Skip to content

HIPAA physical safeguards

By Sam Rivera, Founder, SentinelPanda · June 19, 2026 · 1 min read · HIPAA

Like ISO 27001's physical controls, most HIPAA physical safeguards are inherited from your cloud provider — but your laptops and your media disposal are still on you.

What they cover

HIPAA physical safeguards protect the physical systems and the buildings and devices that hold ePHI: facility access controls, policies for workstation use and security, and device and media controls covering disposal, reuse, and movement of hardware.

Mostly inherited in the cloud

If ePHI lives in a cloud provider that signs a BAA (the major clouds do), the data-centre physical safeguards — facility access, environmental controls — are operated by the provider and covered by their HIPAA compliance and attestations. You inherit them and reference the BAA and reports rather than securing a data centre yourself.

What stays yours

You remain responsible for the physical security you control: workstation security (screen lock, device hardening, where ePHI can be viewed), and device/media controls — wiping or destroying drives and devices before disposal or reuse so ePHI does not walk out the door. For a remote team this is device management and a disposal process.

Document the split

As with ISO 27001, the right posture is documenting which physical safeguards you operate versus inherit, with the provider BAA/attestation referenced. SentinelPanda tracks inherited safeguards and your device/disposal controls together as evidence.

HIPAA administrative safeguards ISO 27001 Annex A physical controls (A.7) Compliance for fully-remote teams

Run your compliance program in one workspace.