Physical Access Controls
Physical access controls are the systems, technologies, and policies that manage who is allowed to enter or move within a building, room, or secure area. In a healthcare compliance setting, they help limit physical access to the places where electronic protected health information (ePHI) and the equipment that stores it are kept. They generally work by authenticating a person's identity and then authorizing or denying entry at controlled access points.
Physical access controls are electronic and procedural measures that authenticate and authorize the entry of people (or vehicles) into protected physical areas, typically through access control points such as doors, gates, or turnstiles. Within the HIPAA Security Rule, physical measures that limit access to facilities and equipment fall under the physical safeguards category and relate to the Facility Access Controls standard at 45 CFR §164.310(a)(1). That standard is itself required, meaning covered entities and business associates must implement policies and procedures to limit physical access to their electronic information systems and the facilities housing them while ensuring properly authorized access is allowed. Its four listed implementation specifications, contingency operations, facility security plan, access control and validation procedures, and maintenance records, are all addressable rather than required. Addressable does not mean optional; a regulated entity must assess whether each specification is reasonable and appropriate in its environment and either implement it, implement an equivalent alternative, or document why it is not reasonable and appropriate. Note that the Security Rule addresses only ePHI, so physical protection of paper or oral PHI is governed by the Privacy Rule rather than these physical safeguards. Many commercial 'PACS' products describe general facility security functions that are broader than, and not synonymous with, HIPAA's specific regulatory requirements; readers should confirm current requirements against the applicable text at 45 CFR Part 164, Subpart C, and consider that state law or the HITECH Act may impose additional obligations.
Why it matters
Physical access controls are a foundational layer of protection for the places where electronic protected health information (ePHI) and the equipment that stores or processes it are kept. Even the strongest technical safeguards, encryption, access logging, network controls, can be undermined if an unauthorized person can walk into a server room, data closet, or workstation area unchallenged. Within the HIPAA Security Rule, limiting physical access to facilities and electronic information systems is addressed through the Facility Access Controls standard at 45 CFR §164.310(a)(1), which is itself a required standard. That means covered entities and business associates generally must have policies and procedures to limit physical access while still permitting properly authorized access.
Who it's relevant to
Inside PACS
Common questions
Answers to the questions practitioners most commonly ask about PACS.