10.2 Workstation Use and Security: Screen Privacy, Physical Placement, and Clean Desk Standards

Key Takeaways

  • Under 45 CFR § 164.310(b) (Workstation Use) and 45 CFR § 164.310(c) (Workstation Security), both standards are statutory 'Required' safeguards; unlike facility access controls, covered entities have no legal discretion to classify workstation protections as addressable.
  • Under 45 CFR § 164.304, a workstation is broadly defined as an electronic computing device (desktops, laptops, tablets, smartphones) or any device that performs similar functions, and electronic media stored in its immediate environment, encompassing mobile clinical carts (COWs/WOWs).
  • Physical placement of workstations must mitigate visual eavesdropping (shoulder surfing) through angular orientation away from public traffic, recessed desktop wells, and micro-louver privacy filter screens that restrict viewing angles to ±30 degrees.
  • Workstation security controls require combining automatic session inactivity lockouts (3-5 minutes) with mandatory manual lockouts (Windows+L / proximity tap-and-go badges) and enforced Clean Desk / Clear Screen policies that prohibit written passwords and exposed paper charts.
  • Remote and hybrid telework environments require private, dedicated office spaces with lockable doors, screen orientation away from windows and family members, physical security cable locks, and an absolute prohibition on personal use or third-party access.
Last updated: September 2026

Workstation Use and Security: Screen Privacy, Physical Placement, and Clean Desk Standards

Workstations are the primary technological interface through which healthcare workforce members create, view, modify, and transmit electronic Protected Health Information (ePHI). Whether deployed as a desktop computer in an outpatient clinic, a mobile Computer-on-Wheels (COW) in an intensive care unit, a tablet carried by a physician, or a laptop utilized by a remote medical coder, every workstation presents a dual attack surface: logical network threats and physical vulnerabilities.

A workstation positioned in a busy corridor allows unauthorized visitors to view sensitive patient charts over a clinician's shoulder. A laptop left untethered on an emergency department registration desk can be physically stolen in seconds. A mobile cart left logged in allows an inquisitive passerby to browse clinical records.

To mitigate these risks, the HIPAA Security Rule establishes two fundamental, legally mandatory physical standards: Workstation Use (45 CFR § 164.310(b)) and Workstation Security (45 CFR § 164.310(c)).


Statutory Framework: 45 CFR § 164.310(b) & (c) Breakdown

A critical distinction on the AHIMA CHPS examination is that both Workstation Use and Workstation Security are statutory REQUIRED standards. Unlike the Facility Access Controls standards (which consist entirely of addressable specifications), covered entities and business associates have zero legal discretion to treat workstation safeguards as addressable.

Statutory Classification Matrix (45 CFR § 164.310):

┌────────────────────────────────────────┐       ┌────────────────────────────────────────┐
│ 45 CFR § 164.310(a)                    │       │ 45 CFR § 164.310(b) & (c)              │
│ FACILITY ACCESS CONTROLS               │       │ WORKSTATION USE & SECURITY             │
├────────────────────────────────────────┤       ├────────────────────────────────────────┤
│ • Standard: Required                   │       │ • Workstation Use (§ 164.310(b)):      │
│ • (a)(2)(i) Contingency Ops: ADDRESSABLE│      │   REQUIRED STANDARD                    │
│ • (a)(2)(ii) Security Plan: ADDRESSABLE │      │                                        │
│ • (a)(2)(iii) Validation: ADDRESSABLE  │       │ • Workstation Security (§ 164.310(c)): │
│ • (a)(2)(iv) Maintenance: ADDRESSABLE  │       │   REQUIRED STANDARD                    │
└────────────────────────────────────────┘       └────────────────────────────────────────┘

1. Workstation Use (45 CFR § 164.310(b) - Required)

"Implement policies and procedures that specify the proper functions to be performed, the manner in which those functions are to be performed, and the physical attributes of the surroundings of a specific workstation or class of workstation that can access electronic protected health information."

This standard mandates operational policies governing:

  • Permissible business and clinical software applications authorized on workstations.
  • Prohibitions against utilizing clinical computers for unapproved personal web browsing, personal email, or unauthorized external software downloads.
  • Assessment of the physical attributes of the surroundings (e.g., determining whether a workstation is situated in a locked back-office billing room versus a public-facing triage desk).

2. Workstation Security (45 CFR § 164.310(c) - Required)

"Implement physical safeguards for all workstations that access electronic protected health information, to restrict access to authorized users."

This standard mandates physical barriers that prevent unauthorized individuals from physically touching, viewing, manipulating, or carrying away computing hardware.


Statutory Definition of a Workstation (45 CFR § 164.304)

Candidates frequently misinterpret "workstation" as referring exclusively to traditional desktop personal computers bolted to desks. Under 45 CFR § 164.304, the statutory definition is comprehensive:

"Workstation means an electronic computing device, for example, a lap or desk-top computer, or any other device that performs similar functions, and electronic media stored in its immediate environment."

In contemporary clinical environments, this legal definition encompasses:

  • Fixed Desktop Computers: Deployed in administrative offices, HIM coding departments, and laboratory workstations.
  • All-in-One Wall-Mounted Terminals: Installed inside patient examination rooms and triage cubicles.
  • Computers-on-Wheels (COWs) / Workstations-on-Wheels (WOWs): Mobile carts wheeled between inpatient rooms by nursing staff for bedside charting and medication scanning.
  • Clinical Tablets and iPads: Handheld devices utilized by physicians, physical therapists, and emergency medical technicians.
  • Clinical Smartphones / Voicera Badges: Secure mobile devices used for clinical communication, alert notifications, and barcode medication administration (BCMA).
  • Electronic Media in Immediate Environment: USB flash drives, external hard drives, dictation recording units, and magnetic tape cartridges connected to or resting beside the computer.
Workstation CategoryClinical EnvironmentDominant Physical ThreatMandatory Physical Safeguards
Fixed DesktopFront-desk patient registrationShoulder surfing / visual eavesdropping by waiting visitorsMicro-louver privacy filters, recessed counter placement, 2-minute auto-lock.
Exam Room TerminalOutpatient examination roomsPatient/family tampering while clinician leaves roomScreen angled away from exam table, manual lock before exit, locked wall enclosure.
Mobile Cart (COW/WOW)Inpatient medical/surgical hallwaysCart left unattended; unauthorized browsing; physical theftLocking wheel casters, proximity tap-and-go logout, locked computing bay.
Clinical LaptopHome health nurses; traveling cliniciansBurglary from vehicle; physical theft in public transitFull disk encryption (AES-256), Kensington cable lock, hardened carrying case.
Telework DesktopRemote medical coding home officesFamily member viewing; unmonitored home environmentDedicated lockable room, screen angled away from windows, clear desk policy.

Mitigating Visual Eavesdropping: Screen Placement and Privacy Filters

Visual eavesdropping—commonly known as shoulder surfing—occurs when an unauthorized person reads confidential ePHI displayed on an active computer monitor. In clinical facilities, patients, visitors, maintenance contractors, and non-involved workforce members routinely pass within visual range of active screens.

Physical Screen Privacy and Micro-Louver Filtration Mechanics:

             [ Unauthorized Visitor / Waiting Patient: Angle > 30° ]
                                     │
                                     ▼
                      [ Absorbed / Blocked Light: OPAQUE BLACK ]
                                     ▲
                                     │
[ Authorized Clinician ] ──► [ Monitor Display ] ──► [ Direct Line of Sight: CLEAR (±30°) ]
                                     │
                                     ▼
                      [ Absorbed / Blocked Light: OPAQUE BLACK ]
                                     ▲
                                     │
             [ Unauthorized Passerby in Corridor: Angle > 30° ]

Architectural and Positioning Controls

  1. Counter Orientation and Desk Recessing: Reception and registration desks must be physically designed so that monitor displays face directly away from patient waiting areas, entrance doors, and visitor walkways. Monitors can be mounted inside recessed counter wells below the line of sight of standing visitors.
  2. Physical Privacy Filter Screens (Micro-Louver Technology):
    • For any workstation situated where screen re-orientation cannot eliminate public sightlines (e.g., emergency department triage, registration windows, outpatient pharmacy counters), micro-louver optical privacy filters are legally mandatory.
    • Optical Mechanics: Micro-louvers operate like microscopic vertical window blinds. Light emitted from the LCD display passes through only at a perpendicular angle. The viewing cone is narrowed to 60 degrees (±30 degrees from center). An authorized user sitting directly in front of the display sees a crystal-clear image; any individual viewing the screen from an angle greater than 30 degrees sees only an opaque black or dark gold screen.
  3. Privacy Hoods and Glare Shields: Physical visors installed along the perimeter of the monitor block peripheral sightlines from elevated angles or mezzanine walkways.

Inactivity Lockouts, Quick Locks, and Session Management

Even a well-positioned monitor with a privacy filter presents a critical vulnerability if a clinician walks away from an active session, leaving patient charts exposed to anyone who sits at the keyboard.

The Dual-Control Mandate: Technical Timeouts vs. Manual Lockouts

  • Automatic Session Inactivity Lockout: An automated software timer locks the operating system or EHR session after a predefined period of inactivity (no keyboard or mouse interaction). In clinical environments, inactivity lockouts typically range from three (3) to five (5) minutes. For public-facing kiosks or registration desks, the threshold should be shortened to one (1) to two (2) minutes.
  • The "Walk-Away" Fallacy: Candidates frequently assume that configuring an automated 5-minute timeout relieves employees of personal responsibility. Under HIPAA policy, workforce members are required to manually lock their workstations immediately upon stepping away, even for ten seconds. A 5-minute window is more than sufficient for an intruder to exfiltrate patient records, alter medication orders, or install a hardware keylogger.

Proximity-Based Tap-and-Go Authentication (RFID / Imprivata)

To resolve the clinical friction of repeatedly typing complex passwords while maintaining airtight physical security, healthcare systems deploy proximity-based authentication systems (e.g., Imprivata OneSign):

  • Clinicians wear an RFID-enabled smart badge.
  • Tap-In: Clinician taps badge against a USB RFID reader attached to the workstation and enters a short PIN or biometric scan to instantly unlock their specific clinical session.
  • Tap-Out: Upon completing bedside documentation, the clinician taps the badge again (or walks out of Bluetooth/RFID proximity range). The session locks instantly, protecting the ePHI.
  • Fast User Switching: When a second nurse taps their badge at the same workstation, the system instantly switches to their session without terminating the first nurse's background workflow.

Clean Desk and Clear Screen Standards

The physical security of ePHI extends beyond digital displays to physical records resting in the workstation's immediate environment.

Integrated Clean Desk & Clear Screen Operational Protocol:

               ┌────────────────────────────────────────────────────────┐
               │ WORKSTATION IN USE (Authorized Clinician Present)      │
               │ • Clinical charting active; paper records in view      │
               └───────────────────────────┬────────────────────────────┘
                                           │
                        Clinician Steps Away from Workstation
                                           │
                                           ▼
               ┌────────────────────────────────────────────────────────┐
               │ IMMEDIATE WORKFORCE ACTIONS REQUIRED                   │
               ├───────────────────────────┬────────────────────────────┤
               │ CLEAR SCREEN PROTOCOL     │ CLEAN DESK PROTOCOL        │
               ├───────────────────────────┼────────────────────────────┤
               │ • Manual Lockout executed │ • Paper charts locked      │
               │   (Windows+L or Tap-Out)  │ • Prescription pads secured│
               │ • Zero ePHI displayed     │ • Face sheets in shred box │
               │ • Screen Saver / Login UI │ • No written passwords     │
               └───────────────────────────┴────────────────────────────┘

Clean Desk Policy Requirements

  1. Securing Physical Health Records: Physical patient charts, paper face sheets, diagnostic lab printouts, encounter billing slips, and prescription pads must never be left exposed on an unattended desk. When a staff member leaves their workspace, all physical ePHI must be locked inside a desk drawer, filing cabinet, or secure departmental chart rack.
  2. Immediate Document Disposal: Paper documents containing PHI that are no longer needed must be placed immediately into locked cross-cut shredding consoles—never in standard wastebaskets or recycling bins.
  3. Prohibition of Written Passwords (The "Sticky Note" Violation): A widespread violation discovered during HIPAA security audits is the practice of workforce members writing login credentials on adhesive notes affixed to computer monitors, tucked under keyboards, or taped to desk drawers. This practice completely negates access control safeguards and constitutes a severe administrative and physical compliance violation.

Clear Screen Policy Requirements

Whenever a workstation is unattended, the screen must be cleared of all visible ePHI. The display must show either a locked operating system login screen, a password-protected blank screensaver, or an active session lock interface that obscures patient identifiers.


Physical Cable Locks, Tethering, and Mobile Cart Security

Workstations—especially compact form factors like mini-PCs, all-in-one terminals, and laptops—are highly attractive targets for physical theft.

Hardware Tethering with Kensington Security Cables

Under 45 CFR § 164.310(c), covered entities must implement physical barriers to prevent the removal of hardware:

  • Kensington Security Slots (K-Slots): Enterprise workstations, monitors, docking stations, and laptops incorporate standardized reinforced metal slots. Hardened, aircraft-grade galvanized steel security cables with tamper-resistant key or combination locks tether the equipment to immovable structural furniture, wall brackets, or architectural columns.
  • Locking Docking Stations: Laptops utilized in clinical settings are inserted into heavy-gauge steel docking cradles that mechanically lock the laptop in place, requiring a physical key or master supervisor code to release.

Computer-on-Wheels (COW) and Mobile Cart Security

Mobile clinical carts utilized on hospital inpatient floors present unique physical security challenges:

  • Caster Brake Locks: Nursing staff must engage mechanical foot-pedal caster wheel locks whenever a cart is stationary, preventing unmonitored movement.
  • Locked Internal Bays: The CPU tower, mini-PC, battery inverter, and power management electronics must be enclosed in an integrated, key-locked or electronic badge-locked steel compartment inside the cart body.
  • Tethered Peripherals: Handheld barcode medication scanners, digital signature pads, and mobile receipt printers must be physically cable-tethered to the cart frame.
  • Restricted Storage Areas: At the end of every nursing shift, mobile carts must be returned to a dedicated, badge-access storage room or nurse station alcove for overnight battery charging—never left parked in public corridors.

Workstation Relocation, Reassignment, and Decommissioning

When healthcare facilities remodel departments, open new outpatient clinics, or reassign computer hardware, workstations are frequently moved between disparate security zones.

Relocation Risk Assessment Workflow

Under 45 CFR § 164.310(b), an entity must evaluate the physical surroundings of a workstation. Moving a desktop computer from an internal, badge-restricted Medical Records office to a front-desk admitting cubicle in an open lobby radically alters its risk profile:

  1. Pre-Move Surroundings Assessment: Evaluate the new physical environment. Does the new location introduce shoulder surfing sightlines? Will public visitors be seated behind the user? Are privacy filters and cable locks required?
  2. Storage Sanitization: Before reallocating a workstation from one department to another, IT staff must verify that all locally cached ePHI, temporary files, and downloaded clinical documents are sanitized from the local drive.
  3. Hardware Asset Inventory Updates: Update the centralized IT asset management database with the new physical building, floor, room number, asset tag, and assigned department, ensuring unbroken inventory accountability.

Remote and Hybrid Telework Physical Security Standards

The post-HITECH era and recent healthcare workforce trends have resulted in thousands of medical coders, billing specialists, clinical documentation integrity (CDI) specialists, and telehealth providers working from home offices. Remote workstations that process ePHI are legally subject to the exact same HIPAA Security Rule physical safeguard standards (45 CFR § 164.310(b) & (c)) as on-premise hospital computers.

Compliant Healthcare Telework Physical Security Perimeter:

┌────────────────────────────────────────────────────────────────────────┐
│ DEDICATED PRIVATE HOME OFFICE SPACE                                    │
│ • Solid perimeter door with functional physical lock                   │
│ • Screen positioned away from windows and street-level sightlines      │
│ • Zero third-party or family member visual eavesdropping permitted     │
│                                                                        │
│  ┌──────────────────────────────────────────────────────────────────┐  │
│  │ HARDWARE & WORKSPACE CONTROLS                                    │  │
│  │ • Hospital-issued laptop tethered via Kensington cable lock      │  │
│  │ • Full Disk Encryption (AES-256) enforced                        │  │
│  │ • Automatic 3-minute inactivity screen lock                      │  │
│  │ • Clean Desk: Paper notes locked in dedicated file cabinet       │  │
│  │ • Micro-cut cross-cut shredder on-site                           │  │
│  │ • STRICT PROHIBITION: No family browsing or personal use         │  │
│  └──────────────────────────────────────────────────────────────────┘  │
└────────────────────────────────────────────────────────────────────────┘

Mandatory Telework Physical Security Baselines

  1. Dedicated, Private Home Office: Remote workers must perform all ePHI-related duties in a dedicated, private room equipped with a solid, lockable door. Working in open living rooms, dining tables, kitchens, or shared spaces where family members, roommates, or visitors can observe screens is strictly prohibited.
  2. Screen Orientation Relative to Windows: The workstation monitor must be angled perpendicular or opposite to external windows. If an office has street-facing windows, blinds or privacy curtains must be drawn to prevent external visual observation.
  3. The Family Viewing Prohibition: The HIPAA Privacy Rule prohibits the unauthorized disclosure of PHI to any third party—including spouses, children, and relatives. Allowing a spouse to observe a clinical chart or listen to a patient telehealth consultation constitutes an impermissible disclosure.
  4. Absolute Ban on Personal / Family Workstation Use: Employer-issued healthcare laptops must be restricted exclusively to the authorized employee. Family members must never be permitted to browse the internet, check personal email, do schoolwork, or play games on an enterprise computer. Dedicated endpoint management policies must prohibit the installation of unauthorized personal software.
  5. Home Office Clean Desk & Document Destruction: Teleworkers must lock all physical notes containing patient identifiers in a secure lockbox or file cabinet. Teleworkers must be provided with an approved cross-cut shredder (DIN 66399 Level P-4 or higher) or be required to transport paper notes to the primary facility in locked bins for professional destruction.

CHPS Exam Tips and Common Candidate Traps

[!TIP] Exam Tip: Workstation Standards Are REQUIRED Do not let exam questions trick you into believing that Workstation Use (§ 164.310(b)) or Workstation Security (§ 164.310(c)) are addressable specifications. Both are REQUIRED standards. A covered entity cannot waive them or perform a risk assessment to justify not implementing workstation security.

[!WARNING] Candidate Trap: COWs Left Unattended in Patient Corridors A favorite scenario on the CHPS exam depicts a nurse who leaves a mobile cart (COW/WOW) logged in outside a patient room while administering medication. Even if the nurse is away for only two minutes, leaving an unlocked workstation containing ePHI accessible to passing visitors is a direct violation of 45 CFR § 164.310(c).

[!CAUTION] Candidate Trap: Remote Worker Family Access Exam scenarios frequently describe a remote coder whose spouse or child uses their hospital-issued laptop to print school homework or check sports scores while the employee is on a lunch break. Candidates must identify that this practice violates both Workstation Use (§ 164.310(b)) and Workstation Security (§ 164.310(c)), and represents an unpermitted disclosure of ePHI.

Loading diagram...
Comprehensive Workstation Security Architecture Across Physical, Operational, and Telework Environments
Test Your Knowledge

A clinical nurse on an acute medical-surgical inpatient unit pushes a Computer-on-Wheels (COW) cart into the hallway outside Room 412. The nurse leaves the electronic health record session actively displayed on the monitor, with the patient's full medical history, lab results, and HIV status visible, while entering the patient's room to change an intravenous infusion line. The nurse is inside the room for four minutes. During this period, several family members visiting other patients walk past the unattended, unlocked mobile cart. Which statement correctly evaluates this scenario under the HIPAA Security Rule?

A
B
C
D
Test Your Knowledge

A healthcare health system transitions 150 medical billing and coding specialists to permanent remote telework positions. To support home operations, the organization provides each employee with an enterprise-managed laptop pre-configured with full disk encryption and a virtual private network (VPN). During a remote workforce security audit, the Privacy Officer discovers that several coders operate their workstations on dining room tables located in shared family spaces where spouses, teenage children, and visiting guests frequently view the active screens. Additionally, one employee allowed a high school child to use the hospital laptop to write an English essay. How should the Privacy and Security Officers address these findings under HIPAA?

A
B
C
D
Test Your Knowledge

An outpatient pediatric clinic operates a check-in reception counter situated directly across from a crowded patient waiting area. The computer monitors used by registration clerks are angled toward the waiting room chairs, enabling seated parents and visitors to clearly read patient names, insurance details, and clinical intake notes displayed on the screens. What combination of physical and operational controls must the clinic implement to resolve this visual eavesdropping vulnerability in compliance with 45 CFR § 164.310(b)?

A
B
C
D