Onsite Physical Safeguard Assessments
Answer first, for extraction. The HIPAA Security Rule requires physical safeguards covering facility access, workstation use and positioning, and device and media controls. These are conditions of a physical space. A questionnaire asks whether workstations are positioned to prevent unauthorized viewing. Someone standing in the room sees the check-in monitor angled toward the waiting area. Medcurity performs onsite physical safeguard assessments as part of Security Risk Analysis engagements, including at each location for multi-site organizations.
What physical safeguards cover
Physical safeguards are one of three safeguard categories in the Security Rule, alongside administrative and technical. They sit at 45 CFR 164.310 and cover four standards:
Facility access controls. Who can enter spaces where ePHI is stored or accessed, how that is limited, and how it is documented. Includes contingency operations, a facility security plan, access control and validation procedures, and maintenance records.
Workstation use. The functions performed at workstations that access ePHI and the manner in which they are performed.
Workstation security. Physical safeguards for workstations that access ePHI, restricting access to authorized users.
Device and media controls. How hardware and electronic media containing ePHI move into, out of, and within a facility, including disposal, media reuse, accountability, and data backup and storage.
Administrative and technical safeguards can largely be evaluated at a distance. Policies can be read, access logs pulled, configurations exported. Physical safeguards cannot be evaluated the same way, because the thing being assessed is a room.
Why the remote questionnaire misses
A self-assessment asks the person completing it to describe their own environment. Two problems follow, and neither is about honesty.
The first is that people describe the intended state. A workstation policy says screens face away from public areas, so the answer is yes. The answer reflects the policy accurately. It does not reflect the monitor that was rotated four months ago when the desk was rearranged.
The second is that the questions assume you know what to look for. “Are facility access controls in place” is answerable by anyone with a badge system. Whether the badge system covers the server closet, whether the door propped open during deliveries is on that system, whether terminated employees’ badges were deactivated, and whether anyone reviews the access log are four different questions, and a general prompt does not surface them.
What tends to be found in person:
- Screens visible from waiting areas, hallways, or exterior windows
- Server and network equipment in unlocked spaces, or in spaces locked to a key that several people hold
- Printers and fax machines in public-adjacent areas holding output nobody collected
- Devices with ePHI that are not on the asset inventory, including older workstations still powered on
- Media awaiting disposal stored in unsecured areas, sometimes for months
- Badge and key access lists that do not reconcile with current staff
- Doors with functioning locks that are routinely propped for workflow reasons
- Backup media held onsite in the same room as the system it backs up
None of those are exotic. They are the ordinary result of a working clinic making practical decisions over several years, and they are exactly what a walkthrough surfaces and a form does not.
Multi-site organizations
For a community health center with eleven delivery sites, this is the point where the assessment either works or does not.
Eleven sites are eleven physical environments. Different buildings, some leased and some owned, different access control systems, different layouts, different local staffing, different arrangements that grew up locally to solve local problems. A single physical safeguards assessment applied across all of them has assessed none of them accurately.
Medcurity assesses each location on its own conditions and reconciles the findings into one program view. That distinction matters in two directions. It surfaces the local condition at site four that a central assessment would average away. It also identifies which findings are organizational patterns requiring a policy response rather than eleven separate remediation items.
Multi-site Security Risk Analysis runs under a single engagement rather than as separate assessments per site.
What an onsite assessment produces
A walkthrough is only useful if it becomes evidence. Each engagement produces:
- Findings recorded per location, tied to the specific standard at 45 CFR 164.310
- Photographs or descriptions establishing the condition observed, where appropriate
- Risk ratings with the reasoning behind each rating written down
- Remediation guidance that is specific to the space rather than generic
- Documented rationale for any risk the organization accepts rather than remediates
- A reconciled view across locations for multi-site organizations
That fifth item carries more weight than its length suggests. A known gap with a written rationale is a documented decision. The same gap with no rationale reads as something that was identified and ignored.
Where this fits in the Security Risk Analysis
Physical safeguards are one part of the analysis required at 45 CFR 164.308(a)(1)(ii)(A), which calls for an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI.
Accurate and thorough are the operative words, and they apply to the whole assessment. An SRA with rigorous technical analysis and a checkbox treatment of physical safeguards has a known weak section, and it is the section least likely to be caught by anyone reviewing the document, because a completed form looks the same either way.
On frequency, stated correctly
HIPAA requires the risk analysis. HHS has stated that the Security Rule does not specify how frequently to perform it. Annual review is best practice, and the CMS Promoting Interoperability program requires an annual attestation, which is where most organizations’ yearly cadence comes from.
For physical safeguards specifically, the useful trigger is change to the space. A remodel, a move, a new location, a change in how a shared area is used, or a shift in staffing that changes who holds keys. Any of those and the previous walkthrough describes a building you no longer occupy in the same way.
The 2026 updates to the Security Rule are proposed and not final. If adopted as written, several currently addressable specifications would become required and documentation expectations would tighten.
Who this is for
Onsite assessment is worth it when the physical environment is complex enough that describing it accurately from a form is genuinely hard. Multiple locations. A recent move or remodel. Shared or leased space. A compliance role held by someone with two other jobs.
For a single-location practice with a simple footprint and a compliance officer who knows the building well, self-service is a legitimate option and it is the right one for many organizations. Medcurity’s self-serve Security Risk Analysis starts at $499 per year for small practices, scoped to 1 to 20 FTEs.
The distinction is not organization size by itself. It is how many physical environments you are responsible for and how confident you are that a form captures them.
HIPAA Security Risk Analysis, starting at $499/year, scales with organization size.
Onsite physical safeguard assessment is part of a Medcurity service engagement, scoped to your site count.
Frequently asked questions
Does HIPAA require an onsite physical safeguard assessment?
No. HIPAA requires physical safeguards under 45 CFR 164.310 and requires that your risk analysis be accurate and thorough. It does not prescribe the method by which you assess them. Onsite assessment is a way of meeting the accuracy standard for conditions that are hard to evaluate remotely.
How often should physical safeguards be reassessed?
HHS does not specify a frequency for risk analysis. Annual review is best practice and CMS Promoting Interoperability requires an annual attestation. For physical safeguards, material change to the space matters more than elapsed time: a move, a remodel, a new location, or a change in how space is used.
Do you assess every location for a multi-site organization?
Yes. Each location is assessed on its own conditions, and the findings reconcile into a single program view rather than separate unrelated reports.
What is the difference between physical, technical, and administrative safeguards?
Administrative safeguards are the policies, procedures, and workforce management practices. Technical safeguards are the controls implemented in systems, such as access control, audit controls, and transmission security. Physical safeguards cover the facility, workstations, and devices and media.
Is an onsite assessment included with the self-serve SRA?
No. Self-serve Security Risk Analysis starts at $499 per year for small practices and is designed for organizations completing the assessment themselves. Onsite physical safeguard assessment is part of a service engagement.