Skip to main content
Category: Physical and Technical Safeguards

Device and Media Controls

Also known as: Media Protection, Device and Media Control
Simply put

Device and Media Controls are HIPAA Security Rule requirements for safely handling the electronic devices and storage media that hold protected health information. They cover how such media is received, moved, backed up, stored, reused, and disposed of, so that patient data is not exposed when hardware is retired, relocated, or repurposed. The goal is to keep track of where electronic health information physically resides throughout the life of the equipment.

Formal definition

Device and Media Controls is a Physical Safeguard standard under the HIPAA Security Rule, located at 45 CFR § 164.310(d)(1) (readers should verify the citation against the current regulatory text). It applies only to electronic protected health information (ePHI) and governs the receipt, removal, backup, storage, reuse, disposal, and accountability of hardware and electronic media that contain ePHI. Implementation specifications generally address disposal, media re-use, accountability, and data backup and storage; note that HIPAA distinguishes between required and addressable implementation specifications, and addressable does not mean optional, covered entities and business associates must implement the specification, document a reasonable alternative, or document why it is not reasonable and appropriate. This standard is separate from the Privacy Rule (which covers PHI in all forms, including oral and paper) and from technical access-control mechanisms; state law, the HITECH Act, or frameworks such as the HITRUST CSF may impose additional or more specific requirements, and organizations should confirm details against current guidance.

Why it matters

Electronic devices and storage media move through a long lifecycle, they are purchased, deployed, backed up, relocated, repurposed, and eventually retired, and ePHI can persist on them at every stage. Device and Media Controls matter because some of the most avoidable data exposures occur not during active use but at the end of a device's life: a laptop is decommissioned without wiping the drive, a hard drive is sold or recycled with data intact, or backup media is moved without a record of where it went. Without disciplined handling procedures, an organization can lose track of where its electronic health information physically resides.

This standard addresses the physical and procedural side of protecting ePHI, which complements technical controls such as encryption and access management. Because it is a Physical Safeguard under the HIPAA Security Rule, it applies specifically to electronic protected health information and to the hardware and media that hold it, not to paper or oral PHI, which fall under the Privacy Rule. The accountability element is particularly important: knowing which media contains ePHI, who has custody of it, and where it has traveled is what allows an organization to demonstrate that data was not exposed when equipment changed hands.

Failures in disposal and media reuse are a recurring theme in HIPAA enforcement, and organizations should treat this standard as an operational discipline rather than a one-time policy. State law, the HITECH Act, or frameworks such as the HITRUST CSF may impose additional or more specific requirements, so readers should confirm the current expectations against applicable guidance rather than assuming that meeting the baseline HIPAA specifications is sufficient in every context.

Who it's relevant to

Security Officers and IT Asset Managers
Those responsible for the HIPAA Security Rule must build and maintain the policies covering media disposal, reuse, backup, and accountability, and ensure that inventory and chain-of-custody records accurately reflect where ePHI-bearing hardware resides throughout its lifecycle.
Covered Entities and Business Associates
Both are directly subject to the Security Rule and must apply Device and Media Controls to the electronic media and hardware that hold ePHI. Business associates carry these obligations through their defined relationships and associated agreements, and should confirm how the specifications apply to their specific operations.
Auditors and Compliance Assessors
Reviewers evaluating Security Rule conformance examine whether disposal, reuse, accountability, and backup procedures are documented and followed, and whether addressable specifications were implemented or supported by documented reasonable alternatives. They should note that HITRUST CSF or other frameworks may impose additional or more specific control expectations beyond the HIPAA baseline.
IT Operations and Decommissioning Teams
Staff who retire, relocate, or repurpose devices execute the day-to-day sanitization, destruction, and tracking activities that this standard governs. Consistent execution at end-of-life is where many avoidable ePHI exposures are prevented.

Inside Device and Media Controls

Regulatory Classification
Device and Media Controls is a standard within the Physical Safeguards category of the HIPAA Security Rule. It applies specifically to electronic protected health information (ePHI), consistent with the Security Rule's scope, and does not govern PHI in oral or paper form.
Disposal
A required implementation specification addressing policies and procedures for the final disposition of ePHI and the hardware or electronic media on which it is stored. The goal is to ensure that ePHI is not recoverable once media is discarded.
Media Re-use
A required implementation specification addressing the removal of ePHI from electronic media before that media is made available for re-use, so residual data is not exposed to unauthorized parties.
Accountability
An addressable implementation specification concerning the maintenance of records of the movements of hardware and electronic media and the person responsible for them. Addressable does not mean optional; an entity must implement it, adopt an equivalent alternative, or document why it is not reasonable and appropriate.
Data Backup and Storage
An addressable implementation specification concerning creating a retrievable, exact copy of ePHI, when needed, before equipment is moved. Like other addressable specifications, it must be assessed rather than ignored.

Common questions

Answers to the questions practitioners most commonly ask about Device and Media Controls.

Is Device and Media Controls a technical safeguard under the Security Rule?
No. Device and Media Controls is formally categorized as one of the Physical Safeguards under the HIPAA Security Rule, not a technical safeguard. It addresses the physical movement, reuse, and disposal of hardware and electronic media that contain ePHI. While it often works alongside technical safeguards such as encryption, the standard itself sits within the physical safeguard category. Readers should confirm the current regulatory text for the precise categorization.
Since some Device and Media Controls specifications are addressable, can we skip them?
No. Addressable does not mean optional. Under the Security Rule, an addressable implementation specification generally requires a covered entity or business associate to assess whether the specification is reasonable and appropriate in its environment, and then either implement it, implement an equivalent alternative measure, or document why it is not reasonable and appropriate. Simply ignoring an addressable specification is typically not compliant. The required specifications within Device and Media Controls must be implemented, and the addressable ones must still be evaluated and documented.
What types of devices and media does this standard typically cover?
Device and Media Controls generally applies to hardware and electronic media that store or can store ePHI. In most cases this includes items such as workstations, servers, laptops, mobile devices, portable drives, backup media, and other removable storage. The focus is on controlling how such items are handled when they are moved, reused, or disposed of. Organizations should scope coverage based on where ePHI actually resides in their environment and verify details against the current regulation.
How should an organization approach disposal of media containing ePHI?
Disposal is one of the areas addressed by this standard, and organizations generally establish policies and procedures for the final disposition of ePHI and the hardware or media on which it is stored. Common approaches include documented sanitization or destruction methods appropriate to the media type. No single method guarantees that data can never be recovered, so the chosen approach should be reasonable and appropriate for the risk. Confirm specific expectations against current HHS OCR guidance.
What role does documentation play in demonstrating compliance with this standard?
Documentation is typically central to demonstrating compliance. Organizations often maintain records of media movement, reuse decisions, disposal actions, and, where applicable, the rationale for how addressable specifications were addressed. Some organizations also maintain records of hardware and media movements to support accountability. Maintaining such documentation does not by itself guarantee compliance, but it generally supports an organization's ability to show that reasonable and appropriate measures were in place.
Do these controls apply to business associates as well as covered entities?
In general, business associates that create, receive, maintain, or transmit ePHI are directly subject to the Security Rule's safeguard standards, including Device and Media Controls, and these obligations are also typically reinforced through business associate agreements. Subcontractors of business associates that handle ePHI can be subject to similar obligations through the relevant agreements. Organizations should verify the specific obligations that flow through their agreements against the current regulatory framework.

Common misconceptions

Device and Media Controls is a technical safeguard because it deals with hardware and electronic media.
It is formally categorized as a Physical Safeguard standard under the HIPAA Security Rule, even though it concerns electronic media. Readers should confirm the classification against the current regulatory text of the Security Rule.
The addressable implementation specifications (Accountability and Data Backup and Storage) are optional and can be skipped.
Addressable does not mean optional. A covered entity or business associate must assess whether the specification is reasonable and appropriate, implement it where it is, adopt an equivalent alternative measure, or document the rationale for not implementing it.
Deleting files or reformatting media satisfies the disposal and re-use requirements.
The standard is concerned with ensuring ePHI is not recoverable; simple deletion or standard formatting may leave recoverable data. Practitioners should verify that their disposal and media re-use methods actually remove ePHI, and confirm expectations against current guidance.

Best practices

Maintain written policies and procedures covering both the disposal of media containing ePHI and the removal of ePHI from media slated for re-use.
Track the movement of hardware and electronic media, including who is responsible for each item, to satisfy the accountability specification or document an equivalent alternative.
Create a retrievable, exact copy of ePHI where reasonable and appropriate before moving equipment, and document your assessment of this addressable specification.
Document the decision process for each addressable specification, including any equivalent measures adopted or the rationale for not implementing it, to demonstrate that addressable was not treated as optional.
Verify that disposal and re-use methods render ePHI non-recoverable rather than relying on simple deletion or reformatting.
Confirm all classifications, implementation specification requirements, and disposal expectations against the current text of the HIPAA Security Rule, and check whether state law or the HITECH Act imposes additional obligations.