Skip to main content
Category: Physical and Technical Safeguards

Facility Security Plan

Also known as: FSP, Facility Security Policies and Procedures
Simply put

A Facility Security Plan is a written set of policies and procedures describing how an organization protects its physical buildings and equipment, and the electronic health information they contain, from unauthorized access, tampering, and theft. In the HIPAA context, it addresses things like who can enter a facility and how physical spaces housing systems are secured. Note that the general term 'Facility Security Plan' is also used in other regulatory settings (such as certain federal facilities and maritime security under 33 CFR Part 105) with different meanings; readers should distinguish those uses from the HIPAA physical safeguard.

Formal definition

Under the HIPAA Security Rule, a Facility Security Plan is generally understood as documented policies and procedures implementing the Facility Access Controls physical safeguard standard, which applies to the safeguarding of electronic protected health information (ePHI) and the facilities and equipment that house it. The Facility Security Plan is typically treated as an addressable implementation specification within that standard, meaning a covered entity or business associate must assess whether it is reasonable and appropriate to its environment and, if not implemented, document the rationale and any equivalent alternative measure; addressable does not mean optional. It commonly covers physical measures such as controlling and validating physical access to areas containing ePHI, protecting facilities and equipment from unauthorized physical access and tampering, and related access documentation. The precise regulatory text, the classification of this specification, and its interaction with the broader Facility Access Controls standard should be verified against the current Security Rule; because the Security Rule applies only to ePHI, physical protection of paper or other non-electronic PHI falls under the Privacy Rule instead. Terms of identical or similar name used in federal facility security guidance (e.g., CISA/ISC) or maritime security regulation (33 CFR Part 105) reflect separate legal frameworks and requirements distinct from HIPAA, and state law or the HITECH Act may impose additional obligations.

Why it matters

Physical access is one of the most direct routes to a data compromise: a person who can walk into a server room, workstation area, or storage location housing electronic protected health information (ePHI) may be able to view, alter, copy, or steal that information regardless of how strong the network defenses are. A Facility Security Plan gives an organization a documented, repeatable approach to controlling who enters sensitive spaces and how equipment is protected, which supports the Facility Access Controls physical safeguard standard under the HIPAA Security Rule.

Because the Facility Security Plan is generally treated as an addressable implementation specification, some organizations mistakenly assume it is optional. It is not. Addressable means the covered entity or business associate must assess whether the measure is reasonable and appropriate for its environment and, where it does not implement the specification as written, document the rationale and adopt an equivalent alternative where reasonable and appropriate. A missing or undocumented decision here is a common gap that surfaces during risk analysis and audits.

Readers should also be careful not to confuse the HIPAA physical safeguard with identically named requirements in other regulatory settings. A 'Facility Security Plan' under maritime security regulation (33 CFR Part 105) or under federal facility guidance from bodies such as CISA/the Interagency Security Committee reflects separate legal frameworks with their own required contents, approval, and audit obligations, and should not be treated as interchangeable with the HIPAA document. Because the Security Rule applies only to ePHI, physical protection of paper or other non-electronic PHI is addressed under the Privacy Rule instead, and state law or the HITECH Act may impose additional obligations.

Who it's relevant to

Security Officers and Compliance Officers
Those responsible for a HIPAA security program need to ensure a Facility Security Plan exists, is grounded in the organization's risk analysis, and documents the reasonableness assessment for addressable specifications, including the rationale and any equivalent alternative measures where the specification is not implemented as written.
Covered Entities and Business Associates
Both covered entities and business associates are subject to the Security Rule's physical safeguards for the facilities and equipment that house ePHI. Business associates should confirm that their physical protections align with obligations that may flow through their business associate agreements, in addition to the Security Rule itself.
Facilities and Physical Security Teams
Staff managing building access, server rooms, and equipment implement the day-to-day controls the plan describes, such as validating entry to areas containing ePHI systems and protecting equipment from tampering or theft. They should coordinate with security and compliance staff to keep the written plan aligned with actual practice.
Auditors and Assessors
Those evaluating HIPAA compliance review whether the Facility Security Plan is documented, whether addressable decisions are supported by written rationale, and how it fits within the broader Facility Access Controls standard. Assessors should verify findings against the current Security Rule text, since classification and requirements are subject to change.
Legal and Regulatory Professionals
Counsel advising healthcare organizations should distinguish the HIPAA physical safeguard from identically named plans under other regimes (such as 33 CFR Part 105 or federal facility guidance), and should account for additional obligations that may arise under state law or the HITECH Act, as well as the Privacy Rule's coverage of non-electronic PHI.

Inside FSP

Physical Access Controls
Measures that limit physical entry to facilities housing electronic protected health information (ePHI) and the systems that store or process it, ensuring only authorized personnel gain access while still permitting properly authorized access.
Contingency Operations Provisions
Documented procedures allowing facility access in support of restoration of lost data under a disaster recovery plan and emergency mode operations plan, so that data recovery efforts can proceed during an emergency.
Facility Security Safeguards
Policies and procedures to safeguard the facility and its equipment from unauthorized physical access, tampering, and theft, addressing the physical protection of the environment where ePHI resides.
Access Control and Validation Procedures
Procedures to control and validate a person's access to facilities based on their role or function, including visitor control and control of access to software programs for testing and revision.
Maintenance Records
Documentation of repairs and modifications to the physical components of a facility that relate to security, such as changes to hardware, walls, doors, and locks.
Relationship to the Facility Access Controls Standard
As part of the Security Rule's physical safeguards, the Facility Security Plan is one of the addressable implementation specifications under the Facility Access Controls standard, which applies specifically to ePHI rather than PHI in all forms.

Common questions

Answers to the questions practitioners most commonly ask about FSP.

Does the Facility Security Plan cover the security of electronic data and networks?
No, not directly. The Facility Security Plan is a physical safeguard under the HIPAA Security Rule, and it addresses the protection of physical facilities and equipment from unauthorized physical access, tampering, and theft. Protecting ePHI within networks and systems is generally handled through technical safeguards such as access controls and transmission security. The Facility Security Plan complements those measures by securing the physical environment where systems housing ePHI reside, but it is not itself a technical control. Readers should confirm the specific safeguard categories against the current regulatory text.
Since the Facility Security Plan is an addressable implementation specification, can a covered entity simply skip it?
No. Addressable does not mean optional. Under the HIPAA Security Rule, an addressable implementation specification generally requires an entity to assess whether the specification is reasonable and appropriate in its environment, and to either implement it, implement an equivalent alternative measure, or document why it is not reasonable and appropriate. The Facility Security Plan is one of the addressable specifications within the Facility Access Controls standard, so a covered entity or business associate must still evaluate and document its approach rather than ignore it. Entities should verify the current classification against the applicable regulatory text.
Who is responsible for developing and maintaining the Facility Security Plan?
Responsibility typically rests with the entity's designated security officer, often in coordination with facilities management, physical security staff, and IT personnel. Because the Facility Security Plan involves both physical premises and the systems housing ePHI, effective plans generally reflect collaboration across these functions. Both covered entities and business associates that maintain facilities housing ePHI are generally expected to address this specification. Roles should be documented in accordance with the entity's overall security management process.
What elements are commonly included in a Facility Security Plan?
A Facility Security Plan generally documents the safeguards used to protect the facility and equipment from unauthorized physical access, tampering, and theft. Commonly addressed elements may include locks and physical barriers, alarm and monitoring systems, visitor and access management, protection of equipment and media, and procedures for maintaining and updating these safeguards. The specific measures depend on the entity's risk analysis and environment. Entities should confirm expectations against the current regulatory text and consider that state law or other frameworks may impose additional requirements.
How does the Facility Security Plan relate to the entity's risk analysis?
The Facility Security Plan is generally informed by the entity's risk analysis, which identifies physical threats and vulnerabilities to facilities and equipment housing ePHI. The measures selected typically reflect the risks identified and the entity's assessment of what is reasonable and appropriate given its size, complexity, and resources. Because addressable specifications call for a documented assessment, the risk analysis often supports and justifies the approach taken in the Facility Security Plan.
How often should the Facility Security Plan be reviewed or updated?
The HIPAA Security Rule generally emphasizes periodic review and updating of security measures in response to environmental or operational changes, though it does not always prescribe a fixed interval for a specific plan. In practice, many entities review the Facility Security Plan periodically and after significant changes such as relocations, facility modifications, new equipment, or findings from a risk analysis. Entities should align review frequency with their overall security management process and verify any specific expectations against current guidance.

Common misconceptions

Because the Facility Security Plan is an addressable implementation specification, organizations can simply skip it.
Addressable does not mean optional. Under the Security Rule, a covered entity or business associate must assess whether the specification is reasonable and appropriate for its environment, and if not, implement an equivalent alternative measure or document why it is not reasonable and appropriate. The decision and its rationale should generally be documented and verified against the current regulatory text.
A Facility Security Plan protects all forms of protected health information.
As a physical safeguard under the HIPAA Security Rule, the Facility Security Plan concerns the physical environment supporting electronic protected health information (ePHI). Protection of PHI in oral and paper forms is addressed by the Privacy Rule and other safeguards, which fall outside the scope of this specification.
Having a Facility Security Plan or achieving a related certification guarantees HIPAA compliance and prevents physical breaches.
No single measure guarantees compliance or prevents all incidents. A Facility Security Plan is one component of the physical safeguards and must work alongside administrative and technical safeguards. Certification frameworks such as the HITRUST CSF are private and do not by themselves establish HIPAA compliance; enforcement authority for HIPAA rests with HHS OCR.

Best practices

Document the Facility Security Plan in writing and record the reasonable-and-appropriate determination for this addressable specification, including any equivalent alternative measures adopted.
Coordinate the plan with contingency operations, ensuring facility access procedures align with the disaster recovery and emergency mode operations plans for data restoration.
Implement access control and validation procedures that tie physical access to role or function, and include visitor control provisions.
Maintain records of security-related repairs and modifications to physical components such as locks, doors, and hardware.
Periodically review and update the plan to reflect changes in the facility, equipment, and threat environment, and confirm alignment with the current Security Rule requirements.
Verify specific requirements, citations, and any related framework version details against the current regulation and, where applicable, the current HITRUST CSF version, noting that state law or the HITECH Act may impose additional obligations.