EMStool LLC — Cadence MIH Scheduling Platform

Physical Security Policy

Policy #: HIPAA-SEC-004 Effective Date: June 1, 2026 Version: 1.0 Next Review: June 1, 2027

1. Purpose

This policy establishes physical security controls to protect the servers, workstations, and infrastructure that store, process, or transmit Protected Health Information (PHI) and electronic PHI (ePHI) for EMStool LLC and its Cadence platform customers.

The HIPAA Security Rule (45 CFR §164.310) requires covered entities and business associates to implement physical safeguards to limit physical access to electronic information systems and the facilities in which they are housed, while ensuring that properly authorized access is allowed.

2. Scope

This policy applies to all physical locations where ePHI is stored or processed, including:

3. Server Infrastructure

3.1 Server Inventory

ServerRoleLocationAuthorized Access
Bender
192.168.0.13
Primary application server for all Cadence customer instances — isolated SWAG + MariaDB pair per customer (encrypted ePHI), plus emstool.com, customer provisioning, and the license server Private residence / secure server room — Jacob Russell Jacob Russell only

All Cadence infrastructure runs on Bender as of 2026-07-08 — a prior server ("Vincent") previously hosted the production Cadence instance and license server but no longer runs any Cadence-related services or holds any ePHI; it now runs an unrelated personal media/home-lab stack and is out of scope for this policy.

3.2 Physical Access Controls — Server Location

3.3 Environmental Controls

4. Workstation Security

4.1 Workstation Use Policy

4.2 Remote Access

5. Media Controls

5.1 Removable Media

5.2 Media Disposal

5.3 Database Encryption Key Media

Critical: The MariaDB InnoDB encryption keyfile is stored on the same server as the encrypted data (current test configuration). For production deployments, a backup copy of all encryption keys must be stored on separate encrypted media (USB drive) kept in a physically secure, off-machine location. Loss of the keyfile renders the database unrecoverable.

6. Visitor and Contractor Access

7. Facility Access Log

A physical access log must be maintained for the server room. The log must include:

FieldRequired
Date and time of accessYes
Name of person accessingYes
Purpose of accessYes
Time of departureYes
Escort name (if visitor)If applicable

Access logs must be retained for a minimum of 6 years.

8. Security Incident Response — Physical

The following physical security events must be reported to the Security Officer immediately:

All physical security incidents must be documented and evaluated for potential HIPAA breach notification requirements per the Breach Notification Procedure.

9. Annual Review

This policy will be reviewed annually by the Security Officer and updated to reflect any changes in server infrastructure, personnel, or physical location. Reviews will be documented with date and any changes noted.

Security Officer Signature
Jacob Russell, Security Officer
Date
June 1, 2026