{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/keep-security-related-door-and-lock-maintenance-records-for-hipaa-scope/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/keep-security-related-door-and-lock-maintenance-records-for-hipaa-scope/",
        "slug": "keep-security-related-door-and-lock-maintenance-records-for-hipaa-scope",
        "url": "https://update.dsesecurity.com/updates/keep-security-related-door-and-lock-maintenance-records-for-hipaa-scope/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/keep-security-related-door-and-lock-maintenance-records-for-hipaa-scope.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/keep-security-related-door-and-lock-maintenance-records-for-hipaa-scope/"
        },
        "title": "Keep security-related door and lock maintenance records for HIPAA scope",
        "summary": "The HIPAA Security Rule addresses maintenance records for physical security components. Covered workflows should capture relevant door, lock, wall, and hardware changes.",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "important",
            "name": "Important"
        },
        "featured": false,
        "image": {
            "theme": "physical-security",
            "label": "Physical security",
            "alt": "Integrated video surveillance and controlled entry at a modern commercial facility.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/physical-security-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/physical-security-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/physical-security-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "access-control",
                "name": "Access Control",
                "url": "https://update.dsesecurity.com/topic/access-control/"
            },
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-08-25T21:35:48+00:00",
        "modified_at": "2026-08-25T21:36:17+00:00",
        "reviewed_on": "2026-08-25",
        "reading_minutes": 3,
        "word_count": 442,
        "potentially_affected": "HIPAA covered entities and business associates operating facilities where physical security components protect electronic protected health information.",
        "dse_recommendation": "Link security-related repair and modification records to the affected facility, component, access boundary, approval, test result, and retained compliance documentation.",
        "primary_source": {
            "name": "45 CFR 164.310(a)(2)(iv) — Maintenance records",
            "url": "https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C/section-164.310#p-164.310%28a%29%282%29%28iv%29",
            "published_on": null,
            "authority": "www.ecfr.gov"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<p><strong>Bottom line:</strong> a lock repair can be both a facilities event and a security-control change. For organizations in scope, the record should establish what security component changed, why, who authorized it, and whether the protected boundary still works as intended.</p>\n<h2>Source fact: the HIPAA rule addresses security-component maintenance records</h2>\n<p><a href=\"https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C/section-164.310#p-164.310%28a%29%282%29%28iv%29\" target=\"_blank\" rel=\"noopener noreferrer\">45 CFR 164.310(a)(2)(iv) — Maintenance records</a> is part of the facility-access-controls standard for covered entities and business associates. The maintenance-records implementation specification calls for documenting repairs and modifications to the physical components of a facility that are related to security, with examples including hardware, walls, doors, and locks. The regulation identifies that specification as addressable.</p>\n<p>Addressable does not mean irrelevant or automatically optional. The HIPAA Security Rule&#8217;s implementation framework requires the regulated organization to make and document the appropriate determination based on its circumstances.</p>\n<h2>Source boundary and applicability</h2>\n<p>The eCFR is an authoritative, continuously updated online version of the CFR, but it is not an official legal edition. This article is not legal advice or a finding that HIPAA applies to a facility, system, or work order. Scope, implementation decisions, documentation period, and safeguards depend on the entity&#8217;s risk analysis, policies, electronic protected health information, facility-access plan, and counsel or compliance interpretation.</p>\n<h2>Applicability questions</h2>\n<ul>\n<li>Does the facility or component protect systems or areas containing electronic protected health information?</li>\n<li>Which documented facility access control or risk-analysis decision depends on it?</li>\n<li>Did the work change a door, lock, wall, hardware, keying, credential, alarm, or monitored state?</li>\n<li>Was temporary access or a compensating control required during repair?</li>\n<li>Where will the record be retained and linked to configuration and test evidence?</li>\n</ul>\n<h2>DSE recommendation: add a security record to the maintenance workflow</h2>\n<p><em>The following steps are DSE recommendations based on the cited source.</em></p>\n<p>Have the HIPAA security or compliance owner define which facilities and components are in scope. For each relevant repair or modification, record asset and location, protected boundary, condition, requested change, requester, authorizer, technicians, dates, parts, key or credential impact, temporary safeguard, final configuration, and post-work test. Avoid including protected health information in the ticket unless necessary and permitted.</p>\n<p>Reconcile facilities work orders with PACS configuration, key-control records, drawings, and incident logs. Review repeat repairs and emergency bypasses for a larger control weakness. Document the organization&#8217;s treatment of the addressable specification through the established HIPAA process.</p>\n<h2>Verification and evidence</h2>\n<p>Retain the applicability decision, policy, work order, before-and-after photos where authorized, parts and configuration record, temporary-control log, door and alarm tests, access review, exception approval, and closeout. Audit a sample from facilities dispatch through the compliance repository to confirm the record is complete and retrievable.</p>\n<h2>Official references</h2>\n<ul>\n<li><a href=\"https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C/section-164.310#p-164.310%28a%29%282%29%28iv%29\" target=\"_blank\" rel=\"noopener noreferrer\">45 CFR 164.310(a)(2)(iv) — Maintenance records</a> &#8211; Electronic Code of Federal Regulations</li>\n</ul>",
        "content_text": "Bottom line: a lock repair can be both a facilities event and a security-control change. For organizations in scope, the record should establish what security component changed, why, who authorized it, and whether the protected boundary still works as intended.\nSource fact: the HIPAA rule addresses security-component maintenance records\n45 CFR 164.310(a)(2)(iv) — Maintenance records is part of the facility-access-controls standard for covered entities and business associates. The maintenance-records implementation specification calls for documenting repairs and modifications to the physical components of a facility that are related to security, with examples including hardware, walls, doors, and locks. The regulation identifies that specification as addressable.\nAddressable does not mean irrelevant or automatically optional. The HIPAA Security Rule’s implementation framework requires the regulated organization to make and document the appropriate determination based on its circumstances.\nSource boundary and applicability\nThe eCFR is an authoritative, continuously updated online version of the CFR, but it is not an official legal edition. This article is not legal advice or a finding that HIPAA applies to a facility, system, or work order. Scope, implementation decisions, documentation period, and safeguards depend on the entity’s risk analysis, policies, electronic protected health information, facility-access plan, and counsel or compliance interpretation.\nApplicability questions\n\nDoes the facility or component protect systems or areas containing electronic protected health information?\nWhich documented facility access control or risk-analysis decision depends on it?\nDid the work change a door, lock, wall, hardware, keying, credential, alarm, or monitored state?\nWas temporary access or a compensating control required during repair?\nWhere will the record be retained and linked to configuration and test evidence?\n\nDSE recommendation: add a security record to the maintenance workflow\nThe following steps are DSE recommendations based on the cited source.\nHave the HIPAA security or compliance owner define which facilities and components are in scope. For each relevant repair or modification, record asset and location, protected boundary, condition, requested change, requester, authorizer, technicians, dates, parts, key or credential impact, temporary safeguard, final configuration, and post-work test. Avoid including protected health information in the ticket unless necessary and permitted.\nReconcile facilities work orders with PACS configuration, key-control records, drawings, and incident logs. Review repeat repairs and emergency bypasses for a larger control weakness. Document the organization’s treatment of the addressable specification through the established HIPAA process.\nVerification and evidence\nRetain the applicability decision, policy, work order, before-and-after photos where authorized, parts and configuration record, temporary-control log, door and alarm tests, access review, exception approval, and closeout. Audit a sample from facilities dispatch through the compliance repository to confirm the record is complete and retrievable.\nOfficial references\n\n45 CFR 164.310(a)(2)(iv) — Maintenance records – Electronic Code of Federal Regulations",
        "content_markdown": "Bottom line: a lock repair can be both a facilities event and a security-control change. For organizations in scope, the record should establish what security component changed, why, who authorized it, and whether the protected boundary still works as intended.\n\n## Source fact: the HIPAA rule addresses security-component maintenance records\n\n[45 CFR 164.310(a)(2)(iv) — Maintenance records](https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C/section-164.310#p-164.310%28a%29%282%29%28iv%29) is part of the facility-access-controls standard for covered entities and business associates. The maintenance-records implementation specification calls for documenting repairs and modifications to the physical components of a facility that are related to security, with examples including hardware, walls, doors, and locks. The regulation identifies that specification as addressable.\n\nAddressable does not mean irrelevant or automatically optional. The HIPAA Security Rule’s implementation framework requires the regulated organization to make and document the appropriate determination based on its circumstances.\n\n## Source boundary and applicability\n\nThe eCFR is an authoritative, continuously updated online version of the CFR, but it is not an official legal edition. This article is not legal advice or a finding that HIPAA applies to a facility, system, or work order. Scope, implementation decisions, documentation period, and safeguards depend on the entity’s risk analysis, policies, electronic protected health information, facility-access plan, and counsel or compliance interpretation.\n\n## Applicability questions\n\n- Does the facility or component protect systems or areas containing electronic protected health information?\n\n- Which documented facility access control or risk-analysis decision depends on it?\n\n- Did the work change a door, lock, wall, hardware, keying, credential, alarm, or monitored state?\n\n- Was temporary access or a compensating control required during repair?\n\n- Where will the record be retained and linked to configuration and test evidence?\n\n## DSE recommendation: add a security record to the maintenance workflow\n\nThe following steps are DSE recommendations based on the cited source.\n\nHave the HIPAA security or compliance owner define which facilities and components are in scope. For each relevant repair or modification, record asset and location, protected boundary, condition, requested change, requester, authorizer, technicians, dates, parts, key or credential impact, temporary safeguard, final configuration, and post-work test. Avoid including protected health information in the ticket unless necessary and permitted.\n\nReconcile facilities work orders with PACS configuration, key-control records, drawings, and incident logs. Review repeat repairs and emergency bypasses for a larger control weakness. Document the organization’s treatment of the addressable specification through the established HIPAA process.\n\n## Verification and evidence\n\nRetain the applicability decision, policy, work order, before-and-after photos where authorized, parts and configuration record, temporary-control log, door and alarm tests, access review, exception approval, and closeout. Audit a sample from facilities dispatch through the compliance repository to confirm the record is complete and retrievable.\n\n## Official references\n\n- [45 CFR 164.310(a)(2)(iv) — Maintenance records](https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C/section-164.310#p-164.310%28a%29%282%29%28iv%29) – Electronic Code of Federal Regulations"
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/keep-security-related-door-and-lock-maintenance-records-for-hipaa-scope/",
                "url": "https://update.dsesecurity.com/updates/keep-security-related-door-and-lock-maintenance-records-for-hipaa-scope/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-08-25"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/keep-security-related-door-and-lock-maintenance-records-for-hipaa-scope/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Keep security-related door and lock maintenance records for HIPAA scope",
                        "item": "https://update.dsesecurity.com/updates/keep-security-related-door-and-lock-maintenance-records-for-hipaa-scope/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/keep-security-related-door-and-lock-maintenance-records-for-hipaa-scope/#article",
                "identifier": "https://update.dsesecurity.com/updates/keep-security-related-door-and-lock-maintenance-records-for-hipaa-scope/",
                "url": "https://update.dsesecurity.com/updates/keep-security-related-door-and-lock-maintenance-records-for-hipaa-scope/",
                "headline": "Keep security-related door and lock maintenance records for HIPAA scope",
                "description": "The HIPAA Security Rule addresses maintenance records for physical security components. Covered workflows should capture relevant door, lock, wall, and…",
                "abstract": "The HIPAA Security Rule addresses maintenance records for physical security components. Covered workflows should capture relevant door, lock, wall, and hardware changes.",
                "articleBody": "Bottom line: a lock repair can be both a facilities event and a security-control change. For organizations in scope, the record should establish what security component changed, why, who authorized it, and whether the protected boundary still works as intended.\nSource fact: the HIPAA rule addresses security-component maintenance records\n45 CFR 164.310(a)(2)(iv) — Maintenance records is part of the facility-access-controls standard for covered entities and business associates. The maintenance-records implementation specification calls for documenting repairs and modifications to the physical components of a facility that are related to security, with examples including hardware, walls, doors, and locks. The regulation identifies that specification as addressable.\nAddressable does not mean irrelevant or automatically optional. The HIPAA Security Rule’s implementation framework requires the regulated organization to make and document the appropriate determination based on its circumstances.\nSource boundary and applicability\nThe eCFR is an authoritative, continuously updated online version of the CFR, but it is not an official legal edition. This article is not legal advice or a finding that HIPAA applies to a facility, system, or work order. Scope, implementation decisions, documentation period, and safeguards depend on the entity’s risk analysis, policies, electronic protected health information, facility-access plan, and counsel or compliance interpretation.\nApplicability questions\n\nDoes the facility or component protect systems or areas containing electronic protected health information?\nWhich documented facility access control or risk-analysis decision depends on it?\nDid the work change a door, lock, wall, hardware, keying, credential, alarm, or monitored state?\nWas temporary access or a compensating control required during repair?\nWhere will the record be retained and linked to configuration and test evidence?\n\nDSE recommendation: add a security record to the maintenance workflow\nThe following steps are DSE recommendations based on the cited source.\nHave the HIPAA security or compliance owner define which facilities and components are in scope. For each relevant repair or modification, record asset and location, protected boundary, condition, requested change, requester, authorizer, technicians, dates, parts, key or credential impact, temporary safeguard, final configuration, and post-work test. Avoid including protected health information in the ticket unless necessary and permitted.\nReconcile facilities work orders with PACS configuration, key-control records, drawings, and incident logs. Review repeat repairs and emergency bypasses for a larger control weakness. Document the organization’s treatment of the addressable specification through the established HIPAA process.\nVerification and evidence\nRetain the applicability decision, policy, work order, before-and-after photos where authorized, parts and configuration record, temporary-control log, door and alarm tests, access review, exception approval, and closeout. Audit a sample from facilities dispatch through the compliance repository to confirm the record is complete and retrievable.\nOfficial references\n\n45 CFR 164.310(a)(2)(iv) — Maintenance records – Electronic Code of Federal Regulations",
                "datePublished": "2026-08-25T21:35:48+00:00",
                "dateModified": "2026-08-25T21:36:17+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/keep-security-related-door-and-lock-maintenance-records-for-hipaa-scope/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/keep-security-related-door-and-lock-maintenance-records-for-hipaa-scope/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/physical-security-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/physical-security-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Keep security-related door and lock maintenance records for HIPAA scope"
                },
                "articleSection": [
                    "Access Control",
                    "Cybersecurity"
                ],
                "keywords": [
                    "Access Control",
                    "Cybersecurity",
                    "Guide",
                    "Important priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Access Control",
                        "url": "https://update.dsesecurity.com/topic/access-control/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    }
                ],
                "wordCount": 442,
                "timeRequired": "PT3M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "45 CFR 164.310(a)(2)(iv) — Maintenance records",
                    "url": "https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C/section-164.310#p-164.310%28a%29%282%29%28iv%29"
                }
            }
        ]
    }
}