Skip to main content
Category: Physical and Technical Safeguards

Workstation Security

Also known as: Workstation Use and Security, Endpoint Workstation Protection
Simply put

Workstation security refers to the measures and technologies used to protect individual end-user computers, such as desktops and laptops, from unauthorized access or use. In a healthcare compliance context, these measures help protect the electronic protected health information (ePHI) that can be accessed or displayed at a workstation. General approaches include controlling physical access to devices, positioning screens away from public view, and enforcing access controls, though specific requirements should be verified against the current regulatory text and organizational policy.

Formal definition

Under the HIPAA Security Rule, Workstation Security is a physical safeguard standard that generally requires covered entities and business associates to implement physical safeguards for all workstations that access ePHI, restricting access to authorized users. It is closely related to, but distinct from, the separate Workstation Use standard, which addresses the proper functions, manner of performance, and physical surroundings of workstations. Workstation Security should not be conflated with technical safeguards such as automatic log-off/screen-lock, access control, and audit controls, which HHS categorizes as technical (not physical) safeguards and which are addressed under separate Security Rule standards. Because the Security Rule governs only ePHI, workstation controls addressed here do not extend to PHI in purely oral or paper form, which fall under the Privacy Rule. Business associates and their subcontractors are directly liable for compliance with applicable Security Rule requirements, in addition to obligations set out in business associate agreements; contractual terms do not replace this direct regulatory liability. Note that the specific implementation specifications, required-versus-addressable designations, and CFR citations should be confirmed against the current regulation, and that the HITECH Act, state law, or frameworks such as the HITRUST CSF may impose additional or more granular requirements. HITRUST certification does not by itself establish HIPAA compliance.

Why it matters

Workstations are among the most common points at which ePHI is accessed, viewed, and entered, which makes them a frequent focus of unauthorized access and physical exposure risks. A desktop left unattended in a busy clinical corridor, a laptop positioned so that a screen faces a public waiting area, or a device that can be physically removed all represent avenues through which protected information can be exposed to individuals who are not authorized to see it. Because the HIPAA Security Rule addresses these risks specifically, workstation security is a compliance obligation and not merely an IT best practice.

Under the Security Rule, Workstation Security is a physical safeguard standard that generally requires covered entities and business associates to implement physical safeguards for all workstations that access ePHI, restricting access to authorized users. It is important to note that since the 2013 Omnibus Rule, business associates and their subcontractors are directly liable for compliance with applicable Security Rule requirements, independent of the terms in a business associate agreement; contractual language supplements, but does not replace, this direct regulatory liability.

Organizations should treat workstation security as one layer within a broader safeguard program rather than a standalone control that guarantees protection. No single measure prevents all breaches, and the Security Rule addresses ePHI only, so information in purely oral or paper form falls under the Privacy Rule instead. Readers should also be aware that the HITECH Act, state law, or frameworks such as the HITRUST CSF may impose additional or more granular requirements, and that HITRUST certification does not by itself establish HIPAA compliance.

Who it's relevant to

Security Officers
Individuals responsible for the Security Rule program use workstation security to help satisfy the physical safeguard standard for devices that access ePHI. They typically define policies for physical access control, screen positioning, and authorized-user restrictions, and must distinguish these physical measures from the technical safeguards (such as automatic log-off) addressed under separate standards.
Compliance Officers and Auditors
These professionals assess whether workstation controls are documented and implemented consistently with the Security Rule and organizational policy. They should confirm required-versus-addressable designations and CFR citations against the current regulation, and recognize that state law or the HITECH Act may impose additional requirements.
Business Associates and Subcontractors
Vendors and their subcontractors that access ePHI on workstations are directly liable for compliance with applicable Security Rule requirements, independent of the terms in their business associate agreements. Contractual obligations supplement but do not replace this direct regulatory liability.
IT and Endpoint Management Teams
Teams that deploy and maintain desktops, laptops, and other endpoints implement the physical and policy measures that protect workstations displaying or accessing ePHI. They should coordinate with security officers to align physical safeguards with the separate technical safeguards required elsewhere in the Security Rule, and verify configurations against organizational policy.

Inside Workstation Security

Workstation Use (Security Rule standard)
A physical safeguard standard under the HIPAA Security Rule that generally requires policies and procedures specifying the proper functions to be performed, the manner in which those functions are to be performed, and the physical attributes of the surroundings of workstations that can access ePHI. Readers should verify the exact standard against the current regulatory text.
Workstation Security (Security Rule standard)
A separate physical safeguard standard under the Security Rule that generally requires implementation of physical safeguards for all workstations that access ePHI, so as to restrict access to authorized users. This standard focuses on protecting the physical device and its environment rather than the software controls running on it.
Scope limited to ePHI
Because these are Security Rule standards, they apply only to electronic protected health information (ePHI). Paper records, oral disclosures, and other non-electronic PHI fall under the Privacy Rule and are outside the scope of workstation security requirements.
Physical vs. technical safeguards
Workstation Use and Workstation Security are physical safeguards addressing the placement, environment, and physical protection of devices. Related controls such as automatic log-off and screen locks are categorized by HHS as technical safeguards, so a complete workstation-protection approach typically draws on both categories.
Applicability to covered entities and business associates
Both covered entities and business associates (and their subcontractors) are generally subject to the Security Rule's workstation standards. Since the 2013 Omnibus Rule, business associates and subcontractors are directly liable for Security Rule compliance, independent of, and in addition to, any obligations set out in a business associate agreement.

Common questions

Answers to the questions practitioners most commonly ask about Workstation Security.

Are business associates only required to secure workstations because their business associate agreement says so?
No. Since the 2013 Omnibus Rule, business associates and their subcontractors are directly liable for compliance with the HIPAA Security Rule, including its workstation-related standards, independent of what any contract states. A business associate agreement documents and allocates responsibilities, but the underlying obligation to safeguard ePHI on workstations arises directly from the Security Rule as enforced by HHS OCR. Readers should verify the current regulatory text, as direct liability provisions and their scope may be refined over time.
Is an automatic screen lock considered a physical safeguard under the Security Rule?
No. Automatic log-off and screen-lock functions are generally categorized by HHS as a technical safeguard, not a physical safeguard. Workstation Security spans multiple safeguard categories: the Security Rule addresses Workstation Use and Workstation Security among the physical safeguards, while access controls such as automatic log-off fall under the technical safeguards. It is important not to conflate the physical placement and use of a workstation with the technical mechanisms that control access to it. Confirm categorizations against the current regulatory text.
What are typical physical safeguards a covered entity or business associate applies to workstations?
Physical safeguards for workstations generally focus on the location, use, and protection of the physical device and its surroundings. Common measures include positioning screens away from public view, restricting physical access to areas where workstations are used, securing devices against theft, and establishing policies governing appropriate workstation use. The Security Rule addresses these through its Workstation Use and Workstation Security standards. These measures are typically combined with technical and administrative safeguards rather than relied upon in isolation. Organizations should tailor measures based on their own risk analysis.
How should an organization decide which workstation controls to implement?
Workstation security decisions generally flow from the organization's risk analysis, which is a foundational requirement of the Security Rule. The analysis helps identify where ePHI is accessed, the associated threats and vulnerabilities, and reasonable and appropriate controls given the organization's size, complexity, and capabilities. Where an implementation specification is addressable rather than required, the organization must assess whether it is reasonable and appropriate; addressable does not mean optional, and any decision not to implement a specification typically must be documented along with an equivalent alternative or the rationale. Verify specific requirements against the current regulation.
Do workstation security requirements apply to remote and mobile devices?
In most cases, the workstation safeguards apply to any electronic computing device used to access ePHI, which can include laptops, tablets, and other portable devices depending on how the organization defines a workstation in its policies. Remote and mobile access typically introduces additional risks that an organization should address through its risk analysis, and additional controls such as encryption or access restrictions may be warranted. Note that state law, the HITECH Act, or other frameworks may impose further requirements beyond the HIPAA baseline. Organizations should verify how their environment maps to current guidance.
How does workstation security relate to a HITRUST CSF certification?
The HITRUST CSF is a certifiable control framework maintained by HITRUST, a private organization, and it includes controls that can map to workstation-related safeguards. However, achieving HITRUST certification is not a legal requirement and does not by itself establish HIPAA compliance. An organization may use the framework to help structure and demonstrate its controls, but its HIPAA obligations continue to arise from the regulation as enforced by HHS OCR. Readers should confirm control mappings against the current HITRUST CSF version and the current regulatory text.

Common misconceptions

Workstation Use and Workstation Security are the same requirement.
They are two distinct physical safeguard standards. Workstation Use generally addresses policies on proper functions and the manner and surroundings of workstation operation, while Workstation Security generally addresses the physical protections applied to the devices themselves. Readers should confirm the precise wording against the current regulatory text.
Business associates only have to secure workstations if their business associate agreement says so.
Since the 2013 Omnibus Rule, business associates and their subcontractors are directly liable for compliance with the HIPAA Security Rule, including its workstation standards, independent of contract terms. A business associate agreement documents responsibilities but is not the sole source of the obligation.
Automatic screen locks and log-off are workstation physical safeguards.
HHS categorizes automatic log-off and related access controls as technical safeguards, not physical safeguards. Effective workstation protection typically combines physical safeguards (device placement and physical restriction) with these technical safeguards, but they should not be conflated.

Best practices

Maintain separate, documented policies and procedures for Workstation Use and Workstation Security so that both the proper-functions/environment standard and the physical-protection standard are addressed.
Position and physically restrict workstations that access ePHI so that access is limited to authorized users, considering screen visibility, device location, and the surrounding environment.
Coordinate physical workstation safeguards with technical safeguards such as automatic log-off and screen locks, recognizing that HHS treats those as technical rather than physical controls.
Ensure business associates and subcontractors understand they are directly responsible for Security Rule workstation obligations, and reflect these expectations in business associate agreements without relying on the agreement alone.
Limit workstation security controls to their appropriate scope by remembering that these Security Rule standards apply to ePHI; handle paper and oral PHI under Privacy Rule policies.
Periodically review and verify workstation policies against the current Security Rule text and current guidance, and check whether state law or the HITECH Act imposes additional requirements beyond HIPAA.