Physical Safeguards
Physical safeguards are the physical measures, policies, and procedures used to protect a healthcare organization's electronic information systems, along with the buildings and equipment that house them, from unauthorized access and environmental hazards. They are one of the three safeguard categories under the HIPAA Security Rule, alongside administrative and technical safeguards. Examples generally include controlling who can physically enter facilities and secure areas where electronic protected health information (ePHI) is stored.
Under the HIPAA Security Rule, physical safeguards are defined as physical measures, policies, and procedures to protect a covered entity's or business associate's electronic information systems and related buildings and equipment from natural and environmental hazards and unauthorized intrusion. This is one of three safeguard categories in the Security Rule (administrative, physical, and technical) and applies only to electronic protected health information (ePHI), not to PHI in oral or paper form, which falls under the Privacy Rule. Physical safeguard standards generally address areas such as facility access controls (implementing policies and procedures to limit physical access to electronic information systems and the facilities housing them while ensuring authorized access is permitted), workstation use and security, and device and media controls. As with other Security Rule standards, physical safeguards consist of implementation specifications that are designated as either required or addressable; addressable does not mean optional, but rather that a regulated entity must assess whether a specification is reasonable and appropriate in its environment and, if not, implement an equivalent alternative or document why it is not applicable. Specific standards, implementation specifications, and CFR citations should be verified against the current text of the Security Rule.
Why it matters
Physical safeguards address a category of risk that technical controls alone cannot cover: the tangible reality that electronic information systems live in buildings, on servers, in workstations, and on portable media that can be physically accessed, stolen, or damaged. Even a well-encrypted network can be undermined if an unauthorized person can walk into a server room, remove a hard drive, or view an unattended workstation displaying ePHI. Because the HIPAA Security Rule requires regulated entities to protect the confidentiality, integrity, and availability of ePHI, physical safeguards form an essential layer alongside administrative and technical safeguards.
For covered entities and business associates, physical safeguards are not a matter of best practice alone but of regulatory obligation under the Security Rule, enforced by HHS OCR. The Rule frames these as physical measures, policies, and procedures that protect electronic information systems and the buildings and equipment that house them from both unauthorized intrusion and natural or environmental hazards. Neglecting these controls can expose an organization to compliance risk and, in the event of a physical loss or theft of a device containing ePHI, potentially to breach notification obligations.
It is important to note that physical safeguards under the Security Rule apply only to ePHI. The physical protection of PHI in paper or oral form is addressed under the HIPAA Privacy Rule, not the Security Rule's physical safeguard standards. Organizations should treat these as distinct but complementary obligations, and should also be aware that state law or the HITECH Act may impose additional requirements beyond the baseline described here.
Who it's relevant to
Inside Physical Safeguards
Common questions
Answers to the questions practitioners most commonly ask about Physical Safeguards.