Facility Access Controls
Facility access controls are the policies and procedures an organization uses to limit and monitor who can physically enter its buildings and the areas where electronic health information and the systems that hold it are located. In the context of HIPAA, this is one of the required physical safeguards under the Security Rule, and it helps ensure that only authorized people can reach sensitive equipment and records. It generally combines physical measures, such as locks, badges, or biometric readers, with written procedures for granting, tracking, and revoking access.
Under the HIPAA Security Rule, Facility Access Controls are a physical safeguard standard requiring covered entities and business associates to implement policies and procedures that limit physical access to their electronic information systems and the facilities in which they are housed, while ensuring that properly authorized access is allowed. The standard is generally associated with several implementation specifications addressing matters such as contingency operations, a facility security plan, access control and validation procedures, and maintenance records; readers should confirm the exact implementation specifications and their required or addressable designations against the current regulatory text at 45 CFR Part 164. Note that addressable implementation specifications are not optional: an entity must implement the specification, adopt a reasonable and appropriate alternative, or document why the specification is not reasonable and appropriate. This standard governs physical access to systems handling electronic protected health information (ePHI); it is distinct from technical access controls (which restrict logical access within information systems) and from the broader Privacy Rule protections that apply to PHI in all forms. State law, the HITECH Act, or frameworks such as the HITRUST CSF may impose additional or more specific physical security requirements, and HITRUST certification does not by itself establish HIPAA compliance.
Why it matters
Physical access to the places where systems and equipment reside is often the first line of defense for electronic protected health information (ePHI). Even the strongest technical controls, such as encryption and logical access restrictions, can be undermined if an unauthorized person can walk up to a server, workstation, or storage device. Facility access controls address this gap by limiting and monitoring who can physically enter buildings and the specific areas where ePHI and the systems that hold it are located.
Under the HIPAA Security Rule, Facility Access Controls are a required physical safeguard standard, meaning covered entities and business associates must implement policies and procedures in this area rather than treating it as optional. The standard is generally associated with several implementation specifications, and because some implementation specifications are designated addressable, entities should be careful not to interpret addressable as optional. An addressable specification must still be implemented, satisfied through a reasonable and appropriate alternative, or formally documented as not reasonable and appropriate for that organization.
Facility access controls also intersect with broader risk management. Physical measures such as locks, badges, and biometric readers work in combination with written procedures for granting, tracking, and revoking access, so that access aligns with authorization over time. Because no single measure guarantees compliance or prevents all incidents, organizations typically treat facility access controls as one layer within a larger security program, and should verify the exact required and addressable designations against the current regulatory text at 45 CFR Part 164.
Who it's relevant to
Inside Facility Access Controls
Common questions
Answers to the questions practitioners most commonly ask about Facility Access Controls.