What you need to know
The HIPAA Security Rule addresses maintenance records for physical security components. Covered workflows should capture relevant door, lock, wall, and hardware changes.
Potentially affected
HIPAA covered entities and business associates operating facilities where physical security components protect electronic protected health information.
DSE recommendation
Link security-related repair and modification records to the affected facility, component, access boundary, approval, test result, and retained compliance documentation.
Bottom line: a lock repair can be both a facilities event and a security-control change. For organizations in scope, the record should establish what security component changed, why, who authorized it, and whether the protected boundary still works as intended.
Source fact: the HIPAA rule addresses security-component maintenance records
45 CFR 164.310(a)(2)(iv) — Maintenance records is part of the facility-access-controls standard for covered entities and business associates. The maintenance-records implementation specification calls for documenting repairs and modifications to the physical components of a facility that are related to security, with examples including hardware, walls, doors, and locks. The regulation identifies that specification as addressable.
Addressable does not mean irrelevant or automatically optional. The HIPAA Security Rule’s implementation framework requires the regulated organization to make and document the appropriate determination based on its circumstances.
Source boundary and applicability
The eCFR is an authoritative, continuously updated online version of the CFR, but it is not an official legal edition. This article is not legal advice or a finding that HIPAA applies to a facility, system, or work order. Scope, implementation decisions, documentation period, and safeguards depend on the entity’s risk analysis, policies, electronic protected health information, facility-access plan, and counsel or compliance interpretation.
Applicability questions
- Does the facility or component protect systems or areas containing electronic protected health information?
- Which documented facility access control or risk-analysis decision depends on it?
- Did the work change a door, lock, wall, hardware, keying, credential, alarm, or monitored state?
- Was temporary access or a compensating control required during repair?
- Where will the record be retained and linked to configuration and test evidence?
DSE recommendation: add a security record to the maintenance workflow
The following steps are DSE recommendations based on the cited source.
Have the HIPAA security or compliance owner define which facilities and components are in scope. For each relevant repair or modification, record asset and location, protected boundary, condition, requested change, requester, authorizer, technicians, dates, parts, key or credential impact, temporary safeguard, final configuration, and post-work test. Avoid including protected health information in the ticket unless necessary and permitted.
Reconcile facilities work orders with PACS configuration, key-control records, drawings, and incident logs. Review repeat repairs and emergency bypasses for a larger control weakness. Document the organization’s treatment of the addressable specification through the established HIPAA process.
Verification and evidence
Retain the applicability decision, policy, work order, before-and-after photos where authorized, parts and configuration record, temporary-control log, door and alarm tests, access review, exception approval, and closeout. Audit a sample from facilities dispatch through the compliance repository to confirm the record is complete and retrievable.
Official references
- 45 CFR 164.310(a)(2)(iv) — Maintenance records – Electronic Code of Federal Regulations
Review the official source
45 CFR 164.310(a)(2)(iv) — Maintenance records · Verified August 25, 2026
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE