Facility Access Control and Validation Policies, v1.0

Specifies that a health care related organization must have policies to control and validate a person's access to facilities based on their role or function.

Assessment Step

1
Policies for Facility Access Control (PoliciesforFacilityAccessControl)
Does the covered entity or business associate have policies to control and validate a person's access to facilities based on their role or function, including visitor control, and control of access to software programs for testing and revision?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) that support the assessor's response to this assessment step.
A covered entity or business associate must perform these requirements in accordance with Section 164.306 (Security standards: General rules).

Conformance Criteria (1)

Policies for Facility Access Control
The covered entity or business associate must have policies to control and validate a person's access to facilities based on their role or function, including visitor control, and control of access to software programs for testing and revision.
Citations
HIPAA-Security-Rule
45 CFR Section 164.310(a)(2)(iii)
HIPAA-Security-Rule
45 CFR Section 164.306