Facility Access Control and Validation Procedures, v1.0
Specifies that a health care related organization must implement procedures to control and validate a person's access to facilities based on their role or function.
                Assessment Step
| 
                                 
                                            1
                                         
                                        Procedures for Facility Access Control (ProceduresforFacilityAccessControl) 
                                            Does the covered entity or business associate implement procedures to control and validate a person's access to facilities based on their role or function, including visitor control, and control of access to software programs for testing and revision? 
                                            
                                                
                                                
                                                
                                                            Artifact
                                                         
                                                        
                                                            A1 
                                                                Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) that support the assessor's response to this assessment step. 
                                                             | 
A covered entity or business associate must perform these requirements in accordance with Section 164.306 (Security standards: General rules).
Conformance Criteria (1)
| 
                                 Procedures for Facility Access Control 
                                    The covered entity or business associate must implement procedures to control and validate a person's access to facilities based on their role or function, including visitor control, and control of access to software programs for testing and revision. 
                                    
                                        
                                            Citations
                                         
                                        
                                            
                                                    HIPAA-Security-Rule
                                                 
                                                
                                                    45 CFR Section 164.310(a)(2)(iii)
                                                 
                                            
                                                    HIPAA-Security-Rule
                                                 
                                                
                                                    45 CFR Section 164.306
                                                 
                                             |