Facility access controls: the questions are smaller than you think

45 CFR 164.310(a)(1) sounds like badge systems and server rooms. At clinic scale it is a short, answerable list: who has keys, does it change when staff leave, and can a parent in the waiting room see the front desk screen.

Last verified: 2026-09-08

Facility access controls sounds like it was written for a hospital with a badge system and a server room behind a locked door. For most ABA clinics it is not that. It is a short list of ordinary questions that almost nobody has actually written down.

What the rule actually requires

Facility access controls is a Required standard: limit physical access to your electronic information systems and the facilities in which they are housed, while ensuring that properly authorized access is allowed (45 CFR 164.310(a)(1)).

Four implementation specifications, all Addressable:

  • Contingency operations. Procedures for facility access that support restoring lost data under your disaster recovery and emergency mode plans.
  • Facility security plan. Procedures to safeguard the facility and equipment from unauthorized physical access, tampering, and theft.
  • Access control and validation procedures. Procedures to control and validate a person’s access based on their role, including visitor control and control of software program testing and revision.
  • Maintenance records. Documentation of repairs and modifications to the physical components of a facility related to security, for example locks, doors, and walls.

What this actually looks like at clinic scale

Addressable means you run the honest assessment, and for a small clinic the honest assessment is refreshingly small. You are not building a badge system. Your facility questions are: who has keys or codes, is there a list, does it change when staff leave, where does the equipment that holds ePHI actually sit relative to the waiting room, and can a parent waiting for intake see the front desk screen.

“You are not building a badge system. Write the answers down; that document is most of the standard at your scale.”

If you rent inside a larger building, your suite is your facility for this standard. You are not responsible for the building’s front door, you are responsible for your door and what is behind it. Write the answers down. That document is most of the standard at your scale.

The trap in the second specification

The facility security plan’s language, safeguard against unauthorized access, tampering, and theft, gets read as a fire-and-flood checklist and stops there. That misses half of what it is asking. Theft is a facility security event just as much as a break-in, and a stolen or missing device routes to the same question every physical safeguard eventually reaches: was the device encrypted. A locked door that a laptop still walked out of has not failed this standard by itself, the encryption question decides what kind of day you are having next.

What real facility access controls look like, next to what most clinics have

What the rule requires What most clinics actually have
Who has access A current, written list of who holds keys or codes Known informally, nobody has written it down
Change on departure The list updates the day someone leaves Locks and codes outlive the employment
Scope Your suite, clearly defined Vague sense of “the building,” undefined
Visibility Screens and records positioned away from public view A monitor facing the waiting room, unnoticed until someone mentions it

Most clinics are not failing this standard through negligence. They are failing it because nobody has ever framed these as compliance questions with an actual, required answer, they read as ordinary office logistics instead.

The short version

  • Facility access controls (164.310(a)(1)) require limiting physical access to your systems and the space they sit in, while still allowing properly authorized access.
  • Four implementation specifications, all Addressable: contingency operations, a facility security plan, access control and validation procedures, and maintenance records.
  • At clinic scale, the honest assessment is small: who has keys or codes, is there a list, does it change when someone leaves, and where does equipment holding ePHI actually sit.
  • If you rent inside a larger building, your suite is your facility for this standard, not the whole building.
  • The second specification's phrase 'and theft' matters as much as the phrase 'fire and vandalism.' Both are facility security events, and both end at the same question: were the devices encrypted.

This article is educational information about the HIPAA regulations, not legal advice. It describes what the rules say; it does not tell you what to do about your specific situation, and reading it does not create an attorney-client or consultant-client relationship. Regulations change, and enforcement positions change with them. For advice on your clinic, talk to a qualified professional.

Sources

Who has access, tracked and current.

WiseUpHIPAA tracks facility access alongside your other controls, so the list of who has keys or codes stays current instead of living in someone's memory until an incident tests it.

Ready to get your HIPAA program in order?

No pressure, no pitch. Book a 20-minute call, or just email a question and we'll point you the right way.