1. Purpose
This policy establishes physical security controls to protect the servers, workstations, and infrastructure that store, process, or transmit Protected Health Information (PHI) and electronic PHI (ePHI) for EMStool LLC and its Cadence platform customers.
The HIPAA Security Rule (45 CFR §164.310) requires covered entities and business associates to implement physical safeguards to limit physical access to electronic information systems and the facilities in which they are housed, while ensuring that properly authorized access is allowed.
2. Scope
This policy applies to all physical locations where ePHI is stored or processed, including:
- The primary server location housing the Bender server
- Any workstations or devices used to access the Cadence platform
- Any off-site backup media containing ePHI
- All workforce members and authorized visitors who access these locations
3. Server Infrastructure
3.1 Server Inventory
| Server | Role | Location | Authorized Access |
Bender 192.168.0.13 |
Primary application server for all Cadence customer instances — isolated SWAG + MariaDB pair per customer (encrypted ePHI), plus emstool.com, customer provisioning, and the license server |
Private residence / secure server room — Jacob Russell |
Jacob Russell only |
All Cadence infrastructure runs on Bender as of 2026-07-08 — a prior server ("Vincent") previously hosted the production Cadence instance and license server but no longer runs any Cadence-related services or holds any ePHI; it now runs an unrelated personal media/home-lab stack and is out of scope for this policy.
3.2 Physical Access Controls — Server Location
- Servers are located in a locked, access-controlled room within Jacob Russell's private residence
- Physical access is restricted to Jacob Russell
- No visitors, contractors, or third parties are permitted unsupervised access to the server room
- Any maintenance requiring third-party physical access must be approved in advance and supervised at all times by Jacob Russell
- The server location address is not published or disclosed to customers or the public
3.3 Environmental Controls
- Servers are protected from heat, moisture, and power surges via UPS (Uninterruptible Power Supply) and surge protection
- Temperature and ventilation are monitored to prevent hardware failure
- Fire suppression (smoke detector) is present in the server room
4. Workstation Security
4.1 Workstation Use Policy
- Only authorized workforce members may use workstations to access ePHI
- Workstations used to access the Cadence platform must have screen lock enabled with a timeout of 15 minutes or less
- Workstations must not be left unattended while logged into the Cadence application
- Personal devices (phones, tablets, personal laptops) may only be used to access Cadence over a secure, password-protected network
4.2 Remote Access
- All administrative access to servers is via SSH with key-based authentication only — password authentication is disabled
- SSH private keys are stored securely and never transmitted via email or messaging
- Remote administrative sessions must be terminated when not in active use
- VPN or Cloudflare Access is used for any web-based administrative interfaces
5. Media Controls
5.1 Removable Media
- USB drives, external hard drives, or other removable media containing ePHI must be encrypted
- Removable media containing ePHI must be stored in a locked location when not in use
- Media containing ePHI must not be left in vehicles, bags, or other unsecured locations
5.2 Media Disposal
- Hard drives and storage media being decommissioned must be physically destroyed or cryptographically wiped before disposal
- Disposal must be documented including date, media description, and method of destruction
- Standard deletion or formatting is not sufficient — use secure erase tools (e.g.,
shred, DBAN, or physical destruction)
5.3 Database Encryption Key Media
Critical: The MariaDB InnoDB encryption keyfile is stored on the same server as the encrypted data (current test configuration). For production deployments, a backup copy of all encryption keys must be stored on separate encrypted media (USB drive) kept in a physically secure, off-machine location. Loss of the keyfile renders the database unrecoverable.
6. Visitor and Contractor Access
- No visitor or contractor may access server infrastructure without prior written approval from Jacob Russell
- All visitors to the server room must be logged with: name, company, date/time in, date/time out, purpose of visit
- Visitors must be escorted at all times and may not access systems without supervision
- Contractor access credentials must be removed immediately upon completion of work
7. Facility Access Log
A physical access log must be maintained for the server room. The log must include:
| Field | Required |
| Date and time of access | Yes |
| Name of person accessing | Yes |
| Purpose of access | Yes |
| Time of departure | Yes |
| Escort name (if visitor) | If applicable |
Access logs must be retained for a minimum of 6 years.
8. Security Incident Response — Physical
The following physical security events must be reported to the Security Officer immediately:
- Unauthorized entry or attempted entry into the server room
- Theft or loss of any device, drive, or media that may contain ePHI
- Discovery of unauthorized physical access to server hardware
- Natural disaster or environmental event affecting server availability
- Loss or theft of any encryption key or keyfile
All physical security incidents must be documented and evaluated for potential HIPAA breach notification requirements per the Breach Notification Procedure.
9. Annual Review
This policy will be reviewed annually by the Security Officer and updated to reflect any changes in server infrastructure, personnel, or physical location. Reviews will be documented with date and any changes noted.
Security Officer Signature
Jacob Russell, Security Officer