Free HIPAA procedures template · v1.0 · Applies to covered entities & business associates · Companion: Policy →
Adopting this document means committing to these HIPAA controls, the 45 CFR §164 requirements it helps satisfy, by area:
Common threats (NIST SP 800-30 classes) that the controls behind this document defend against:
Exploits: Endpoint not encrypted · 164.312(a)(2)(iv) Encryption; 164.310(d) Device Controls
Exploits: No disposal/sanitization procedure · 164.310(d)(2)(i) Disposal
Exploits: No contingency operations · 164.310(a)(2)(i) Contingency Ops
Template. These procedures operationalize the Physical & Facility Security Policy. Replace
[bracketed]items with your specifics and adjust steps to match your facilities, tools, and team size. A[remote-first]organization with no controlled office can mark the office-specific steps N/A and document why.
To provide repeatable, auditable steps for controlling physical access to [Organization] facilities and workspaces, validating visitors, accessing facilities during an emergency, logging maintenance to security components, and disposing of ePHI and its media, implementing the Physical & Facility Security Policy.
[Security Official] (or facilities manager) maintains a key/badge register listing every physical credential issued for a controlled space: holder, credential ID, area(s) authorized, date issued, and date returned/revoked.See where your organization stands on the controls this template cites.
Join UsFor a
[remote-first]organization that issues no physical credentials, record that no controlled space exists and skip steps 1–5; home-work-area expectations are covered by the Physical & Facility Security Policy §3.
[cloud infrastructure provider]; [Organization] maintains at least two administrators with MFA so recovery is possible if one is unavailable.[24 hours] the [Security Official] reviews it, confirms it was warranted, and rotates any shared credential or code that was used.[ticketing system] (or a maintenance log).[Organization]'s control for repair, ePHI is first removed (secure wipe) or the storage medium is retained in-house; this is noted in the record.[Security Official]).[cloud infrastructure provider] / [cloud productivity & storage suite] (provider sanitizes media at end of life under the BAA);Disposal record (representative fields): item/serial · media type · method · date · performed by · witness/approver · certificate ref.
Key/badge register · visitor logs · emergency facility-access records · maintenance log (security components & ePHI devices) · disposal records and certificates of destruction · vendor return/destruction confirmations. These are the artifacts an auditor will request to confirm the physical safeguards operate.
| Citation | Requirement | Addressed in |
|---|---|---|
| 164.310(a)(1) | Facility Access Controls | §1, §2 |
| 164.310(a)(2)(iii) | Access Control and Validation Procedures | §1, §2 |
| 164.310(a)(2)(i) | Contingency Operations | §3 |
| 164.310(a)(2)(iv) | Maintenance Records | §4 |
| 164.310(d)(2)(i) | Disposal | §5 |
Reviewed at least annually by the [Security Official]. v1.0.