I Just attended a HIPAA security meeting and they told me that any off site ext HD need to be stored in a fireproof safe bolted to the ground and which has a combination known only to the physician !
HIPAA tends to be intentionally vague when it comes to security. I doubt this is necessary. Encryption and common sense would be much easier than bolting a safe to the ground and having to remove/replace the drive daily. Then again those fireproof/waterproof ioSafe drives are pretty nice.
http://www.newegg.com/Product/Product.aspx?Item=N82E16822501025If not, everyone would be using servers with Active Directory.