Skip to main content
Category: Physical and Technical Safeguards

Physical Safeguards

Also known as: HIPAA Physical Safeguards
Simply put

Physical safeguards are the physical measures, policies, and procedures used to protect a healthcare organization's electronic information systems, along with the buildings and equipment that house them, from unauthorized access and environmental hazards. They are one of the three safeguard categories under the HIPAA Security Rule, alongside administrative and technical safeguards. Examples generally include controlling who can physically enter facilities and secure areas where electronic protected health information (ePHI) is stored.

Formal definition

Under the HIPAA Security Rule, physical safeguards are defined as physical measures, policies, and procedures to protect a covered entity's or business associate's electronic information systems and related buildings and equipment from natural and environmental hazards and unauthorized intrusion. This is one of three safeguard categories in the Security Rule (administrative, physical, and technical) and applies only to electronic protected health information (ePHI), not to PHI in oral or paper form, which falls under the Privacy Rule. Physical safeguard standards generally address areas such as facility access controls (implementing policies and procedures to limit physical access to electronic information systems and the facilities housing them while ensuring authorized access is permitted), workstation use and security, and device and media controls. As with other Security Rule standards, physical safeguards consist of implementation specifications that are designated as either required or addressable; addressable does not mean optional, but rather that a regulated entity must assess whether a specification is reasonable and appropriate in its environment and, if not, implement an equivalent alternative or document why it is not applicable. Specific standards, implementation specifications, and CFR citations should be verified against the current text of the Security Rule.

Why it matters

Physical safeguards address a category of risk that technical controls alone cannot cover: the tangible reality that electronic information systems live in buildings, on servers, in workstations, and on portable media that can be physically accessed, stolen, or damaged. Even a well-encrypted network can be undermined if an unauthorized person can walk into a server room, remove a hard drive, or view an unattended workstation displaying ePHI. Because the HIPAA Security Rule requires regulated entities to protect the confidentiality, integrity, and availability of ePHI, physical safeguards form an essential layer alongside administrative and technical safeguards.

For covered entities and business associates, physical safeguards are not a matter of best practice alone but of regulatory obligation under the Security Rule, enforced by HHS OCR. The Rule frames these as physical measures, policies, and procedures that protect electronic information systems and the buildings and equipment that house them from both unauthorized intrusion and natural or environmental hazards. Neglecting these controls can expose an organization to compliance risk and, in the event of a physical loss or theft of a device containing ePHI, potentially to breach notification obligations.

It is important to note that physical safeguards under the Security Rule apply only to ePHI. The physical protection of PHI in paper or oral form is addressed under the HIPAA Privacy Rule, not the Security Rule's physical safeguard standards. Organizations should treat these as distinct but complementary obligations, and should also be aware that state law or the HITECH Act may impose additional requirements beyond the baseline described here.

Who it's relevant to

Security Officers and Compliance Teams
Those responsible for HIPAA Security Rule compliance must ensure physical safeguards are implemented and documented alongside administrative and technical safeguards. This includes evaluating addressable implementation specifications and recording decisions where an alternative measure is used or a specification is deemed not applicable.
Covered Entities and Business Associates
The Security Rule's physical safeguard obligations apply to both covered entities and business associates that create, receive, maintain, or transmit ePHI. Business associates should confirm how these obligations are reflected in their business associate agreements and applied to the facilities and equipment under their control.
IT and Facilities Personnel
Staff managing data centers, server rooms, workstations, and portable media are central to implementing facility access controls, workstation security, and device and media controls. They translate policy requirements into the day-to-day physical measures that protect electronic information systems from unauthorized access and environmental hazards.
Auditors and Assessors
Professionals evaluating an organization's HIPAA posture review whether physical safeguards are in place and appropriately documented. They should verify findings against the current Security Rule text and note that frameworks such as the HITRUST CSF may map to these controls but do not by themselves establish HIPAA compliance.

Inside Physical Safeguards

Facility Access Controls
A standard requiring policies and procedures to limit physical access to electronic information systems and the facilities in which they are housed, while ensuring properly authorized access is allowed. Its implementation specifications (such as contingency operations, a facility security plan, access control and validation procedures, and maintenance records) are all addressable, meaning they must be assessed and either implemented or documented with an equivalent alternative or justification.
Workstation Use
A required standard directing covered entities and business associates to specify the proper functions to be performed, the manner in which they are performed, and the physical attributes of the surroundings of workstations that can access ePHI.
Workstation Security
A required standard directing implementation of physical safeguards for all workstations that access ePHI, in order to restrict access to authorized users.
Device and Media Controls
A standard governing the receipt and removal of hardware and electronic media containing ePHI into, out of, and within a facility. It includes required implementation specifications for disposal and media re-use, and addressable specifications for accountability (tracking movement) and data backup and storage.
Scope Limitation
Physical Safeguards are one of the three safeguard categories under the HIPAA Security Rule (alongside administrative and technical safeguards) and apply only to electronic protected health information (ePHI). They do not govern PHI in oral or paper form, which falls under the Privacy Rule.

Common questions

Answers to the questions practitioners most commonly ask about Physical Safeguards.

Are physical safeguards only about locking doors and securing the building?
No. While facility access controls are one component, physical safeguards under the HIPAA Security Rule are broader. They generally address facility access controls, workstation use, workstation security, and device and media controls. This includes governing how workstations that access ePHI are positioned and used, and how electronic media and devices are handled, reused, and disposed of. Reducing physical safeguards to door locks overlooks these workstation and media-related requirements.
Do physical safeguards apply to protected health information in all forms, including paper records?
Not under the Security Rule. Physical safeguards are a category within the HIPAA Security Rule, which governs only electronic protected health information (ePHI). They protect the physical infrastructure and equipment that store or access ePHI. Protection of paper and oral PHI is addressed under the HIPAA Privacy Rule rather than the Security Rule's physical safeguards. Organizations often address both, but the regulatory basis differs, and readers should not conflate the two rules.
How do we decide what to implement for the addressable implementation specifications within physical safeguards?
Addressable does not mean optional. Generally, a covered entity or business associate assesses whether a given addressable specification is reasonable and appropriate in its environment. If it is, the organization implements it. If it is not, the organization typically documents why, and implements an equivalent alternative measure where reasonable and appropriate. This analysis should be documented and revisited over time. Confirm the specific required versus addressable designations against the current regulatory text.
How should physical safeguards address disposal of old devices and media that held ePHI?
Device and media controls generally cover the disposal and reuse of electronic media, as well as the removal of ePHI before media are made available for reuse. In practice, organizations typically establish documented procedures for sanitizing or destroying media so ePHI is not recoverable, and may maintain records of media movement. The goal is to ensure ePHI does not remain accessible on discarded or repurposed hardware.
What should we consider for workstations that access ePHI in shared or public-facing areas?
Workstation use and workstation security specifications generally address the proper functions to be performed on workstations that access ePHI, the manner in which they are performed, and the physical attributes of the surroundings. In most cases this involves considering positioning, screen visibility, and physical access restrictions so that ePHI is not exposed to unauthorized individuals in shared or public areas. The specific measures depend on the organization's environment and risk analysis.
How do physical safeguards apply to remote workers and workstations located outside the main facility?
Physical safeguards generally extend to any workstation or device used to access ePHI, which can include those in remote or home settings. Organizations typically consider how workstation use, workstation security, and device and media controls apply to off-site locations as part of their risk analysis. The reasonable and appropriate measures may differ from those in a controlled facility, and this should be evaluated and documented against current requirements.
Does implementing physical safeguards satisfy the whole HIPAA Security Rule?
No. Physical safeguards are one of three safeguard categories in the Security Rule, alongside administrative safeguards and technical safeguards. Addressing physical safeguards alone does not establish compliance with the full Security Rule, and the Security Rule itself is only part of broader HIPAA obligations. Note also that state law and the HITECH Act may impose additional requirements, and readers should verify specifics against current guidance.

Common misconceptions

Addressable physical safeguard specifications, such as facility access control procedures, are optional and can be skipped.
Addressable does not mean optional. A covered entity or business associate must assess whether the specification is reasonable and appropriate in its environment, and then either implement it, implement an equivalent alternative measure, or document why it is not reasonable and appropriate. The decision and rationale generally must be documented.
Physical Safeguards cover all forms of protected health information, including paper records and spoken information.
The Security Rule, including its Physical Safeguards, applies only to ePHI. Protection of paper and oral PHI is generally addressed under the HIPAA Privacy Rule, though physical measures like locking file rooms may support Privacy Rule obligations.
Achieving a physical security certification, such as HITRUST CSF certification, satisfies the HIPAA Physical Safeguards requirements.
HITRUST is a private organization and the HITRUST CSF is a certifiable framework that may help demonstrate control coverage, but certification is not a legal requirement and does not by itself establish HIPAA compliance. HIPAA is enforced by HHS OCR, and obligations must be met against the current regulatory text regardless of any private certification.

Best practices

Conduct and document a risk analysis to determine which addressable physical safeguard specifications are reasonable and appropriate for your environment, and record the rationale for any alternative or non-implementation decisions.
Establish and enforce facility access controls that limit physical entry to systems housing ePHI, including validation procedures for visitors, vendors, and maintenance personnel.
Implement disposal and media re-use procedures so that ePHI is rendered unrecoverable before hardware or electronic media are discarded, repurposed, or transferred.
Maintain accountability records that track the movement of hardware and electronic media containing ePHI into, out of, and within the facility, along with the persons responsible.
Define workstation use and workstation security policies that specify proper functions, physical placement, and protective measures for any device that can access ePHI.
Review physical safeguard policies and documentation periodically and after significant environmental changes, verifying alignment with the current HIPAA Security Rule text and noting where state law or the HITECH Act may impose additional requirements.