Facility Access and Physical Security
2025.04.16
It is the goal of ClearHealth to provide a safe and secure environment for all employees. Access to the ClearHealth facilities is limited to authorized individuals only.
ClearHealth works with Subcontractors (e.g., property management companies and facilities management) to assure restriction of physical access to systems used as part of the ClearHealth Platform.
Physical Access to all of ClearHealth’s facilities is limited to only those authorized in this policy. All workforce members are responsible for reporting an incident of unauthorized visitor and/or unauthorized access to ClearHealth’s facility.
ClearHealth, and its subcontractors, control access to the physical buildings/facilities that house these systems/applications, or in which ClearHealth workforce members operate, in accordance with the HIPAA Security Rule 164.310 and its implementation specifications. In an effort to safeguard ePHI from unauthorized access, tampering, and theft, access is allowed to areas only to those persons authorized to be in them and with escorts for unauthorized persons.
Policy Statements
ClearHealth policy requires that
(a) Physical access to ClearHealth facilities is restricted.
(b) All employees are required to wear employee badges at secure facilities (such as server rooms, data centers, labs).
(c) All employees must follow physical security requirements and procedures documented by facility management.
(d) On-site visitors and vendors must be escorted by a ClearHealth employee at all times while on premise.
(e) All workforce members are responsible for reporting an incident of unauthorized visitor and/or unauthorized access to ClearHealth’s facility.
(f) Retain a record for each physical access, including visits, maintenance, and repairs to ClearHealth’s production environments and secure facilities.
- Details must be captured for all maintenance and repairs performed to physical security equipment such as locks, walls, doors, surveillance cameras; and
- All records must be retained for a minimum of seven years.
(g) Building security, such as fire extinguishers and detectors, escape routes, floor warden responsibilities, shall be maintained according to applicable laws and regulations.