PE-2 Physical Protection

Physical Access Authorizations

Medium Risk Easy Low Cost

PE-2 requires developing, approving, and maintaining a list of individuals with authorized access to the facility where the system resides; issuing authorization credentials; reviewing the list on a defined frequency; and removing individuals when access is no longer required. It is the authorization layer that PE-3 physical controls enforce.

Control Objective

Keep an accurate, approved roster of who is allowed into facilities and sensitive areas that house ePHI systems or media — and revoke promptly when roles change.

Implementation Guidance

  1. Maintain authorization lists by area (building, server room, records room, wiring closet).
  2. Require manager approval before adding physical access rights.
  3. Issue credentials (badge/key) only after authorization is recorded.
  4. Review lists periodically (e.g., quarterly) and after reorgs.
  5. Remove access the same day as termination or role change that no longer needs entry.
  6. Include vendors/cleaners with time-bound authorizations.
  7. Coordinate PE-2 lists with HR and AC-2 logical access terminations.
  8. Store lists securely; limit who can modify them.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Quarterly server-room access review

Review finds two former contractors still listed. PE-2 removes them and PE-3 disables badges before an audit sampling.

Clinician transferred to another site

Badge rights to the old site records room are revoked as part of mover workflow — least privilege for physical space.

Night cleaning crew scope creep

Cleaners had master access including IT closet. Authorization is narrowed to public/clinical areas only; IT closet requires escorted entry.

Best Practices

  • Area-specific authorization lists.
  • Same-day removal on termination.
  • Periodic access reviews with sign-off.
  • Time-bound vendor access.
  • Link HR events to physical access changes.
  • Dual control for approving sensitive-area access.

Common Gaps & Violations

  • Everyone with a badge can enter the server room.
  • Lists never reviewed.
  • Terminations revoke EHR but not badges.
  • Vendors with permanent unreviewed access.
  • No approval trail for who authorized entry rights.

Required Documentation

  • Physical access authorization procedure
  • Current authorized-access lists by area
  • Approval records for new access
  • Periodic review evidence
  • Termination/revocation checklist including physical access

How to Test & Validate

  1. Compare a PE-2 list to active badges for a sensitive area.
  2. Sample a termination for same-day physical revoke.
  3. Verify last review date and sign-off.
  4. Check vendor access end dates.
  5. Confirm approvals exist for recent additions.

Audit Considerations

Facility access authorization is a HIPAA addressable implementation specification. Show lists, reviews, and revocation evidence tied to real doors/areas.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.310(a)(2)(iii) Access Control and Validation Procedures — control and validate a person's access to facilities based on their role or function.
  • 164.310(a)(1) Facility Access Controls — limit physical access to systems and facilities.
  • 164.308(a)(3) Workforce Security — authorization and termination procedures support physical access lists.
  • 164.308(a)(3)(ii)(C) Termination Procedures — remove physical access when employment ends.

Compliance Tips

  • Put physical access on the same JML checklist as system accounts.
  • Review server-room lists more often than general building access.
  • Keep vendor access on a separate list with contract end dates.

Frequently Asked Questions

Is PE-2 only for data centers?

It applies to facilities where the system resides — including clinic areas housing servers, networking gear, and sensitive records storage.

How does PE-2 relate to PE-3?

PE-2 authorizes people; PE-3 enforces entry controls and logging.

Can we use the same list as logical access?

You can correlate them, but physical areas often need narrower subsets than 'all employees.'

References & Resources

  • NIST SP 800-53 Rev. 5 — PE-2
  • HIPAA § 164.310(a)
  • Related controls: PE-3, AC-2, PS-4, PS-5

Need Help Implementing PE-2?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.