PE-4 Physical Protection

Access Control for Transmission Medium

High Risk Moderate Medium Cost

PE-4 requires controlling physical access to information system distribution and transmission lines within organizational facilities. Exposed Ethernet in waiting areas, unlocked IDF closets on clinic floors, and shared telecom rooms allow tap, disconnect, or rogue device insertion on networks carrying ePHI.

Control Objective

Prevent unauthorized physical access to cabling and transmission pathways that carry ePHI so attackers cannot easily tap, splice, or disrupt clinical network communications.

Implementation Guidance

  1. Identify distribution points: MDF/IDF, under-floor trays, wall ports in public areas, wireless controllers, and telecom demarc rooms.
  2. Lock closets; badge or key control with logging where feasible.
  3. Avoid open cabling runs through publicly accessible spaces; use conduit/raceway.
  4. Disable unused wall ports in lobbies and conference rooms near clinical networks.
  5. Separate guest Wi-Fi physically/logically; protect backbone pathways nonetheless.
  6. Escort vendors working on cabling; document work (pair with MA-5/PE-2).
  7. Inspect periodically for rogue taps, unknown devices, or damaged locks.
  8. Include off-site clinics and leased suites in PE-4 scope — not only the data center.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Unlocked IDF behind registration

A closet with EHR VLAN switches sits unlocked beside a waiting room. PE-4 mandates badge locks and removal of spare patch cables left dangling.

Ethernet jack in the café

Public jack bridges to production. PE-4/port security disables it or places it solely on guest isolation.

Cabling vendor after hours

Fiber work in the MDF requires escorted access and documented patch changes so undocumented taps are not introduced.

Best Practices

  • Locked distribution rooms with access logs.
  • Disable unused public ports.
  • Conduit for exposed runs.
  • Periodic physical inspections.
  • Escort for cabling vendors.
  • Include ambulatory sites.

Common Gaps & Violations

  • Clinic IDFs propped open for convenience.
  • Live jacks in public spaces on prod VLANs.
  • No inventory of who has closet keys.
  • Shared telecom rooms with other tenants unlocked to all.
  • Patch panels unlabeled and unsupervised.

Required Documentation

  • PE-4 transmission medium protection procedure
  • Inventory of MDF/IDF and key distribution points
  • Physical access control evidence for closets
  • Port disable / inspection records
  • Vendor escort rules for cabling work

How to Test & Validate

  1. Inspect sample IDFs for locks and door status.
  2. Test public area jacks for network access.
  3. Review badge logs for telecom rooms.
  4. Confirm unused ports disabled in a lobby sample.
  5. Interview facilities on key control for closets.

Audit Considerations

Physical network access can bypass many logical controls. Assessors touring clinics often find propped IDF doors — a straightforward PE-4 finding with HIPAA facility-access implications.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.310(a) Facility Access Controls — limit physical access to electronic information systems and the facilities in which they are housed.
  • 164.310(a)(2)(ii) Facility Security Plan — safeguard equipment from unauthorized physical access, tampering, and theft.
  • 164.312(e) Transmission Security — physical protection of transmission medium complements technical transmission controls.
  • 164.308(a)(1) Risk Analysis — exposed cabling is a physical/technical risk to ePHI.

Compliance Tips

  • Add IDF door-prop alarms where practical.
  • Include PE-4 checks in monthly clinic security walkthroughs.
  • Coordinate with network team so physical port security matches VLAN design.

Frequently Asked Questions

Does PE-4 apply to wireless?

PE-4 targets physical transmission medium (cabling/distribution). Protect APs and controllers physically as well; wireless RF risks are addressed under other SC/AC controls.

Are patch cords in a locked rack enough?

Lock the room/rack and control who can open it — an unlocked closet with a locked rack still fails if the rack key is widely shared.

What about cable pathways above ceilings?

Control access to those spaces in sensitive areas and avoid leaving live spare drops unterminated in public ceilings when feasible.

References & Resources

  • NIST SP 800-53 Rev. 5 — PE-4
  • Related controls: PE-2, PE-3, AC-4, SC-7, MA-5

Need Help Implementing PE-4?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.