Facility Security Plan
A Facility Security Plan is a written set of policies and procedures describing how an organization protects its physical buildings and equipment, and the electronic health information they contain, from unauthorized access, tampering, and theft. In the HIPAA context, it addresses things like who can enter a facility and how physical spaces housing systems are secured. Note that the general term 'Facility Security Plan' is also used in other regulatory settings (such as certain federal facilities and maritime security under 33 CFR Part 105) with different meanings; readers should distinguish those uses from the HIPAA physical safeguard.
Under the HIPAA Security Rule, a Facility Security Plan is generally understood as documented policies and procedures implementing the Facility Access Controls physical safeguard standard, which applies to the safeguarding of electronic protected health information (ePHI) and the facilities and equipment that house it. The Facility Security Plan is typically treated as an addressable implementation specification within that standard, meaning a covered entity or business associate must assess whether it is reasonable and appropriate to its environment and, if not implemented, document the rationale and any equivalent alternative measure; addressable does not mean optional. It commonly covers physical measures such as controlling and validating physical access to areas containing ePHI, protecting facilities and equipment from unauthorized physical access and tampering, and related access documentation. The precise regulatory text, the classification of this specification, and its interaction with the broader Facility Access Controls standard should be verified against the current Security Rule; because the Security Rule applies only to ePHI, physical protection of paper or other non-electronic PHI falls under the Privacy Rule instead. Terms of identical or similar name used in federal facility security guidance (e.g., CISA/ISC) or maritime security regulation (33 CFR Part 105) reflect separate legal frameworks and requirements distinct from HIPAA, and state law or the HITECH Act may impose additional obligations.
Why it matters
Physical access is one of the most direct routes to a data compromise: a person who can walk into a server room, workstation area, or storage location housing electronic protected health information (ePHI) may be able to view, alter, copy, or steal that information regardless of how strong the network defenses are. A Facility Security Plan gives an organization a documented, repeatable approach to controlling who enters sensitive spaces and how equipment is protected, which supports the Facility Access Controls physical safeguard standard under the HIPAA Security Rule.
Because the Facility Security Plan is generally treated as an addressable implementation specification, some organizations mistakenly assume it is optional. It is not. Addressable means the covered entity or business associate must assess whether the measure is reasonable and appropriate for its environment and, where it does not implement the specification as written, document the rationale and adopt an equivalent alternative where reasonable and appropriate. A missing or undocumented decision here is a common gap that surfaces during risk analysis and audits.
Readers should also be careful not to confuse the HIPAA physical safeguard with identically named requirements in other regulatory settings. A 'Facility Security Plan' under maritime security regulation (33 CFR Part 105) or under federal facility guidance from bodies such as CISA/the Interagency Security Committee reflects separate legal frameworks with their own required contents, approval, and audit obligations, and should not be treated as interchangeable with the HIPAA document. Because the Security Rule applies only to ePHI, physical protection of paper or other non-electronic PHI is addressed under the Privacy Rule instead, and state law or the HITECH Act may impose additional obligations.
Who it's relevant to
Inside FSP
Common questions
Answers to the questions practitioners most commonly ask about FSP.