Skip to main content
Category: Physical and Technical Safeguards

Facility Access Controls

Also known as: Physical Access Controls, Facility Access Control
Simply put

Facility access controls are the policies and procedures an organization uses to limit and monitor who can physically enter its buildings and the areas where electronic health information and the systems that hold it are located. In the context of HIPAA, this is one of the required physical safeguards under the Security Rule, and it helps ensure that only authorized people can reach sensitive equipment and records. It generally combines physical measures, such as locks, badges, or biometric readers, with written procedures for granting, tracking, and revoking access.

Formal definition

Under the HIPAA Security Rule, Facility Access Controls are a physical safeguard standard requiring covered entities and business associates to implement policies and procedures that limit physical access to their electronic information systems and the facilities in which they are housed, while ensuring that properly authorized access is allowed. The standard is generally associated with several implementation specifications addressing matters such as contingency operations, a facility security plan, access control and validation procedures, and maintenance records; readers should confirm the exact implementation specifications and their required or addressable designations against the current regulatory text at 45 CFR Part 164. Note that addressable implementation specifications are not optional: an entity must implement the specification, adopt a reasonable and appropriate alternative, or document why the specification is not reasonable and appropriate. This standard governs physical access to systems handling electronic protected health information (ePHI); it is distinct from technical access controls (which restrict logical access within information systems) and from the broader Privacy Rule protections that apply to PHI in all forms. State law, the HITECH Act, or frameworks such as the HITRUST CSF may impose additional or more specific physical security requirements, and HITRUST certification does not by itself establish HIPAA compliance.

Why it matters

Physical access to the places where systems and equipment reside is often the first line of defense for electronic protected health information (ePHI). Even the strongest technical controls, such as encryption and logical access restrictions, can be undermined if an unauthorized person can walk up to a server, workstation, or storage device. Facility access controls address this gap by limiting and monitoring who can physically enter buildings and the specific areas where ePHI and the systems that hold it are located.

Under the HIPAA Security Rule, Facility Access Controls are a required physical safeguard standard, meaning covered entities and business associates must implement policies and procedures in this area rather than treating it as optional. The standard is generally associated with several implementation specifications, and because some implementation specifications are designated addressable, entities should be careful not to interpret addressable as optional. An addressable specification must still be implemented, satisfied through a reasonable and appropriate alternative, or formally documented as not reasonable and appropriate for that organization.

Facility access controls also intersect with broader risk management. Physical measures such as locks, badges, and biometric readers work in combination with written procedures for granting, tracking, and revoking access, so that access aligns with authorization over time. Because no single measure guarantees compliance or prevents all incidents, organizations typically treat facility access controls as one layer within a larger security program, and should verify the exact required and addressable designations against the current regulatory text at 45 CFR Part 164.

Who it's relevant to

Security Officers
Security officers are typically responsible for designing and maintaining the policies and procedures that limit physical access to systems handling ePHI. They generally coordinate physical measures such as locks, badges, and biometric readers with written procedures for authorizing, validating, tracking, and revoking access, and should confirm which implementation specifications apply and whether each is required or addressable under the current Security Rule text.
Covered Entities and Business Associates
Both covered entities and business associates are subject to the Security Rule's physical safeguard requirements, including Facility Access Controls, with respect to the electronic information systems and facilities they control. Each should assess its own facilities and document how it satisfies the standard, keeping in mind that addressable specifications are not optional.
Facilities and Physical Security Teams
Facilities and physical security staff often manage the day-to-day operation of access technologies and entry controls for buildings and secured areas. Their work supports the Security Rule standard by ensuring that only properly authorized people can reach equipment and areas housing ePHI, in coordination with the organization's documented security procedures.
Compliance and Audit Professionals
Compliance officers and auditors evaluate whether facility access controls are documented and operating as intended, including maintenance records and access validation procedures where applicable. They should note that HITRUST certification does not by itself establish HIPAA compliance, and that state law or other frameworks may impose additional physical security requirements to verify against current guidance.

Inside Facility Access Controls

Regulatory Basis
Facility Access Controls is a standard within the physical safeguards category of the HIPAA Security Rule. As a Security Rule provision, it applies specifically to the protection of electronic protected health information (ePHI) and the systems and physical locations that house it, rather than to PHI in all forms.
Addressable Implementation Specifications
The Facility Access Controls standard is generally supported by implementation specifications that are addressable rather than required. Addressable does not mean optional; a covered entity or business associate must assess whether each specification is reasonable and appropriate in its environment, implement it if so, or document why it is not and adopt an equivalent alternative measure where reasonable.
Contingency Operations
Procedures that generally allow authorized personnel to access a facility in support of restoring lost data under a disaster recovery plan or emergency mode operation plan. Practitioners should confirm the exact scope against the current regulatory text.
Facility Security Plan
Policies and procedures intended to safeguard the physical facility and the equipment within it from unauthorized physical access, tampering, and theft.
Access Control and Validation Procedures
Procedures typically used to control and validate a person's access to facilities based on their role or function, including visitor control and control of access to software programs used for testing and revision.
Maintenance Records
Documentation of repairs and modifications to the physical components of a facility that relate to security, such as changes to hardware, walls, doors, and locks.

Common questions

Answers to the questions practitioners most commonly ask about Facility Access Controls.

Are facility access controls part of the Security Rule's technical safeguards?
No. Facility access controls are one of the physical safeguards under the HIPAA Security Rule, not a technical safeguard. Technical safeguards address controls implemented through technology (such as access control on information systems, audit controls, and encryption), while facility access controls concern the physical protection of the buildings, rooms, and equipment where ePHI is stored or accessed. Confusing the two categories is a common error; readers should confirm the current safeguard categories against the applicable regulatory text.
Since facility access controls are an addressable implementation specification, can we skip them if they are inconvenient?
No. Addressable does not mean optional. Where an implementation specification is addressable, a covered entity or business associate must generally assess whether it is a reasonable and appropriate safeguard in its environment, and either implement it, implement an equivalent alternative measure, or document why it is not reasonable and appropriate. Simply declining to act without that analysis and documentation would not typically satisfy the requirement. Readers should verify which specifications are required versus addressable against the current regulation.
What kinds of measures typically fall under facility access controls?
Facility access controls generally encompass measures that limit physical access to facilities and equipment while ensuring authorized access is permitted. Commonly referenced implementation specifications address areas such as contingency operations (access during emergency or recovery situations), a facility security plan, access control and validation procedures for personnel and visitors, and maintenance records for physical security-related repairs and modifications. The specific specifications and their required/addressable status should be confirmed against the current Security Rule text.
How should we document our facility access control decisions?
Documentation typically includes the risk analysis or assessment supporting each decision, the safeguard chosen (or the alternative measure adopted), and, for addressable specifications, a written rationale explaining why a given measure is or is not reasonable and appropriate. Maintaining records of physical security modifications and periodic reviews is also generally advisable. Because retention and documentation expectations may be shaped by both HIPAA and applicable state law, readers should confirm current requirements against the regulation and relevant guidance.
Do facility access controls apply to business associates as well as covered entities?
Generally, the Security Rule's safeguard obligations, including physical safeguards such as facility access controls, apply to business associates directly and are also reflected in business associate agreements. A business associate that stores or accesses ePHI at its own facilities would typically need to address physical protection of those locations. The precise obligations flow through the applicable relationship and agreement; readers should confirm scope against the current regulation and the specific terms of their agreements.
How do facility access controls relate to remote work and cloud-hosted ePHI?
Facility access controls remain relevant even when ePHI is hosted remotely or accessed off-site, but the responsibility may be shared. For cloud-hosted environments, physical security of the data center is often the provider's responsibility as addressed through the business associate relationship, while the organization typically remains responsible for physical safeguards at its own locations and for workstations used to access ePHI. Remote and telework arrangements may raise additional considerations that HIPAA, the HITECH Act, or state law could affect; readers should verify current requirements and assess their specific environment.

Common misconceptions

Facility Access Controls covers all physical protection of PHI, including paper records in file rooms.
As part of the HIPAA Security Rule, this standard concerns the physical protection of electronic protected health information and the facilities and systems housing it. Physical protection of paper and other non-electronic PHI is generally addressed under the Privacy Rule's safeguard requirements rather than the Security Rule.
Because its implementation specifications are addressable, an organization can simply skip Facility Access Controls if it seems inconvenient.
Addressable does not mean optional. An organization must evaluate whether each specification is reasonable and appropriate for its environment and either implement it, implement a documented equivalent alternative, or document a justified decision not to implement it. Failing to address the standard at all is generally not compliant.
Meeting Facility Access Controls, or obtaining HITRUST certification that maps to it, guarantees HIPAA compliance and prevents physical breaches.
No single safeguard guarantees compliance or prevents all incidents. Facility Access Controls is one standard among many across the administrative, physical, and technical safeguard categories. HITRUST is a private organization and its CSF is a certifiable framework; certification does not by itself establish HIPAA compliance, which is enforced by HHS OCR.

Best practices

Conduct and document a risk analysis to determine which addressable implementation specifications for facility access are reasonable and appropriate, and record the rationale for any specification not implemented along with any equivalent alternative adopted.
Develop contingency operations procedures that allow only authorized personnel to access facilities during emergency or disaster recovery activities, and align them with your emergency mode operation and disaster recovery plans.
Maintain a facility security plan and role-based access control and validation procedures, including visitor controls and controls over access to systems used for testing and revision.
Keep maintenance records of security-related repairs and modifications to physical components such as locks, doors, and hardware, so changes are traceable.
Review and update facility access policies and procedures periodically and after significant changes to facilities, personnel, or the threat environment.
Verify all specifics against the current version of the HIPAA Security Rule, and remember that state law, the HITECH Act, or frameworks such as the HITRUST CSF may impose additional requirements beyond this standard.