PE-17 Physical Protection

Alternate Work Site

Medium Risk Moderate Low Cost

PE-17 requires employing organization-defined security controls at alternate work sites, assessing such sites as needed, and providing a means for employees to communicate with information security personnel about security issues. Telehealth clinicians, remote coders, and hybrid admins process ePHI outside the facility — PE-17 extends physical and environmental expectations to those sites without pretending every home is a data center.

Control Objective

Define, communicate, and verify appropriate security controls for alternate work sites where ePHI is accessed, and give remote workforce a clear path to report security issues.

Implementation Guidance

  1. Publish alternate work site / telework security requirements: private workspace, screen privacy, locked storage for paper ePHI, device encryption, secure Wi-Fi, and no public-computer use.
  2. Require telework agreements acknowledging PE-17/PL-4 expectations before remote EHR access.
  3. Prefer organization-managed endpoints (MDM) over BYOD for High-ePHI roles.
  4. Assess higher-risk roles (e.g., bulk coding, revenue cycle) via checklist or virtual walkthrough sampling.
  5. Provide a help channel for remote security issues (lost laptop, suspected shoulder surfing, unsafe printing).
  6. Ban printing ePHI at home unless policy explicitly allows with shredding/return controls.
  7. Align with AC-17 remote access and PE-5/PE-3 concepts adapted for home.
  8. Revisit controls when hybrid policy or tooling changes.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Remote coder in a shared apartment

PE-17 rules require privacy screen, headset for dictation, and no paper charts left on the kitchen table; manager attests quarterly.

Clinician starts telehealth from a café

Policy prohibits public Wi-Fi without org VPN and visual privacy; access attempt from risky network triggers coaching.

Home printer jam leaves ePHI pages visible

Incident reported via the PE-17 security contact path; printing entitlement removed for that role.

Best Practices

  • Written telework security standard.
  • Agreement before remote access.
  • Managed devices for high-risk roles.
  • Sampling assessments of alternate sites.
  • Easy security reporting channel.
  • Restrict home printing of ePHI.

Common Gaps & Violations

  • Remote access granted with no site rules.
  • Paper ePHI shipped home without controls.
  • Public Wi-Fi used for EHR.
  • No way for staff to ask security questions remotely.
  • BYOD with no MDM on coding teams.

Required Documentation

  • Alternate work site / telework security procedure
  • Telework agreement template
  • Minimum control checklist for home sites
  • Assessment/sampling methodology
  • Security contact/reporting instructions for remote staff

How to Test & Validate

  1. Sample remote workers for signed telework/security agreements.
  2. Verify MDM/encryption on endpoints used for ePHI.
  3. Review printing policy compliance.
  4. Confirm security help channel is published and monitored.
  5. Spot-check a high-volume remote role against the checklist.

Audit Considerations

Hybrid work is normal; assessors expect documented alternate-site safeguards — not only facility badge controls under PE-2/PE-3.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.310(a) Facility Access Controls — physical safeguards concepts extend to places where ePHI is accessed, including alternate sites as reasonable and appropriate.
  • 164.310(b) Workstation Use — functions and physical attributes around workstations apply to home workstations.
  • 164.310(c) Workstation Security — physical safeguards for workstations that access ePHI.
  • 164.308(a)(5) Security Awareness — train workforce on telework risks and reporting.

Compliance Tips

  • Put PE-17 requirements in the remote-access approval packet.
  • Offer a simple photo-checklist for managers of remote coding teams.
  • Treat hotel/'workcation' sites as alternate work sites under the same rules.

Frequently Asked Questions

Must we inspect every employee's home?

Not usually — define risk-based assessments and mandatory self-attestations; inspect or interview higher-risk roles as needed.

How does PE-17 relate to AC-19?

AC-19 focuses on mobile device controls; PE-17 focuses on the alternate site environment and associated physical/procedural safeguards.

Are temporary disaster-recovery work sites covered?

Yes — contingency relocation sites should meet PE-17/CP physical security expectations.

References & Resources

  • NIST SP 800-53 Rev. 5 — PE-17
  • NIST SP 800-46 Guide to Enterprise Telework
  • Related controls: AC-17, AC-19, PL-4, MP-2, CP-2

Need Help Implementing PE-17?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.