Quarterly server-room access review
Review finds two former contractors still listed. PE-2 removes them and PE-3 disables badges before an audit sampling.
PE-2 requires developing, approving, and maintaining a list of individuals with authorized access to the facility where the system resides; issuing authorization credentials; reviewing the list on a defined frequency; and removing individuals when access is no longer required. It is the authorization layer that PE-3 physical controls enforce.
Keep an accurate, approved roster of who is allowed into facilities and sensitive areas that house ePHI systems or media — and revoke promptly when roles change.
How this control shows up in healthcare and HIPAA-covered environments.
Review finds two former contractors still listed. PE-2 removes them and PE-3 disables badges before an audit sampling.
Badge rights to the old site records room are revoked as part of mover workflow — least privilege for physical space.
Cleaners had master access including IT closet. Authorization is narrowed to public/clinical areas only; IT closet requires escorted entry.
Facility access authorization is a HIPAA addressable implementation specification. Show lists, reviews, and revocation evidence tied to real doors/areas.
How this NIST control supports HIPAA Security Rule expectations.
It applies to facilities where the system resides — including clinic areas housing servers, networking gear, and sensitive records storage.
PE-2 authorizes people; PE-3 enforces entry controls and logging.
You can correlate them, but physical areas often need narrower subsets than 'all employees.'
Related controls that commonly accompany PE-2.
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.