Physical and technical safeguards for a distributed workforce — the section most remote-first health tech companies leave blank.
What is in the download
- Format: DOCX
- Length: 5 page(s) / file(s)
- Includes: rule citations, fill-in guidance in the margin, and a completed example
- Licence: free to modify and use commercially
What is in the template
The Security Rule’s physical safeguards at §164.310 do not vanish when the lease does — a home office is a facility in the rule’s sense, a kitchen-table laptop is a workstation, and the standard still expects you to specify the functions performed, the manner performed, and the physical surroundings. This template is that specification for a distributed workforce. Sections cover: workspace expectations — a reasonably private working area for PHI work, screens positioned away from household traffic, and rules for clinical or patient-facing calls where household members or smart speakers could overhear; device requirements — organisation-managed or MDM-enrolled machines, full-disk encryption, automatic screen lock, and the prohibition on family use of work devices; network rules — what is required of home networks, when a VPN is mandatory, and how to work safely from public spaces; paper handling — printing PHI at home (the defensible default is “don’t”, with a shredding procedure if you must); the approved-channels list for discussing and transmitting PHI; incident reporting from remote settings, including lost devices and household exposure; and the offboarding step for retrieving or wiping hardware from remote employees.
How to use it
- Read it end to end before filling anything in.
- Delete every clause describing a control you do not have. An untrue policy is evidence against you.
- Assign an owner and a review date to each section.
- Publish it, collect acknowledgements against the version number, and retain both for six years.
Step two applies with force here: a VPN mandate nobody enforces, or an MDM requirement covering half the fleet, converts this document from protection into self-documented non-compliance. Scope it to what is actually deployed and put the rest in a dated remediation plan.
How to customise it
The first decision is device posture: company-issued hardware only, or personal devices under a BYOD policy — this template assumes the former and cross-references the latter, so delete whichever half you do not run. The second is role differentiation: an engineer querying a production database and a coordinator answering patient messages have different exposure, and the template’s role-scoped sections let you tighten requirements for high-exposure roles without burdening everyone. The third is enforcement mechanics: name your actual MDM, your actual VPN or zero-trust product, and your actual screen-lock timeout, because auditors check the policy against the configuration. Finally, adapt the clinical-call section to your reality — telehealth from home is now routine, and the private-space expectation needs to be written in a way your clinicians can genuinely meet, or they will quietly ignore it and take the policy’s credibility with it.
Common mistakes
- Leaving the physical safeguards section blank. “We have no offices” is the most common gap in remote-first health tech. The environments exist; the standard applies; this document is the answer.
- Policy by prohibition alone. Banning public Wi-Fi without providing a VPN, or banning texting without an approved fast channel, guarantees violations. Every prohibition needs a sanctioned alternative.
- Ignoring the household. The spouse who borrows the laptop and the smart speaker beside the telehealth desk are real disclosure paths that a policy written for offices never imagines.
- No hardware retrieval procedure. Remote departures are where laptops with cached ePHI disappear. The offboarding section needs an owner and a tracking step, not good intentions.
- One policy for every role. Uniform rules end up too loose for clinicians and too strict for everyone else — role-scoping keeps them followable.
Related templates
This policy leans on the BYOD policy for personal devices, the encryption policy for the disk and transmission standards it references, the access control and password policies for identity, and the incident response plan for the reporting path it points remote staff toward. The regulatory background — why home offices are facilities — is in the physical safeguards guide.
The honest limitation
A template is a starting point, not a program. It cannot record who acknowledged it, prove it was followed, or update itself when your environment changes. Those three things are what the platform does, and they are the difference between having documents and having compliance.
Start where you are
Take the free readiness assessment — 24 questions, about eight minutes, no call required. You get a scored report identifying which required specifications you are missing and what to fix first. If it turns out you are further along than you thought, we will tell you that too.