← HIPAA · Physical safeguards
164.310(b)-(c) — Workstation use and security (R)
Requirement
Specify the proper functions to be performed and the manner in which they are to be performed for workstations that access electronic protected health information, and implement physical safeguards to restrict access to authorised users.
What the engine looks for
Every group below must be satisfied — by an affirmative statement, not a plan, a hedge or a denial — for the control to count as covered. A term ending in … matches any word it begins. Supporting terms do not change the verdict — they raise confidence and distinguish a policy that names a mechanism from one that gestures at a category.
Equivalent controls elsewhere
Matched on shared topics. Satisfying this control usually moves these too.
| Framework | Control | Title | Shared topics |
|---|---|---|---|
| ISO 27001 | A.7.9 | Security of assets off-premises | endpoint physical-security |
| SOC 2 | CC6.4 | Physical access to facilities | physical-security |
| SOC 2 | CC6.8 | Prevention and detection of unauthorised software | endpoint |
| ISO 27001 | A.6.7 | Remote working | endpoint |
| ISO 27001 | A.7.1 | Physical security perimeters | physical-security |
| ISO 27001 | A.7.4 | Physical security monitoring | physical-security |
| ISO 27001 | A.8.1 | User end point devices | endpoint |
| ISO 27001 | A.8.7 | Protection against malware | endpoint |