Practical tips to safeguard workstations

Written by Reed Tinsley | December 2, 2008

Under HIPAA, each organization must perform its own risk assessment to determine, as the preamble says, "an appropriate solution to a covered entity's workstation security issues." Start with a physical walk-through of your facility, noting the locations of computers, both desktop devices and, if any, portables.

There are many simple antitheft devices for fixed workstations and for portables. You may decide to install a cable lock to tether vulnerable workstations to desks or carts. These cable locks can be used as theft deterrents for printers, fax machines, projectors, and other valuable devices.

Although the rule's physical safeguard standards do not explicitly address the security of servers and network devices, facility security plans should also include locks for your server closet. It is risky to leave servers and network devices in open office areas; they should be kept in a locked closet with access limited to authorized technical staff. If it is not feasible to have a locked closet or room, consider using a special-purpose cage to protect these critical devices.

About the Author

Reed Tinsley CPA

This article is written by Reed Tinsley, a Houston, TX-based CPA with over 30 years of experience advising physicians and medical practices across Texas and the United States. Reed holds certifications as a Certified Valuation Analyst (CVA), Certified Healthcare Business Consultant (CHBC), and Certified Financial Planner (CFP), specializing exclusively in the healthcare sector. He is a published author, nationally recognized speaker, and trusted advisor to physicians on accounting & tax, practice management, and financial planning. Schedule a Free Consultation.

Have questions? I’m here to help.