field note

HIPAA security camera requirements

HIPAA security camera requirements come from 45 CFR 164.310 facility access controls. Cameras are not named. What OCR asks, and how to prove the cameras ran.

2026-08-21

HIPAA security camera requirements are the Security Rule physical safeguards as they apply to cameras a covered entity or business associate uses to limit physical access to electronic information systems and the facilities that house them. 45 CFR 164.310 does not name cameras. It requires policies and procedures that limit physical access to those systems and buildings, while still allowing authorized access. Security for healthcare facilities, under HIPAA, is that control plus proof it operated.

Cameras show up when the facility security plan uses them to watch the doors that lead to rooms where electronic protected health information (ePHI) lives. They fail that job when they go dark and nobody can show they were watching. Footage that captures patients is a separate Privacy Rule problem. It is not a substitute for a working access control.

What 45 CFR 164.310 actually requires

The Security Rule’s physical safeguards are four standards. Only the first one is where cameras usually land.

164.310 standardRequired or addressableWhat it asksWhere cameras show up
Facility access controls, (a)Required standard; four addressable specs under itLimit physical access to electronic information systems and the facilities that house themCameras at those doors, if the plan uses them
Workstation use, (b)RequiredHow and where a workstation that can reach ePHI may be usedNot a camera rule
Workstation security, (c)RequiredPhysical safeguards on those workstations so only authorized users reach themNot a camera rule
Device and media controls, (d)Required standard; mixed specsReceipt, removal, reuse, and disposal of hardware and media that hold ePHIRecorders and storage media, not the dome on the door

Addressable does not mean optional. 45 CFR 164.306(d)(3) requires the entity to assess whether the specification is reasonable and appropriate in its environment. If it is, implement it. If it is not, document why, and implement an equivalent alternative when one is reasonable. OCR’s August 2024 cybersecurity newsletter walks the four facility-access specifications in those terms.

The four specs under facility access controls are all addressable:

  1. Contingency operations. Physical access so people can restore systems in an emergency.
  2. Facility security plan. Policies and procedures that safeguard the facility and the equipment in it from unauthorized physical access, tampering, and theft.
  3. Access control and validation procedures. Role-based access, including visitors, and control of who reaches software used for testing and revision.
  4. Maintenance records. Document repairs and modifications to physical security components: hardware, walls, doors, locks. A camera in the plan belongs in that log when it is installed, moved, or repaired.

None of those sentences say “install cameras.” The facility security plan is where OCR puts them on the list of things a regulated entity might integrate: surveillance cameras, alarms, badges, visitor control, guards, escorts, and mechanical or electronic locks. The list is examples, not a mandate. A clinic that can prove badge control and visitor logs on a server room, and that documented why cameras were not reasonable, has a 164.310 answer. A hospital that wrote “cameras cover the pharmacy” and cannot show those cameras were up is missing the control it claimed.

Where cameras land in the plan

HIPAA facility access controls as a chain. A risk analysis identifies where ePHI is stored. The facility security plan may place cameras at those doors. If a camera is dark, the monitoring the plan claimed is not operating, and maintenance records plus OCR evidence have a hole. 164.310 facility access, if the plan uses cameras risk analysis where ePHI lives facility plan may name cameras cameras at those doors records repairs, six years camera dark plan not operating HIPAA names the control. It does not name the camera. a dark camera on an ePHI door is a failed facility access control, not a facilities ticket
Identify where ePHI is stored, write the plan, then keep the cameras the plan named. A dark dome at that door is the control not operating.

Start with the risk analysis. 45 CFR 164.308(a)(1)(ii)(A) requires an accurate, thorough assessment of risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI the entity holds. Identify where ePHI is stored before you argue about cameras. The server room, the pharmacy system closet, the health-information management file area, the data closet that holds the electronic medical record. Those rooms are why 164.310 exists. A parking-lot camera is not a HIPAA physical safeguard unless the plan put that lot on the path to those systems.

OCR tells entities that share a building, or that do not control the shell, they still own their own facility security plan. Third-party measures in the building have to be in that plan, because they affect it. A hospital in a medical office building does not get to point at the landlord’s lobby camera and stop.

If the plan names cameras, those cameras are in the maintenance-records population. Install, move, repair, replace: date, what changed, where, who did it, who authorized it. OCR’s newsletter uses hardware, walls, doors, and locks as the examples. A camera covering a pharmacy door is hardware related to security.

When footage is PHI

A camera pointed at an ePHI closet is doing facility access control. A camera pointed at a nursing station, an exam room corridor, or a treatment bay can record protected health information: a name on a whiteboard, a wristband, a monitor, a conversation, a patient’s presence in a unit that reveals a diagnosis.

That footage, stored electronically, is ePHI. The Privacy Rule’s minimum-necessary and authorization rules attach. So do the Security Rule’s technical safeguards on whatever stores and transmits it. This page is not a VMS design guide. The operational fact for the fleet is: cameras used as physical safeguards belong on the rooms the risk analysis identified. Cameras used to watch patients are a different program with a different legal load.

Reasonable physical safeguards for patient care areas include the measures HHS already lists for incidental disclosure: limiting who walks those halls, supervising the area, escorting visitors, turning chart faces to the wall, keeping whiteboards and screens out of public view. That is HHS Privacy Rule FAQ 200, not a camera catalog. Putting a dome over a bedside does not satisfy that FAQ, and it can create the PHI you were trying to limit.

HIPAA sets no footage retention clock. The six-year retention in 45 CFR 164.316 is for written policies, procedures, and required documentation. It never mentions video. The split, and the folklore around it, is in video retention requirements. Keep the policy pack six years. Keep footage for whatever the risk analysis and state law actually require.

Healthcare IoT and the camera fleet

Medical IoT and other smart devices in hospitals share a network with the camera fleet more often than the facility security plan admits. IoT examples in healthcare that matter for this page are the cameras, the badge panels, and the workstations on that same segment, not a tour of infusion pumps. Healthcare IoT vulnerabilities that actually get cameras compromised are the same three doors as everywhere else: default or shared credentials, known CVEs in old firmware, and management interfaces reachable from where they should not be. The methods, and why a one-time pass decays, are in IP camera vulnerabilities.

A camera that is in the HIPAA facility security plan and still on a default password is a physical safeguard with an open management path. Hardening the fleet is how that plan stays true after install week. Segment the cameras. Unique credentials, current firmware, valid certificates, closed management. OCR’s stolen-equipment numbers are the other half of 164.310: from 2020 through 2023 the agency received more than 50 large breach reports, affecting more than a million individuals, attributed to stolen equipment and devices that held ePHI. A dark camera on the door to the room that held those devices is the monitoring the plan claimed and did not perform.

Covered entities and business associates both sit under the Security Rule. A clinic, a hospital system, a billing company, a cloud EHR vendor: if they create, receive, maintain, or transmit ePHI, 164.310 applies to the facilities that house the systems. The camera program follows the ePHI, not the letterhead.

What OCR and auditors ask to see

OCR investigates after a breach and in compliance reviews. Independent auditors walk a similar list. The shape matches what auditors actually ask about camera systems: inventory, operation across the period, access, upkeep, proof. On a healthcare facility the requests look like this.

  1. Show where ePHI is stored, and which cameras the facility security plan assigned to those rooms. The risk analysis and the plan have to name the same doors. A commissioning spreadsheet of every dome on campus is not that list.
  2. For those doors, show the cameras were operating on dates in the review period. Not a live view today. History. Outages happen. Undetected outages are the finding.
  3. Show access control and validation: who was allowed in, and how visitors were handled. Badges and visitor logs. Cameras support that story. They do not replace it.
  4. Show maintenance records for the physical security components, including those cameras. Install, repair, move, replace, with dates and names.
  5. Show the six-year documentation: the policies, the plan, the risk analysis, the decisions on addressable specs. Footage is not that pack.

OCR has resolved investigations in which stolen equipment and a missing facility security plan sat on the same record, including Fresenius Medical Care. The finding language is the 164.310(a)(2)(ii) specification: failure to implement policies and procedures to safeguard facilities and equipment from unauthorized access, tampering, and theft. Cameras are one way that specification gets implemented. They are not a defense if the plan never ran.

Doing this across 500 cameras

At one clinic the plan is a binder and a known set of doors. Across a health system the ePHI rooms multiply, the landlord’s lobby coverage gets confused with the entity’s own plan, cameras get added for workplace safety and never enter the 164.310 inventory, and a dark dome on a pharmacy door is filed as a facilities ticket. Maintenance records live in a work-order system that does not know which cameras are HIPAA controls. The six-year policy pack is current. The operating evidence is not.

MentatNOC keeps per-camera health and inventory current for the devices you put under management, records detections and repairs as they happen, and assembles a period into an evidence pack a covered entity or business associate can hand to OCR or to an auditor. Staged firmware and credential work stay in the same trail. It monitors device health, not video. MentatNOC helps you prove your controls operated. It does not certify anyone, and no platform makes an organization HIPAA compliant on its own. The evidence shape is on compliance and proof, and a sample pack runs in the live platform demo.