PE-3 Physical Protection

Physical Access Control

High Risk Moderate Medium Cost

PE-3 requires enforcing physical access authorizations at entry/exit points, verifying individual access authorizations before granting access, controlling ingress/egress with authenticators and audit logs, escorting visitors, securing keys/badges, inventorying physical access devices, and changing combinations/keys when keys are lost or individuals transferred. It turns PE-2 authorizations into real door, badge, and visitor controls around ePHI.

Control Objective

Ensure only authorized people can enter areas housing systems, workstations, or media with ePHI — with logging, visitor control, and credential management.

Implementation Guidance

  1. Control entrances to clinics, wiring closets, server rooms, records rooms, and high-sensitivity areas.
  2. Use badges/PINs/keys matched to PE-2 authorizations; revoke on termination same day.
  3. Maintain visitor sign-in, badges, and escorts in restricted areas.
  4. Log physical access where systems support it; review anomalies.
  5. Inventory keys/badges; rekey or disable after loss or role change.
  6. Secure after-hours access paths and shared tenant building risks.
  7. Position workstations to reduce public shoulder surfing (ties to PE-5).
  8. Test door fail modes (fail secure vs fail safe) against clinical safety needs.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Server closet on a master key

The IT closet shared a master key with facilities vendors. PE-3 moves it to badge access with unique IDs and logs, plus visitor escort rules.

Terminated employee badge still works

A no-longer-employed staff badge opened the records room. PE-3 + HR leaver process disables badges within hours and audits access logs.

Unescorted vendor in clinical areas

A telecom tech walked freely among nursing stations. Visitor policy now requires check-in, badge, and escort in restricted zones.

Best Practices

  • Badge access with prompt revocation.
  • Visitor logs and escorts for sensitive areas.
  • Inventory and rekey discipline.
  • Review physical access logs periodically.
  • Align fail-safe doors with life-safety codes.
  • Coordinate with PE-2 authorization lists.

Common Gaps & Violations

  • Propped-open server room doors.
  • Shared badges or written door codes.
  • No visitor process.
  • Keys not collected at termination.
  • No inventory of who has closet access.

Required Documentation

  • Physical access control procedures
  • Badge/key issuance and revocation SOP
  • Visitor control procedure
  • Access device inventory
  • Sample access logs / review records

How to Test & Validate

  1. Attempt entry to server room without authorization; confirm deny.
  2. Verify a recent termination revoked badge promptly.
  3. Review visitor log completeness for a sample week.
  4. Confirm key/badge inventory accuracy.
  5. Check that physical access logs are retained and reviewed.

Audit Considerations

HIPAA facility access controls are sampled onsite — propped doors and undmanaged keys are obvious findings. Show badge reports and visitor logs.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.310(a)(1) Facility Access Controls — limit physical access to electronic information systems and the facilities where they are housed.
  • 164.310(a)(2)(ii) Facility Security Plan — safeguards to protect the facility and equipment from unauthorized access.
  • 164.310(a)(2)(iii) Access Control and Validation Procedures — control and validate access to facilities based on role.
  • 164.310(c) Workstation Security — physical safeguards for workstations that access ePHI.

Compliance Tips

  • Add badge disable to the same termination checklist as EHR disable (AC-2).
  • Photo-audit server rooms quarterly for propped doors and unlabeled keys.
  • Brief front-desk staff on visitor rules — they are the control owners in many clinics.

Frequently Asked Questions

How does PE-3 differ from PE-2?

PE-2 decides who is authorized; PE-3 enforces and logs physical access at doors and entry points.

Do small clinics need badge systems?

Not always electronic badges — but you still need locks, key control, visitor processes, and authorization lists appropriate to risk.

Are waiting rooms in scope?

Public areas need different treatment; focus PE-3 on restricted areas housing systems/media with ePHI and staff-only clinical zones.

References & Resources

  • NIST SP 800-53 Rev. 5 — PE-3
  • HIPAA § 164.310(a), 164.310(c)
  • Related controls: PE-2, PE-5, MP-2, AC-2

Need Help Implementing PE-3?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.