Already a member or subscriber? Sign in now

Perform a quick HIPAA security check

FPM Editors
March 15, 2018

The HIPAA Security Rule requires practices to protect patients’ health information by establishing physical safeguards such as the following:

• Tweak your office layout. For example, if unauthorized individuals could see protected health information on a monitor through an office window, consider repositioning the computer to prevent that from happening.

• Protect workstations. In exam rooms, nurses’ stations, and other easily accessible areas, require staff members to log off after a specific amount of time to prevent protected health information from being left unattended.

• Establish device and electronic media controls. Because thumb drives, laptops, smartphones, and tablets are easy to move in and out of a practice, they can be a significant security risk. Therefore, practices must have policies and procedures in place to protect the information stored on these devices, such as requiring password protection and limiting who is permitted to use these devices.

Adapted from “The HIPAA Security Rule: Are You in Compliance?

Posted on Mar 14, 2018 by FPM Editors

Copyright © 2026 by the American Academy of Family Physicians.

This content is owned by the AAFP. A person viewing it online may make one printout of the material and may use that printout only for his or her personal, non-commercial reference. This material may not otherwise be downloaded, copied, printed, stored, transmitted or reproduced in any medium, whether now known or later invented, except as authorized in writing by the AAFP. See permissions for copyright questions and/or permission requests.