Device and Media Controls
Device and Media Controls are HIPAA Security Rule requirements for safely handling the electronic devices and storage media that hold protected health information. They cover how such media is received, moved, backed up, stored, reused, and disposed of, so that patient data is not exposed when hardware is retired, relocated, or repurposed. The goal is to keep track of where electronic health information physically resides throughout the life of the equipment.
Device and Media Controls is a Physical Safeguard standard under the HIPAA Security Rule, located at 45 CFR § 164.310(d)(1) (readers should verify the citation against the current regulatory text). It applies only to electronic protected health information (ePHI) and governs the receipt, removal, backup, storage, reuse, disposal, and accountability of hardware and electronic media that contain ePHI. Implementation specifications generally address disposal, media re-use, accountability, and data backup and storage; note that HIPAA distinguishes between required and addressable implementation specifications, and addressable does not mean optional, covered entities and business associates must implement the specification, document a reasonable alternative, or document why it is not reasonable and appropriate. This standard is separate from the Privacy Rule (which covers PHI in all forms, including oral and paper) and from technical access-control mechanisms; state law, the HITECH Act, or frameworks such as the HITRUST CSF may impose additional or more specific requirements, and organizations should confirm details against current guidance.
Why it matters
Electronic devices and storage media move through a long lifecycle, they are purchased, deployed, backed up, relocated, repurposed, and eventually retired, and ePHI can persist on them at every stage. Device and Media Controls matter because some of the most avoidable data exposures occur not during active use but at the end of a device's life: a laptop is decommissioned without wiping the drive, a hard drive is sold or recycled with data intact, or backup media is moved without a record of where it went. Without disciplined handling procedures, an organization can lose track of where its electronic health information physically resides.
This standard addresses the physical and procedural side of protecting ePHI, which complements technical controls such as encryption and access management. Because it is a Physical Safeguard under the HIPAA Security Rule, it applies specifically to electronic protected health information and to the hardware and media that hold it, not to paper or oral PHI, which fall under the Privacy Rule. The accountability element is particularly important: knowing which media contains ePHI, who has custody of it, and where it has traveled is what allows an organization to demonstrate that data was not exposed when equipment changed hands.
Failures in disposal and media reuse are a recurring theme in HIPAA enforcement, and organizations should treat this standard as an operational discipline rather than a one-time policy. State law, the HITECH Act, or frameworks such as the HITRUST CSF may impose additional or more specific requirements, so readers should confirm the current expectations against applicable guidance rather than assuming that meeting the baseline HIPAA specifications is sufficient in every context.
Who it's relevant to
Inside Device and Media Controls
Common questions
Answers to the questions practitioners most commonly ask about Device and Media Controls.