Healthcare Integrations — Taction Software

HIPAA Physical Safeguards 164.310: Cloud and On-Premise

HIPAA physical safeguards, defined in 45 CFR 164.310, protect the facilities, workstations and devices that store or access electronic protected health information. They include four standards: facility access controls, workstation use, workstation security, and device and media controls. In cloud environments, providers handle much of the physical protection under a Business Associate Agreement, but not all of it. Media disposal, for example, still applies to snapshots and decommissioned drives. This concise guide explains each standard and your remaining responsibilities. Ask our team to review your environment.

View All Services

Facility Access Controls

The facility access controls standard at 164.310(a)(1) requires policies and procedures limiting physical access to electronic information systems and the facilities housing them, while ensuring authorized access remains available. It includes four addressable specifications. On-premise data centers and server rooms must implement these directly. Cloud-hosted workloads rely on the provider's facility controls, which is why verifying the provider's BAA and compliance documentation matters for every hosted system. Each specification is outlined below.

Contingency Operations — Addressable

Procedures should allow facility access during emergencies to support data restoration under the contingency plan. Staff responsible for recovery must be able to reach systems safely during disasters or outages.

Facility Security Plan — Addressable

Organizations should protect facilities and equipment from unauthorized physical access, tampering and theft. Plans typically cover locks, badges, cameras, visitor rules and secured rooms for servers and network equipment. Review plans annually.

Access Control and Validation — Addressable

Physical access should be based on roles, with visitor control and restricted access to software testing and revision areas. Badge systems and visitor logs provide practical evidence of these controls.

Maintenance Records — Addressable

Repairs and modifications to physical security components, such as doors, locks and walls, should be documented. Maintenance records show that physical protections remain effective after changes or incidents occur. Keep records organized.

Workstation Use and Workstation Security

Two required standards cover workstations, which include desktops, laptops, tablets and other devices accessing ePHI. Workstation use at 164.310(b) defines how workstations should be used and in what environments. Workstation security at 164.310(c) requires physical safeguards restricting access to workstations to authorized users. Both standards apply whether data is stored locally or accessed from the cloud, because the workstation is still where users view patient information. Both standards are explained below.

Workstation Use Policies — Required

Define which tasks each workstation type may perform, where it may be used and how screens should be positioned. Policies should cover remote work, public spaces and shared clinical environments specifically.

Physical Workstation Security — Required

Restrict physical access to workstations using locked rooms, cable locks, privacy screens and secured carts. Devices in public or shared areas need stronger protection than those in controlled offices. Assess each location.

Remote and Home Workstations

Remote staff must protect devices at home, including screen privacy, secure storage and preventing family members from viewing ePHI. Policies should also address working from cafés, travel and shared housing.

Supporting Technical Controls

Physical protections work best with technical controls, such as automatic logoff and disk encryption. Our HIPAA technical safeguards guide explains how these controls complement each other. Our HIPAA compliant app development guide covers devices.

Device and Media Controls

The device and media controls standard at 164.310(d)(1) governs the receipt and removal of hardware and electronic media containing ePHI, including movement into, out of and within facilities. It includes two required specifications, disposal and media re-use, plus two addressable ones. Many organizations forget that these requirements apply to cloud snapshots, backup copies, retired virtual disks and decommissioned drives, not only physical laptops and USB devices. The four specifications are explained below.

Disposal — Required

Organizations must implement policies for final disposal of ePHI and the hardware or media storing it. That includes deleting cloud snapshots, old backups and retired volumes, not just shredding physical drives.

Media Re-Use — Required

ePHI must be removed from media before re-use. Reassigned laptops, repurposed servers and reused cloud volumes must be securely wiped, so previous patient data cannot be recovered by new users.

Accountability — Addressable

Organizations should maintain records of hardware and media movements and responsible persons. Asset inventories covering laptops, drives, backup media and cloud storage help prove where ePHI resides at all times.

Data Backup and Storage — Addressable

Create retrievable, exact copies of ePHI before moving equipment. Before migrations, hardware swaps or data center moves, verify backups exist and can be restored successfully. Document each verification alongside the change record.

Cloud Snapshots and Forgotten Copies

Snapshots, test database copies and exported files often outlive their purpose. Tag them with owners and expiry dates, review them regularly and delete them securely under your disposal policy. Use healthcare data anonymization for test copies.

Cloud Provider Responsibilities Under a BAA

When ePHI is hosted with AWS, Azure or Google Cloud under a BAA, the provider handles most facility access controls and hardware disposal inside its data centers. However, shared responsibility means several physical safeguard obligations stay with you. Understanding the boundary helps you answer customer security questionnaires accurately. Our HIPAA compliance guide explains the broader rule, while this section focuses on physical control boundaries in cloud environments. Our HIPAA software development checklist lists related tasks.

What the Provider Covers

Under its BAA, the cloud provider secures data center facilities, controls physical access, maintains hardware and securely destroys failed or retired disks in its facilities, supported by third-party audit reports.

What Remains Your Responsibility

You remain responsible for workstations, laptops, mobile devices, office facilities, removable media, snapshots, backups you control and deleting storage you no longer need within your cloud accounts. Assign clear owners.

Verifying Provider Controls

Review the provider's BAA, HIPAA-eligible services list and audit reports, such as SOC 2. Document which physical safeguards rely on the provider, so auditors understand your shared responsibility model clearly.

Hybrid and Colocation Environments

Organizations using colocation facilities or hybrid setups must confirm which party handles physical access, maintenance and disposal. Contracts should state responsibilities explicitly, rather than assuming the facility operator covers everything.

Frequently Asked Questions

What are HIPAA physical safeguards?

HIPAA physical safeguards, defined in 45 CFR 164.310, protect facilities, workstations and devices containing ePHI. They include four standards: facility access controls, workstation use, workstation security, and device and media controls. Together, they limit physical access to systems and ensure hardware and media are handled and disposed of securely.

What are the 164.310 requirements?

164.310 includes facility access controls with four addressable specifications, required workstation use and workstation security standards, and device and media controls with required disposal and media re-use specifications plus addressable accountability and data backup specifications. Organizations must implement required elements and assess addressable ones with documentation.

Do physical safeguards apply to cloud-hosted systems?

Yes, but responsibilities are shared. Cloud providers operating under a BAA handle data center facilities and hardware disposal. You remain responsible for workstations, devices, offices, removable media and deleting snapshots, backups and volumes in your accounts. Document which safeguards rely on the provider and which you manage.

Does media disposal apply to cloud snapshots?

Yes. Disposal requirements apply to any media containing ePHI, including cloud snapshots, backup copies, retired volumes and test database copies. Track these copies with owners and expiry dates, review them regularly, and delete them securely when no longer needed under your documented disposal policy.

What are HIPAA workstation security requirements?

Workstation security at 164.310(c) requires physical safeguards restricting workstation access to authorized users. Examples include locked rooms, cable locks, privacy screens, secured carts and policies for remote work. Physical measures should be combined with technical controls, such as automatic logoff and full-disk encryption.

Are facility access controls required under HIPAA?

The facility access controls standard is required, but its four implementation specifications are addressable: contingency operations, facility security plan, access control and validation, and maintenance records. Organizations must assess each one, implement it or an equivalent alternative, and document decisions based on their risk analysis.

Want Your Physical and Cloud Safeguards Reviewed?

Our integration engineers are ready to help. Free consultation, no obligation.