PE-15 Physical Protection

Water Damage Protection

High Risk Moderate Medium Cost

PE-15 requires protecting the system from damage resulting from water leakage by providing master shutoff or isolation valves that are accessible, working properly, and known to key personnel — and by monitoring for presence of water. Burst pipes above EHR racks and leaking roofs into HIM storage remain common healthcare disaster scenarios.

Control Objective

Protect ePHI systems and media from water damage through detection, known isolation valves, and trained response so leaks do not silently destroy clinical infrastructure.

Implementation Guidance

  1. Map water risks above/adjacent to data centers, IDFs, and records storage (pipes, chillers, roofs).
  2. Install leak detection where risk warrants; alert facilities/NOC.
  3. Identify master shutoff/isolation valves; keep accessible and labeled; brief key personnel.
  4. Test valves periodically where safe; document locations on emergency maps.
  5. Avoid locating critical ePHI systems directly under bathrooms/kitchens when redesigning.
  6. Use drip trays/raised flooring strategies as design allows.
  7. Include water events in CP tabletops.
  8. After any leak, assess media and hardware for integrity before returning to service.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Chiller line leak over storage

Rope water sensors alarm; facilities isolates the valve mapped under PE-15 before water reaches EHR SAN.

Clinic IDF under a sink

Renovation relocates the closet; PE-15 design review blocks placing switches under plumbing.

Night roof leak into HIM

Detection and response protect paper/hybrid records and scanning workstations with ePHI caches.

Best Practices

  • Leak detection in high-risk rooms.
  • Labeled, accessible isolation valves.
  • Key personnel know shutoff locations.
  • Design reviews avoid water-over-IT.
  • CP scenarios include flood/leak.
  • Post-leak hardware/media checks.

Common Gaps & Violations

  • Valves painted over and unknown.
  • No sensors in basement DCs.
  • Critical racks under restrooms.
  • Alarms disabled for nuisance.
  • No after-action when minor leaks occur.

Required Documentation

  • Water damage protection procedure (PE-15)
  • Valve location maps
  • Leak detection inventory and alert paths
  • Training for key personnel
  • Post-incident assessment checklist

How to Test & Validate

  1. Locate isolation valves with staff guidance.
  2. Verify leak detection function/alert path.
  3. Review facility maps for water-over-IT risks.
  4. Check last water-related incident response.
  5. Confirm CP tabletop included water event.

Audit Considerations

Water is a top physical threat to availability. Assessors ask who can shut water off and whether detection exists near ePHI systems.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.310(a) Facility Access Controls — protect against environmental hazards including water.
  • 164.308(a)(7) Contingency Plan — water damage is a classic contingency trigger.
  • 164.310(a)(2)(ii) Facility Security Plan — safeguard equipment from environmental damage.
  • 164.310(d) Device and Media Controls — wet media may require special handling/disposal.

Compliance Tips

  • Label shutoff valves with IT emergency contacts.
  • Put valve maps in the data center emergency binder.
  • Inspect ceilings above racks during PE walkthroughs.

Frequently Asked Questions

Is PE-15 only for data centers?

Apply wherever system components processing ePHI face material water risk — including IDFs and records areas.

Do we need wet-pipe fire suppression alternatives?

Fire suppression choices interact with water risk; document PE-13/PE-15 design tradeoffs for IT spaces.

Who must know the shutoff locations?

Key personnel — typically facilities, security, and data center operators on shift.

References & Resources

  • NIST SP 800-53 Rev. 5 — PE-15
  • Related controls: PE-14, PE-9, CP-2, PE-13

Need Help Implementing PE-15?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.