Facility access, workstation use and security, and device and media controls — including the fully remote workforce.
What this category covers
Physical safeguards live at 45 CFR §164.310 and cover the tangible layer of security: buildings, rooms, desks, screens, laptops, phones, drives, and paper-adjacent media. Four standards — facility access controls, workstation use, workstation security, and device and media controls — and they are the shortest safeguard category by far, which is probably why they get the least attention. The neglect is a mistake for two reasons. First, physical failures are embarrassingly common: the laptop from the car, the server room propped open, the drive sold on a marketplace with patient data intact. Second, encryption changes the stakes here more than anywhere else — a lost encrypted laptop is an incident log entry, while a lost unencrypted one is a reportable breach with a 60-day clock. The physical and technical safeguards are load-bearing for each other.
A definitional note that trips people up: “facility” means the physical premises and interior where ePHI systems are housed or accessed. That is not limited to premises you own — which is where remote work enters, below.
Facility access controls
Contingency operations, facility security plan, access control and validation, and maintenance records. All addressable, all expected.
The four implementation specifications, operationally: contingency operations means planning how people get physical access to systems and data during a disaster — who can enter, how restoration works when badge systems are down. The facility security plan is the written description of how premises are protected: locks, alarms, badge zones, camera coverage, key custody. Access control and validation covers how you verify who enters sensitive areas — visitor sign-in and escort, role-based badge access to server or records rooms, and revoking physical access at termination with the same urgency as digital access. Maintenance records track repairs and modifications to security-relevant hardware: locks changed, doors rekeyed, badges reissued.
Addressable status means a fully remote organisation with no premises can document an alternative posture — but “all expected” is the honest gloss: if you have an office with ePHI access, a reviewer expects all four, scaled sensibly.
Workstation use and security
Both required. Specify the functions performed, the manner performed, and the physical surroundings — which now includes home offices and coffee shops.
Workstation use (§164.310(b)) is the policy standard: a written statement of what activities are appropriate on workstations that access ePHI, how they are performed, and what surroundings are acceptable. The operational content most policies need: screens positioned or filtered so ePHI is not readable by bystanders, automatic screen lock at a short timeout, a lock-when-you-walk-away habit that is actually enforced, and rules for working in public and shared spaces. Workstation security (§164.310(c)) is the physical counterpart: restricting physical access to the machines themselves — cable locks where theft is plausible, clean-desk rules where paper PHI exists, and not leaving devices in vehicles, which remains a leading cause of reported breaches year after year. “Workstation” is defined broadly: laptops, tablets, and any device performing similar functions are in scope, not just desktops.
Device and media controls
Disposal and media re-use are required. Accountability and data backup before movement are addressable. Certificates of destruction for drives and devices are the evidence auditors ask for.
This standard (§164.310(d)) governs hardware and electronic media through their whole life. Disposal means ePHI is made unrecoverable before hardware leaves your control — cryptographic erasure, verified wiping, or physical destruction, with a record; deleting files and factory resets do not clear the bar for magnetic media. Media re-use requires the same sanitisation before a device is reassigned internally. Accountability means knowing where your hardware is: a device inventory recording what exists, who holds it, and what it can access — which is also the input your risk analysis needs. Data backup before movement means you do not lose the only copy of anything when equipment is relocated. The disposal chain is the classic silent failure: devices accumulate in a cupboard, then leave via an untracked recycler. A disposal log plus certificates of destruction from a vendor (under BAA, if they handle media containing ePHI) closes it. Printers and multifunction copiers deserve a special mention — many contain storage drives that retain scanned and printed documents, and leased units returned to the vendor with those drives intact have produced real breaches. Add copiers, network hardware, and any device with onboard storage to the inventory, and make drive removal or wiping an explicit line in the lease-return and disposal procedures.
Remote-first organisations
The most common gap in modern health tech: a physical safeguards section that says ‘we have no offices’ and stops there. Your workforce has physical environments; the standard still applies.
The defensible translation for a distributed team: the remote work policy carries the workstation-use content — private workspace expectations, screen privacy, household member and smart-speaker considerations for clinical calls. Full-disk encryption plus MDM carries most of the device-controls weight: inventory, remote lock and wipe, and enforced screen lock, extended to personal devices via a BYOD policy if you allow them. Shipped-back devices from departing employees follow the same sanitisation procedure as office hardware. Document all of this as your implementation of §164.310 rather than writing the section off — the standard scales to your reality; it does not vanish with the lease.
Evidence that satisfies a reviewer
Physical safeguards are unusually easy to evidence once you decide to bother, and unusually embarrassing when you cannot. The artefact set that answers most requests: the facility security plan (even a two-page one) with its last review date; badge or key issuance records reconciled against the roster, the physical twin of your access reviews; a visitor log where sensitive areas exist; the device inventory with assignment history; the disposal log with certificates of destruction attached; and, for distributed teams, MDM enrolment and encryption status exports standing in for the office walk-through. Photographs help more than teams expect — a dated photo of the locked rack or the screen-privacy arrangement is cheap, concrete evidence.
Two review habits close the loop. Fold a physical walk-through into the annual evaluation — server room, workstation sightlines, the drawer of forgotten devices — and record what you found. And after any move, expansion, or shift in remote policy, re-open the risk assessment’s physical rows, because facilities change faster than the documents describing them. Most organisations discover their physical-safeguard gaps in exactly two ways: an auditor’s request, or a lost device. The walk-through is cheaper than either.
Where SuperHIPAA fits
Everything above is work. The platform does the parts that are mechanical — evidence collection, acknowledgement tracking, register maintenance, renewal reminders — and our team does the parts that need judgement. You keep the parts that need to be yours.
Start where you are
Take the free readiness assessment — 24 questions, about eight minutes, no call required. You get a scored report identifying which required specifications you are missing and what to fix first. If it turns out you are further along than you thought, we will tell you that too.