Services Access Control SystemsCommercial LocksmithVideo Surveillance Why Action 1st Customers & Reviews Contact Get a Quote Call (949) 661-3010
Compliance Guide · 2026

Access control and HIPAA for medical offices

What the Security Rule actually says about physical access, what "addressable" means in practice, and which doors in a clinic are worth controlling.

The short answer: HIPAA never says "install access control." It says at 45 CFR 164.310(a) that you must limit physical access to facilities and systems that hold electronic PHI, and that you must be able to show how. All four facility access specifications are addressable, meaning you implement them, document an equivalent, or record why they do not apply. Electronic access control wins in practice because it generates the proof automatically, which a box of keys never will.

We do a fair amount of work in medical suites around Orange County, and the same two mistakes come up. Either a practice buys nothing and hopes the topic never surfaces during an audit, or a practice buys badge readers for twenty doors including the supply closet. Neither is what the rule asks for.

This is not legal advice, and your compliance officer or attorney gets the final say. But we can tell you what the regulation says, and what the buildings that pass their assessments actually look like.

What the rule actually requires

The physical safeguards live at 45 CFR 164.310. Four standards matter for a medical office:

  • Facility access controls, 164.310(a). Limit physical access to your facility and the systems in it, while still letting authorized people in. This is the one people mean when they say "HIPAA and door locks."
  • Workstation use, 164.310(b). Define how and where workstations that touch ePHI get used, including the physical surroundings.
  • Workstation security, 164.310(c). Put physical safeguards around those workstations so only authorized users reach them. A check-in monitor angled toward the waiting room is the classic failure here.
  • Device and media controls, 164.310(d). Govern how hardware and media holding PHI move in, out, and around the building. Disposal and media re-use are required, not addressable.

Required vs. addressable, in plain terms

This trips up more practices than any other part of the rule. Under facility access controls, all four implementation specifications are addressable: contingency operations, facility security plan, access control and validation procedures, and maintenance records.

Addressable does not mean you get to ignore it. It means you have three legitimate paths for each one. Implement it as written. Implement something equivalent that fits your practice and write down what you did. Or document, based on your risk analysis, why it is not reasonable and appropriate for a practice your size. What auditors penalize is the fourth path, which is doing nothing and having no paperwork explaining the decision.

SpecificationStatusWhat it looks like in a real clinic
Contingency operations Addressable How staff get into the building to restore records after an emergency, and who is allowed to
Facility security plan Addressable A written plan covering doors, locks, alarms, and who holds what access
Access control and validation Addressable Badge or credential policy, visitor sign-in, escorting vendors, and how you verify identity
Maintenance records Addressable A log of repairs to doors, locks, and hardware that affect security
Disposal / media re-use Required Under 164.310(d): how drives and devices holding PHI get wiped or destroyed

Which doors actually matter

Start from where PHI lives, not from the floor plan. In a typical Orange County medical suite, four doors carry nearly all the risk.

1
Waiting room to clinical area. The single most important door in the practice. It separates the public from charts, workstations, and conversations. This is where a reader earns its cost.
2
Server or IT closet. Everything electronic lives or dies here. Control it and log it, even if it is a small closet nobody thinks about.
3
Medical records or file room. If you still keep paper, and most practices do somewhere, this door needs the same treatment as the server closet.
4
Staff exterior entrance. The back door people prop open with a rock in July. A credential and a door-held-open alert solve a problem you probably already have.

Exam rooms almost never need readers. Neither do supply closets, break rooms, or restrooms. If a quote has readers on all of those, ask what risk each one addresses, and see whether the answer is specific.

The audit trail is the point

A mechanical key tells you nothing. If a chart walks out of the records room, a key-based practice can say who was issued a key at some point in the last decade, which is not an answer. An access platform can say that badge 14 opened that door at 6:42 p.m. on a Tuesday, and that nobody else did.

That difference is the entire reason electronic access control keeps showing up in HIPAA conversations. The rule wants you to control access and be able to demonstrate it. One of these approaches demonstrates it by existing, and the other requires you to write a memo.

Two practical notes on logs. Keep Security Rule documentation for six years, and check what your platform's retention default actually is, because some tiers keep 12 months and charge for more. Review the log occasionally, too. An audit trail nobody has ever opened is a weaker answer than one with a quarterly review behind it.

Where compliance and fire code collide

Practices sometimes ask for locks that hold people in a corridor, or for a mag-lock on a door that turns out to be part of the exit path. California fire code does not bend for HIPAA. Anyone inside the building has to be able to get out without a credential, without special knowledge, and without power.

In practice that means doors on an egress path need push-to-exit hardware, fire alarm release, and fail-safe behavior on power loss. In most Orange County cities it also means a permit and a fire marshal inspection. A licensed low-voltage contractor should be handling that as part of the job. If a bidder does not mention permits at all on a medical build-out, that is worth a follow-up question.

A reasonable starting setup

For a typical five to fifteen provider practice, a defensible setup is four controlled doors, cloud-managed so credentials can be revoked the same day someone leaves, mobile or badge credentials by staff preference, and a visitor policy that covers vendors and contractors. That usually lands in the range we cover in our Orange County cost guide, roughly $1,500 to $3,000 per door installed, plus per-door licensing.

Pair it with the paperwork side: a written facility security plan, a visitor log, and a maintenance record for door hardware. The hardware without the documentation only answers half of what an assessor asks for.

FAQ

HIPAA and access control: quick answers

No. HIPAA does not name any product or technology. The Security Rule's physical safeguards at 45 CFR 164.310(a) require you to limit physical access to facilities and systems holding electronic PHI while still allowing authorized access. A locked door with a well-managed key policy can satisfy that. Electronic access control is simply the easiest way to prove you did it, because it produces the audit trail on its own.
Addressable does not mean optional. All four facility access control specifications (contingency operations, facility security plan, access control and validation procedures, and maintenance records) are addressable. For each one you must either implement it, implement a documented equivalent, or write down why it is not reasonable for your practice based on your risk analysis. Skipping it silently is the one option that is not available.
Work from where PHI physically lives rather than from a floor plan. In most practices that means the door between the waiting room and the clinical area, the server or IT closet, the medical records room, and any exterior staff entrance. Exam room doors usually do not need readers, and putting them everywhere is the most common way practices overspend.
HIPAA requires documentation related to the Security Rule to be retained for six years from creation or from when it was last in effect, whichever is later. Cloud access platforms keep event history for you, but confirm the retention window in your subscription tier. Some default to 12 months and charge for longer.
Yes, and arguably more so. If the workstations, servers, or network gear that can reach ePHI sit behind that door, then that door is a physical safeguard for electronic records. 164.310(c) also expects physical safeguards around workstations that access ePHI, so a monitor visible from an unsecured hallway is its own separate problem.
Egress always wins. California fire code requires people to be able to get out of the building without special knowledge or a credential, so doors on an exit path must release on fire alarm and on power loss. A compliance-driven lock that traps people in a corridor will fail inspection, and it should. This is why permits and fire marshal sign-off are part of the job.
Free on-site survey & written quote

Secure the right doors.

Tell us about your practice and we will walk it, point out what an assessor will look for, and price only the doors that matter.

✆ Call Get a Quote