R297. Install sensors on information assets

This document contains the details of the security requirements related to the definition and management of physical control in the organization. This requirement establishes the importance of monitoring the integrity of physical and/or digital information assets using sensors.


The organization must have temperature and moisture sensors in areas where digital or physical information assets are stored.


  1. HIPAA Security Rules 164.310(a)(2)(ii): Facility Security Plan: Implement policies and procedures to safeguard the facility and the equipment therein from unauthorized physical access, tampering, and theft

  2. HIPAA Security Rules 164.310(c): Workstation Security: Implement physical safeguards for all workstations that access electronic protected health information to restrict access to authorized users.

