HIPAA physical safeguards
By Sam Rivera, Founder, SentinelPanda · June 19, 2026 · 1 min read · HIPAA
Like ISO 27001's physical controls, most HIPAA physical safeguards are inherited from your cloud provider — but your laptops and your media disposal are still on you.
What they cover
HIPAA physical safeguards protect the physical systems and the buildings and devices that hold ePHI: facility access controls, policies for workstation use and security, and device and media controls covering disposal, reuse, and movement of hardware.
Mostly inherited in the cloud
If ePHI lives in a cloud provider that signs a BAA (the major clouds do), the data-centre physical safeguards — facility access, environmental controls — are operated by the provider and covered by their HIPAA compliance and attestations. You inherit them and reference the BAA and reports rather than securing a data centre yourself.
What stays yours
You remain responsible for the physical security you control: workstation security (screen lock, device hardening, where ePHI can be viewed), and device/media controls — wiping or destroying drives and devices before disposal or reuse so ePHI does not walk out the door. For a remote team this is device management and a disposal process.
Document the split
As with ISO 27001, the right posture is documenting which physical safeguards you operate versus inherit, with the provider BAA/attestation referenced. SentinelPanda tracks inherited safeguards and your device/disposal controls together as evidence.