45 CFR § 164.310(b)–(c)
Specifies the proper use of and physical safeguards for workstations that access ePHI. Covers screen positioning, auto-lock requirements, clean desk procedures, and restrictions on workstation functions to minimize risk of unauthorized access.
Sample Preview
Version 1.0·Effective [EFFECTIVE DATE]·Approved by [PRIVACY/SECURITY OFFICER NAME]
This policy specifies the proper functions and physical attributes of the electronic workstations at [PRACTICE NAME] that access ePHI, and the manner in which those workstations must be physically protected. Workstations are a primary access point for ePHI and must be secured against unauthorized access, both physical and visual.
This policy applies to all electronic computing devices used to access, process, or transmit ePHI, including desktop computers, laptops, tablets, thin clients, and any other device that functions as a workstation. It applies to devices owned by [PRACTICE NAME] and, where permitted, personal devices used to access ePHI (if a BYOD policy is in effect). All workforce members who use workstations are covered by this policy.
[PRACTICE NAME] shall specify the proper functions to be performed by electronic computing devices and the manner in which those functions shall be performed, as required by 45 CFR § 164.310(b). Additionally, physical safeguards shall be implemented for all workstations that access ePHI to restrict access to authorized users, as required by 45 CFR § 164.310(c).
Workstation: An electronic computing device — for example, a laptop or desktop computer, or any other device that performs similar functions — and electronic media stored in its immediate environment. This includes the device itself, attached peripherals, and any removable media connected to it.
ePHI System: Any application or service that stores, processes, or transmits ePHI, such as the EHR, practice management system, patient portal, or encrypted email.
Clean Desk: A practice whereby all sensitive information, including printed PHI, is secured or removed from the desk and surrounding area when the workstation is unattended.
while we’re in beta
A professional, CFR-referenced policy template, ready to customize for your practice. Free during the beta.
Free while we’re in beta
Need more than one?
The Complete HIPAA Policy Library — every policy, checklist, and review template. Free while we’re in beta.
Free while we’re in beta
Templates require customization and legal review before adoption. Not legal advice. See full disclaimer.