedures governing facility access, workstation security, and media disposal.
  • Certificates of destruction from third-party vendors proving that old hard drives or devices were physically destroyed.

Common pitfalls

  • Failing to track "shadow IT," such as unauthorized USB drives or tablets used by staff that are not listed in the official asset inventory.
  • Relying on a written policy for workstation locks without implementing technical enforcement via Group Policy (GPO) or Mobile Device Management (MDM).
  • Assuming cloud hosting removes all physical requirements; auditors still require evidence of how you secure the local devices and offices used to access that cloud data.