45 CFR § 164.310(a)
Governs physical access to facilities that house systems containing ePHI. Covers contingency operations, facility security plans, access control and validation, and maintenance records for physical security measures.
Sample Preview
Version 1.0·Effective [EFFECTIVE DATE]·Approved by [PRIVACY/SECURITY OFFICER NAME]
This policy establishes physical safeguards to limit access to [PRACTICE NAME]'s facilities while ensuring that authorized workforce members and visitors can access the facility as needed. Physical security is the first line of defense for the hardware and systems that contain ePHI and the paper records that contain PHI.
This policy applies to all facilities owned, leased, or operated by [PRACTICE NAME] where ePHI is created, received, maintained, transmitted, or stored. This includes the primary office, any satellite locations, server rooms, file storage areas, and any area where workstations accessing ePHI are located. It applies to all workforce members, business associates, vendors, visitors, and maintenance personnel who enter these facilities.
[PRACTICE NAME] shall implement facility access controls to limit physical access to its electronic information systems and the facilities in which they are housed, while ensuring that properly authorized access is allowed, as required by 45 CFR § 164.310(a). The practice shall address contingency operations, facility security plans, access control and validation procedures, and maintenance records.
Restricted Area: Any area within the facility that contains ePHI systems, servers, network equipment, or paper records containing PHI. Access to restricted areas is limited to authorized workforce members.
Public Area: Areas of the facility accessible to patients and visitors, such as the waiting room and restrooms.
Visitor: Any person who is not a workforce member of [PRACTICE NAME], including patients, patient family members, vendors, maintenance personnel, and inspectors.
Access Control Mechanism: Any physical device or procedure used to control entry to a facility or area, such as locks, key cards, access codes, biometric scanners, or staffed reception desks.
while we’re in beta
A professional, CFR-referenced policy template, ready to customize for your practice. Free during the beta.
Free while we’re in beta
Need more than one?
The Complete HIPAA Policy Library — every policy, checklist, and review template. Free while we’re in beta.
Free while we’re in beta
Templates require customization and legal review before adoption. Not legal advice. See full disclaimer.