Physical safeguards are the HIPAA Security Rule controls over buildings, workstations and hardware. Cloud hosting changes who performs them, not whether they apply.
The short answer
Physical safeguards are the four Security Rule standards covering the physical environment around ePHI: facility access controls, workstation use, workstation security, and device and media controls. They cover who can walk up to a machine, how screens and laptops are handled, and what happens to a disk before it leaves the building.
The common misconception is that a cloud-native company has no physical safeguards to worry about. The data centre obligations transfer to your provider under a BAA. The laptop in a co-working space remains entirely yours.
On this page
The four standards
| Standard | Covers |
|---|---|
| Facility access controls | Contingency operations, a facility security plan, access control and validation, maintenance records. All addressable |
| Workstation use | Policies on what may be done at a workstation with ePHI access, and in what physical surroundings. Required |
| Workstation security | Physical controls restricting who can reach a workstation. Required |
| Device and media controls | Disposal and media re-use are required; accountability tracking and data backup before a move are addressable |
What the cloud does and does not cover
Remote and hybrid teams
Workstation use and workstation security were written with clinic desktops in mind. Applied to a distributed engineering team they translate into a small set of practical rules.
| Requirement | What it looks like remotely |
|---|---|
| Restrict physical access to workstations | Full-disk encryption, automatic screen lock, no shared home machines |
| Control the surroundings ePHI is viewed in | Policy on working in public spaces, privacy screens where relevant |
| Know which devices hold ePHI | A device inventory that is current, not a spreadsheet from last year |
| Control removable media | USB storage blocked or governed by policy and logged |
Lost laptops still drive breach reports
A missing encrypted laptop is usually not a reportable breach. A missing unencrypted one usually is. That single control is the difference between an asset loss and a notification exercise under the Breach Notification Rule.
Device and media disposal
Disposal
Required. Final disposition of ePHI and the hardware it lived on, documented.
Media re-use
Required. ePHI removed before hardware is reassigned or resold.
Accountability
Addressable. A record of hardware movements and who is responsible for each device.
How Osto covers the endpoint side
The physical safeguards you cannot delegate are the ones sitting on employee devices. Osto’s endpoint and device control maintains the inventory, enforces encryption and screen lock, governs removable media, and supports remote wipe when a device is lost or an employee leaves. File access DLP limits what can be copied off in the first place, and evidence maps to the HIPAA safeguards in the compliance platform.
Free security assessment
The safeguards your cloud provider cannot cover
Device inventory, encryption enforcement, removable media control and remote wipe on the endpoints you actually own.
Get a free security assessment Book a platform walkthroughmacOS agent · Device control and DLP · One platform, everything
Frequently asked questions
What are physical safeguards under HIPAA?
The four Security Rule standards covering the physical environment around ePHI: facility access controls, workstation use, workstation security, and device and media controls.
Do physical safeguards apply to cloud-only companies?
Yes. Data centre obligations shift to the cloud provider as a business associate under a BAA, but workstation policy, device inventory, removable media and disposal remain yours.
How do physical safeguards work for remote teams?
Through device controls rather than building controls: full-disk encryption, automatic lock, current inventory, restrictions on removable media, and a policy on where ePHI may be viewed.
What does the disposal requirement cover?
Documented final disposition of ePHI and the hardware holding it. Wiping a laptop before resale and secure destruction of failed drives both fall under it, and both are required rather than addressable.
Is a device inventory required?
Accountability tracking is addressable, so a formal inventory is not strictly mandatory. In practice you cannot demonstrate the required disposal and re-use controls without knowing which devices exist.

