Physical Safeguards: Beyond the Data Centre

Physical safeguards under HIPAA for cloud and remote teams

Physical safeguards are the HIPAA Security Rule controls over buildings, workstations and hardware. Cloud hosting changes who performs them, not whether they apply.

  • Glossary
  • HIPAA

The short answer

Physical safeguards are the four Security Rule standards covering the physical environment around ePHI: facility access controls, workstation use, workstation security, and device and media controls. They cover who can walk up to a machine, how screens and laptops are handled, and what happens to a disk before it leaves the building.

The common misconception is that a cloud-native company has no physical safeguards to worry about. The data centre obligations transfer to your provider under a BAA. The laptop in a co-working space remains entirely yours.

The four standards

StandardCovers
Facility access controlsContingency operations, a facility security plan, access control and validation, maintenance records. All addressable
Workstation usePolicies on what may be done at a workstation with ePHI access, and in what physical surroundings. Required
Workstation securityPhysical controls restricting who can reach a workstation. Required
Device and media controlsDisposal and media re-use are required; accountability tracking and data backup before a move are addressable

What the cloud does and does not cover

Your cloud provider Data centre access control and guards Server hardware and disk destruction Environmental and power protection Still yours Laptops, phones and portable drives Offices, desks and screen visibility Wiping a device before it is resold Your provider is a business associate. Their controls need a BAA, not an assumption.
Swipe to see the full diagram. Outsourcing the data centre does not outsource the standard.

Remote and hybrid teams

Workstation use and workstation security were written with clinic desktops in mind. Applied to a distributed engineering team they translate into a small set of practical rules.

RequirementWhat it looks like remotely
Restrict physical access to workstationsFull-disk encryption, automatic screen lock, no shared home machines
Control the surroundings ePHI is viewed inPolicy on working in public spaces, privacy screens where relevant
Know which devices hold ePHIA device inventory that is current, not a spreadsheet from last year
Control removable mediaUSB storage blocked or governed by policy and logged

Lost laptops still drive breach reports

A missing encrypted laptop is usually not a reportable breach. A missing unencrypted one usually is. That single control is the difference between an asset loss and a notification exercise under the Breach Notification Rule.

Device and media disposal

Disposal

Required. Final disposition of ePHI and the hardware it lived on, documented.

Media re-use

Required. ePHI removed before hardware is reassigned or resold.

Accountability

Addressable. A record of hardware movements and who is responsible for each device.

How Osto covers the endpoint side

The physical safeguards you cannot delegate are the ones sitting on employee devices. Osto’s endpoint and device control maintains the inventory, enforces encryption and screen lock, governs removable media, and supports remote wipe when a device is lost or an employee leaves. File access DLP limits what can be copied off in the first place, and evidence maps to the HIPAA safeguards in the compliance platform.

Free security assessment

The safeguards your cloud provider cannot cover

Device inventory, encryption enforcement, removable media control and remote wipe on the endpoints you actually own.

Get a free security assessment Book a platform walkthrough

macOS agent · Device control and DLP · One platform, everything

Frequently asked questions

What are physical safeguards under HIPAA?

The four Security Rule standards covering the physical environment around ePHI: facility access controls, workstation use, workstation security, and device and media controls.

Do physical safeguards apply to cloud-only companies?

Yes. Data centre obligations shift to the cloud provider as a business associate under a BAA, but workstation policy, device inventory, removable media and disposal remain yours.

How do physical safeguards work for remote teams?

Through device controls rather than building controls: full-disk encryption, automatic lock, current inventory, restrictions on removable media, and a policy on where ePHI may be viewed.

What does the disposal requirement cover?

Documented final disposition of ePHI and the hardware holding it. Wiping a laptop before resale and secure destruction of failed drives both fall under it, and both are required rather than addressable.

Is a device inventory required?

Accountability tracking is addressable, so a formal inventory is not strictly mandatory. In practice you cannot demonstrate the required disposal and re-use controls without knowing which devices exist.