Skip to main content
green gradient background, "The Future of Application Security Is Already Here." and a read the report button.
Should You Prioritize Digital or Physical Data Controls?Incident & Breach Response
5 min readFor Data Privacy Officers

Should You Prioritize Digital or Physical Data Controls?

The question at hand

Your team just passed its annual SOC 2 audit with clean findings on endpoint detection, encryption at rest, and privileged access management. Two weeks later, a janitorial contractor throws patient intake forms into a dumpster instead of the secure destruction bin. You're writing breach notification letters to thousands of individuals.

This scenario isn't hypothetical. Regional Center of Orange County faced exactly this situation on May 27, 2026, when paper records containing names, addresses, and personal health information were mistakenly disposed of in regular trash bins. The documents were gone before anyone could retrieve them.

The debate: Should compliance programs focus more on digital controls than physical safeguards, or does the reverse make more sense? Where you land on this question shapes everything from budget allocation to audit scope to training priorities.

The case for digital-first programs

Most data privacy officers argue that digital controls deserve the majority of resources. The reasoning is straightforward: your attack surface is overwhelmingly digital.

American Addiction Centers learned this on May 12, 2026, when an unauthorized party accessed their Salesforce instance and exfiltrated names, contact information, Social Security numbers, and health insurance data. Oculus Pathology dealt with compromised email accounts between March 31 and April 2, 2026, exposing not just personally identifiable information but also financial account numbers, payment card data, and protected health information.

These incidents reflect where threat actors actually operate. You don't see organized crime rings breaking into file rooms at 2 a.m. You see credential stuffing attacks, business email compromise, and API exploits. The NIST Cybersecurity Framework (CSF) 2.0 dedicates entire function categories to digital asset management, identity and access management, and data security because that's where breaches happen at scale.

Third-party vendor risks compound the digital problem. American Addiction Centers' breach involved their Salesforce environment, a system managed by external specialists. When you integrate SaaS platforms, API connections, and cloud storage, you're extending your security perimeter into environments you don't fully control. NIST SP 800-171 and ISO/IEC 27001 Annex A control A.5.19 both require formal supplier relationship management, but implementing those controls demands technical expertise and continuous monitoring.

From a risk quantification standpoint, digital breaches also tend to expose more records faster. Email compromise can leak thousands of messages in minutes. A misconfigured S3 bucket can expose entire databases. Physical records, by contrast, are limited by what someone can physically carry or photograph.

The case for physical-first programs

The counterargument starts with a simple observation: you can't encrypt paper.

Physical records don't have multi-factor authentication. They don't log access attempts. They can't be remotely wiped. Once a document leaves secure storage, whether through improper disposal, theft, or simple loss, you have zero technical controls to prevent further exposure. Regional Center of Orange County couldn't deploy incident response playbooks to retrieve documents from a garbage truck.

Organizations that handle sensitive data in physical form face risks that digital-first programs often underestimate. Healthcare providers maintain paper consent forms, lab results, and intake questionnaires. Legal firms keep physical case files. Financial institutions store signature cards and account opening documents. These records often contain the exact data elements that trigger breach notification under the Health Insurance Portability and Accountability Act and state laws: Social Security numbers, diagnoses, account numbers.

The HIPAA Security Rule explicitly requires administrative, physical, and technical safeguards. Physical safeguards aren't an afterthought. They're a regulatory requirement with enforcement teeth. Facility access controls, workstation security, and device and media controls all fall under 45 CFR § 164.310. If your audit program treats these as checkbox exercises while pouring resources into penetration testing and SIEM tuning, you're building a compliance gap.

Training failures hit harder with physical data. An employee who clicks a phishing link might trigger your endpoint detection and response platform. An employee who tosses intake forms in the wrong bin has already caused the breach before anyone notices. There's no technical control that catches human error with paper records in real time.

Physical breaches also carry unique reputational risks. When a contractor improperly disposes of patient records, the headline isn't "sophisticated threat actor exploits zero-day vulnerability." It's "nonprofit throws disability records in trash." The optics are worse because the failure feels more preventable, more careless.

Where practitioners actually land

Most mature compliance programs don't choose one approach over the other. They weight controls based on data flow analysis, not theoretical preferences.

Start by mapping where sensitive data actually lives and moves. If you're processing Data Subject Access Requests under the General Data Protection Regulation, you need to know whether responsive records exist in SharePoint, email archives, or filing cabinets. That inventory tells you where to focus.

Then assess breach likelihood and impact for each storage type. If you maintain three filing cabinets of paper records from legacy systems but process 50,000 digital transactions daily, your risk profile is clear. Conversely, if you're a medical practice that still collects paper intake forms before digitizing them, that intake process is a critical control point.

The organizations that manage both well build parallel control frameworks. For digital systems: Role-Based Access Control, encryption, logging, and vendor risk assessments. For physical records: locked storage, clean desk policies, witnessed destruction, and contractor oversight. ISO/IEC 27002 control 5.10 (acceptable use of information) and control 5.14 (information transfer) apply to both domains.

Training becomes the bridge. Oculus Pathology's email compromise suggests employees need better recognition of phishing and credential theft tactics. Regional Center of Orange County's disposal incident points to gaps in vendor management and physical security awareness. You can't train one without the other if your data exists in both forms.

Our take

Prioritize digital controls if your data is primarily digital, but don't let that priority become neglect of physical safeguards.

The disposal incident at Regional Center of Orange County happened because someone assumed physical security was simple enough to handle with basic procedures. It's not. Physical controls require the same rigor you apply to technical controls: documented processes, regular training, vendor oversight, and audit verification.

Here's what that looks like practically. Include physical security scenarios in your annual awareness training, not as an afterthought slide but as case studies with real consequences. When you conduct vendor risk assessments, don't limit scope to SaaS providers and cloud hosts. Assess janitorial services, document destruction vendors, and anyone with physical access to areas where sensitive data is stored or processed.

Audit both. Your SOC 2 Type II report should test physical access controls and media disposal procedures with the same sampling rigor applied to logical access reviews. If your auditor isn't requesting evidence of witnessed destruction certificates or facility access logs, you're getting an incomplete assessment.

The American Addiction Centers breach via Salesforce and the Regional Center disposal incident aren't competing narratives. They're complementary warnings. You need technical depth on digital threats and operational discipline on physical handling. Budget accordingly, train comprehensively, and audit both domains every cycle.

Application Security Isn’t Optional Anymore.

You Might Also Like