Keep security-related door and lock maintenance records for HIPAA scope

The HIPAA Security Rule addresses maintenance records for physical security components. Covered workflows should capture relevant door, lock, wall, and hardware changes.

Integrated video surveillance and controlled entry at a modern commercial facility.
DSE visual intelligencePhysical securityGuide · 3 min read
Executive summary

What you need to know

The HIPAA Security Rule addresses maintenance records for physical security components. Covered workflows should capture relevant door, lock, wall, and hardware changes.

Potentially affected

HIPAA covered entities and business associates operating facilities where physical security components protect electronic protected health information.

DSE recommendation

Link security-related repair and modification records to the affected facility, component, access boundary, approval, test result, and retained compliance documentation.

Bottom line: a lock repair can be both a facilities event and a security-control change. For organizations in scope, the record should establish what security component changed, why, who authorized it, and whether the protected boundary still works as intended.

Source fact: the HIPAA rule addresses security-component maintenance records

45 CFR 164.310(a)(2)(iv) — Maintenance records is part of the facility-access-controls standard for covered entities and business associates. The maintenance-records implementation specification calls for documenting repairs and modifications to the physical components of a facility that are related to security, with examples including hardware, walls, doors, and locks. The regulation identifies that specification as addressable.

Addressable does not mean irrelevant or automatically optional. The HIPAA Security Rule’s implementation framework requires the regulated organization to make and document the appropriate determination based on its circumstances.

Source boundary and applicability

The eCFR is an authoritative, continuously updated online version of the CFR, but it is not an official legal edition. This article is not legal advice or a finding that HIPAA applies to a facility, system, or work order. Scope, implementation decisions, documentation period, and safeguards depend on the entity’s risk analysis, policies, electronic protected health information, facility-access plan, and counsel or compliance interpretation.

Applicability questions

  • Does the facility or component protect systems or areas containing electronic protected health information?
  • Which documented facility access control or risk-analysis decision depends on it?
  • Did the work change a door, lock, wall, hardware, keying, credential, alarm, or monitored state?
  • Was temporary access or a compensating control required during repair?
  • Where will the record be retained and linked to configuration and test evidence?

DSE recommendation: add a security record to the maintenance workflow

The following steps are DSE recommendations based on the cited source.

Have the HIPAA security or compliance owner define which facilities and components are in scope. For each relevant repair or modification, record asset and location, protected boundary, condition, requested change, requester, authorizer, technicians, dates, parts, key or credential impact, temporary safeguard, final configuration, and post-work test. Avoid including protected health information in the ticket unless necessary and permitted.

Reconcile facilities work orders with PACS configuration, key-control records, drawings, and incident logs. Review repeat repairs and emergency bypasses for a larger control weakness. Document the organization’s treatment of the addressable specification through the established HIPAA process.

Verification and evidence

Retain the applicability decision, policy, work order, before-and-after photos where authorized, parts and configuration record, temporary-control log, door and alarm tests, access review, exception approval, and closeout. Audit a sample from facilities dispatch through the compliance repository to confirm the record is complete and retrievable.

Official references

Primary reference

Review the official source

45 CFR 164.310(a)(2)(iv) — Maintenance records · Verified August 25, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE