Skip to main content
Category: Physical and Technical Safeguards

Physical Access Controls

Also known as: PACS, Physical Access Control System, Physical Access Control, PACS
Simply put

Physical access controls are the systems, technologies, and policies that manage who is allowed to enter or move within a building, room, or secure area. In a healthcare compliance setting, they help limit physical access to the places where electronic protected health information (ePHI) and the equipment that stores it are kept. They generally work by authenticating a person's identity and then authorizing or denying entry at controlled access points.

Formal definition

Physical access controls are electronic and procedural measures that authenticate and authorize the entry of people (or vehicles) into protected physical areas, typically through access control points such as doors, gates, or turnstiles. Within the HIPAA Security Rule, physical measures that limit access to facilities and equipment fall under the physical safeguards category and relate to the Facility Access Controls standard at 45 CFR §164.310(a)(1). That standard is itself required, meaning covered entities and business associates must implement policies and procedures to limit physical access to their electronic information systems and the facilities housing them while ensuring properly authorized access is allowed. Its four listed implementation specifications, contingency operations, facility security plan, access control and validation procedures, and maintenance records, are all addressable rather than required. Addressable does not mean optional; a regulated entity must assess whether each specification is reasonable and appropriate in its environment and either implement it, implement an equivalent alternative, or document why it is not reasonable and appropriate. Note that the Security Rule addresses only ePHI, so physical protection of paper or oral PHI is governed by the Privacy Rule rather than these physical safeguards. Many commercial 'PACS' products describe general facility security functions that are broader than, and not synonymous with, HIPAA's specific regulatory requirements; readers should confirm current requirements against the applicable text at 45 CFR Part 164, Subpart C, and consider that state law or the HITECH Act may impose additional obligations.

Why it matters

Physical access controls are a foundational layer of protection for the places where electronic protected health information (ePHI) and the equipment that stores or processes it are kept. Even the strongest technical safeguards, encryption, access logging, network controls, can be undermined if an unauthorized person can walk into a server room, data closet, or workstation area unchallenged. Within the HIPAA Security Rule, limiting physical access to facilities and electronic information systems is addressed through the Facility Access Controls standard at 45 CFR §164.310(a)(1), which is itself a required standard. That means covered entities and business associates generally must have policies and procedures to limit physical access while still permitting properly authorized access.

Who it's relevant to

Security Officers and IT Teams
Those responsible for the HIPAA Security Rule must ensure physical safeguards protect facilities and equipment housing ePHI. Because the Facility Access Controls standard at 45 CFR §164.310(a)(1) is required, security officers should confirm that supporting policies and procedures are in place, and evaluate each of the four addressable implementation specifications, contingency operations, facility security plan, access control and validation procedures, and maintenance records, to determine whether each is reasonable and appropriate, or whether a documented alternative or justification is warranted.
Compliance and Privacy Officers
Compliance staff should recognize that the physical safeguards discussed here address ePHI under the Security Rule. Physical protection of paper or oral PHI is governed instead by the Privacy Rule, so a complete physical security program often needs to address both. Compliance officers should also note that state law or the HITECH Act may impose additional obligations beyond HIPAA.
Business Associates and Subcontractors
Business associates, and their subcontractors where applicable, are directly subject to the Security Rule and must implement physical safeguards for the ePHI they handle. Specific obligations often flow through business associate agreements, and these parties should confirm their facility access measures against the applicable requirements at 45 CFR Part 164, Subpart C.
Facilities and Physical Security Managers
Personnel who manage badge systems, locks, and building access should understand that many commercial 'PACS' products offer general facility security functions that are broader than, and not synonymous with, HIPAA's specific requirements. Deploying such a system does not by itself establish HIPAA compliance; readers should confirm current requirements against the applicable regulatory text.

Inside PACS

Physical Safeguards Category
Physical access controls fall within the physical safeguards category of the HIPAA Security Rule, which addresses the protection of electronic information systems, related buildings, and equipment from natural and environmental hazards and unauthorized physical intrusion. This category applies specifically to ePHI, not to PHI in oral or paper form (which the Privacy Rule addresses).
Facility Access Controls Standard
The Facility Access Controls standard is itself a required standard under the Security Rule's physical safeguards. While the standard must be addressed by covered entities and business associates, each of its underlying implementation specifications is designated as addressable.
Contingency Operations (Addressable)
An addressable implementation specification concerning procedures that allow facility access to support restoration of lost data under a disaster recovery or emergency mode operations plan when needed.
Facility Security Plan (Addressable)
An addressable implementation specification concerning policies and procedures to safeguard the facility and equipment from unauthorized physical access, tampering, and theft.
Access Control and Validation Procedures (Addressable)
An addressable implementation specification concerning procedures to control and validate a person's access to facilities based on their role or function, including visitor control and access to software programs for testing and revision.
Maintenance Records (Addressable)
An addressable implementation specification concerning policies and procedures to document repairs and modifications to the physical components of a facility related to security, such as hardware, walls, doors, and locks.
Addressable Does Not Mean Optional
For each addressable specification, the organization must assess whether it is a reasonable and appropriate safeguard in its environment. If so, it must be implemented; if not, the organization must document why and implement an equivalent alternative measure where reasonable and appropriate. This determination generally follows from the organization's risk analysis.

Common questions

Answers to the questions practitioners most commonly ask about PACS.

Are the implementation specifications under the Facility Access Controls standard required or addressable?
Under the Security Rule's Facility Access Controls standard, the listed implementation specifications, generally described as contingency operations, facility security plan, access control and validation procedures, and maintenance records, are each addressable rather than required. Addressable does not mean optional: a covered entity or business associate must assess whether each specification is reasonable and appropriate in its environment, and if not, must document that determination and implement an equivalent alternative measure where reasonable and appropriate. Readers should confirm the current regulatory text, as the standard is set out at 45 CFR §164.310(a).
Does 'addressable' at the specification level mean the physical access control safeguard as a whole is optional?
No. The Facility Access Controls standard itself is a required standard that regulated entities must satisfy, even though its underlying implementation specifications are addressable. In other words, an organization cannot skip physical access controls entirely; it must meet the standard, while retaining flexibility in how it implements the addressable specifications beneath it. Any decision not to implement an addressable specification as written must be documented along with the rationale and any alternative safeguards adopted.
How should an organization document its handling of the addressable specifications?
For each addressable implementation specification, organizations generally document their risk-based assessment of whether the specification is reasonable and appropriate for their environment. Where it is implemented, document how; where an alternative is used instead, document the equivalent measure and the reasoning; and where neither is implemented, document why that decision is reasonable given the organization's risk analysis. This documentation is typically retained as part of the broader Security Rule documentation and should be reviewed against the current regulation.
What types of physical measures typically support facility access controls?
Common measures include controlling and validating who may enter facilities and areas housing systems that store or process ePHI, procedures for restoring access during contingency operations, a facility security plan describing how equipment and premises are protected, and records documenting repairs and modifications to physical security components. The specific measures an organization selects should follow from its risk analysis, and physical controls generally work alongside administrative and technical safeguards rather than in isolation.
How do physical access controls relate to the Security Rule's other safeguard categories?
Facility Access Controls fall within the physical safeguards category of the Security Rule. Physical safeguards work together with administrative safeguards (such as workforce and access management policies) and technical safeguards (such as access control and audit controls at the system level). Because the Security Rule addresses only ePHI, physical protections for paper or other non-electronic PHI are generally governed by the Privacy Rule rather than these Security Rule provisions.
How does physical access control apply when systems containing ePHI are hosted with a vendor or in a data center?
When a third party such as a hosting provider or data center handles ePHI on behalf of a regulated entity, that vendor typically functions as a business associate, and the relevant obligations flow through a business associate agreement. Both parties generally remain responsible for physical safeguards appropriate to their roles. Organizations should confirm how physical access responsibilities are allocated in their agreements and verify the arrangement against the current regulatory requirements; note that HITRUST CSF certification, if used, may address related controls but does not by itself establish HIPAA compliance.

Common misconceptions

Physical access controls only concern locking doors and are less important than technical safeguards like encryption.
Physical safeguards are a distinct, mandatory category under the Security Rule alongside administrative and technical safeguards. They address the protection of information systems and equipment holding ePHI from unauthorized physical access, and are treated as part of an integrated safeguard framework rather than a lesser concern.
Because the Facility Access Controls implementation specifications are addressable, physical access controls are optional and can be skipped.
The Facility Access Controls standard itself is required and must be addressed. Addressable applies only to its underlying implementation specifications, and addressable does not mean optional; an organization must implement the specification if reasonable and appropriate, or document its rationale and adopt an equivalent alternative measure where reasonable and appropriate.
Meeting a certifiable control framework's physical security requirements automatically satisfies HIPAA's physical access control obligations.
Frameworks such as the HITRUST CSF are maintained by a private organization and are not themselves legal requirements; certification does not by itself establish HIPAA compliance. Organizations must still map their controls to the Security Rule and confirm requirements against the current regulation and, separately, the current framework version. State law or other requirements may impose additional obligations.

Best practices

Base decisions on each addressable implementation specification, contingency operations, facility security plan, access control and validation, and maintenance records, on a documented risk analysis, and record the rationale where you determine a specification is not reasonable and appropriate along with any equivalent alternative measure adopted.
Maintain written policies and procedures for validating and controlling personnel and visitor access to facilities and equipment that house ePHI, distinguishing access by role or function.
Document repairs and modifications to security-related physical components such as locks, doors, walls, and hardware to support the maintenance records specification.
Coordinate physical safeguards with administrative and technical safeguards so that facility access procedures align with the organization's broader Security Rule program rather than standing alone.
Establish and periodically test contingency and emergency-access procedures that permit facility access to support data restoration under a disaster recovery or emergency mode plan.
Verify your physical access control measures against the current text of the Security Rule and confirm any framework mappings against the current framework version, and check whether state law or other requirements impose additional obligations.