Workstation security

Workstation security, per device in your inventory

A composed workstation policy shaped by your device posture, plus a per-asset check on whether every workstation, tablet, and phone has a current physical-safeguards attestation.

The rule was written for desks in offices. Your workstations include a tablet in a family’s living room and a phone an RBT texts parents from, and the definition does not care which picture came to mind first.

The policy is composed from your clinic’s facts

Your workstation policy is generated against your recorded facts and covers what counts as a device, proper use, where devices may be used, screen privacy, auto-lock and per-person login, network rules including public wifi, prohibited uses like personal cloud storage and pasting PHI into consumer AI tools, and lost or stolen device reporting.

Which devices may be used renders directly from your recorded device ownership posture, so the policy states your actual position rather than a generic one. Mobile and field activity pulls in clauses on securing devices away from the clinic. Shared workstations pull in a clause on per-account sign-in at shared machines.

What gets tracked after the policy exists

Six requirements:

  • The policy is active, adopted, reviewed within twelve months, and its facts have not drifted.
  • Every active workstation, portable workstation, tablet, and smartphone in your asset inventory has a physical safeguards attestation on file.
  • None of those attestations is more than twelve months old.
  • No theft, loss, or unauthorized-access incidents are sitting open from the last twelve months.

The second and third requirements work per device, not per clinic. Add a tablet without recording its safeguards and the control drops. Let an attestation age past a year and it drops for staleness, so the answer cannot quietly become a document from three years ago.

What this is, and what it is not

The attestation is a record you enter about a device, not a reading of the device. The system does not check whether a screen actually locks, whether a login is actually unique to one person, or whether encryption is switched on. It tracks whether you have said so, per device, recently.

What that gives you is a per-device answer instead of a blanket claim, and a clock on how stale that answer is allowed to get.

What an investigator gets

A dated, adopted policy naming your real device classes, including the ones that leave the building. A per-device record of physical safeguards, each with a date. Evidence that the field tablet was considered, which is the class most policies never mention.

The regulation: read the rule behind this control.

Ready to get your HIPAA program in order?

No pressure, no pitch. Book a 20-minute call, or just email a question and we'll point you the right way.