Access control and HIPAA for medical offices
What the Security Rule actually says about physical access, what "addressable" means in practice, and which doors in a clinic are worth controlling.
We do a fair amount of work in medical suites around Orange County, and the same two mistakes come up. Either a practice buys nothing and hopes the topic never surfaces during an audit, or a practice buys badge readers for twenty doors including the supply closet. Neither is what the rule asks for.
This is not legal advice, and your compliance officer or attorney gets the final say. But we can tell you what the regulation says, and what the buildings that pass their assessments actually look like.
What the rule actually requires
The physical safeguards live at 45 CFR 164.310. Four standards matter for a medical office:
- Facility access controls, 164.310(a). Limit physical access to your facility and the systems in it, while still letting authorized people in. This is the one people mean when they say "HIPAA and door locks."
- Workstation use, 164.310(b). Define how and where workstations that touch ePHI get used, including the physical surroundings.
- Workstation security, 164.310(c). Put physical safeguards around those workstations so only authorized users reach them. A check-in monitor angled toward the waiting room is the classic failure here.
- Device and media controls, 164.310(d). Govern how hardware and media holding PHI move in, out, and around the building. Disposal and media re-use are required, not addressable.
Required vs. addressable, in plain terms
This trips up more practices than any other part of the rule. Under facility access controls, all four implementation specifications are addressable: contingency operations, facility security plan, access control and validation procedures, and maintenance records.
Addressable does not mean you get to ignore it. It means you have three legitimate paths for each one. Implement it as written. Implement something equivalent that fits your practice and write down what you did. Or document, based on your risk analysis, why it is not reasonable and appropriate for a practice your size. What auditors penalize is the fourth path, which is doing nothing and having no paperwork explaining the decision.
| Specification | Status | What it looks like in a real clinic |
|---|---|---|
| Contingency operations | Addressable | How staff get into the building to restore records after an emergency, and who is allowed to |
| Facility security plan | Addressable | A written plan covering doors, locks, alarms, and who holds what access |
| Access control and validation | Addressable | Badge or credential policy, visitor sign-in, escorting vendors, and how you verify identity |
| Maintenance records | Addressable | A log of repairs to doors, locks, and hardware that affect security |
| Disposal / media re-use | Required | Under 164.310(d): how drives and devices holding PHI get wiped or destroyed |
Which doors actually matter
Start from where PHI lives, not from the floor plan. In a typical Orange County medical suite, four doors carry nearly all the risk.
Exam rooms almost never need readers. Neither do supply closets, break rooms, or restrooms. If a quote has readers on all of those, ask what risk each one addresses, and see whether the answer is specific.
The audit trail is the point
A mechanical key tells you nothing. If a chart walks out of the records room, a key-based practice can say who was issued a key at some point in the last decade, which is not an answer. An access platform can say that badge 14 opened that door at 6:42 p.m. on a Tuesday, and that nobody else did.
That difference is the entire reason electronic access control keeps showing up in HIPAA conversations. The rule wants you to control access and be able to demonstrate it. One of these approaches demonstrates it by existing, and the other requires you to write a memo.
Two practical notes on logs. Keep Security Rule documentation for six years, and check what your platform's retention default actually is, because some tiers keep 12 months and charge for more. Review the log occasionally, too. An audit trail nobody has ever opened is a weaker answer than one with a quarterly review behind it.
Where compliance and fire code collide
Practices sometimes ask for locks that hold people in a corridor, or for a mag-lock on a door that turns out to be part of the exit path. California fire code does not bend for HIPAA. Anyone inside the building has to be able to get out without a credential, without special knowledge, and without power.
In practice that means doors on an egress path need push-to-exit hardware, fire alarm release, and fail-safe behavior on power loss. In most Orange County cities it also means a permit and a fire marshal inspection. A licensed low-voltage contractor should be handling that as part of the job. If a bidder does not mention permits at all on a medical build-out, that is worth a follow-up question.
A reasonable starting setup
For a typical five to fifteen provider practice, a defensible setup is four controlled doors, cloud-managed so credentials can be revoked the same day someone leaves, mobile or badge credentials by staff preference, and a visitor policy that covers vendors and contractors. That usually lands in the range we cover in our Orange County cost guide, roughly $1,500 to $3,000 per door installed, plus per-door licensing.
Pair it with the paperwork side: a written facility security plan, a visitor log, and a maintenance record for door hardware. The hardware without the documentation only answers half of what an assessor asks for.
HIPAA and access control: quick answers
Secure the right doors.
Tell us about your practice and we will walk it, point out what an assessor will look for, and price only the doors that matter.