Device and media

Device and media controls, tied to your asset inventory

Per-asset disposal tracking: every clinic-owned storage device that reaches retired or disposed needs a sanitization record, every paper disposal needs a certificate, every disposal vendor needs a current BAA.

Disposal is the specification most likely to be satisfied in good faith and fail on paper. Someone wiped the tablet. Nobody recorded that they did, and a year later there is no way to show it.

The policy is composed from your clinic’s facts

Your device and media policy is generated against your recorded facts. It covers what counts as a device or media, tracking receipt and removal and movement, disposal under 164.310(d)(2)(i), media re-use under (d)(2)(ii), and six-year records retention. A clinic that keeps paper records gains a clause on destroying PHI paper in the same care.

It also renders your recorded decisions on both addressable specifications: the accountability and movement record at (d)(2)(iii), and data backup before equipment movement at (d)(2)(iv).

This one runs against your real asset inventory

Eight requirements are tracked, and several work per asset rather than per clinic:

  • Every clinic-owned, leased, or rented asset with storage media that has reached retired or disposed status has a sanitization record on file, referencing the NIST SP 800-88 standard.
  • Every paper records disposal has a certificate of destruction attached.
  • Every vendor performing media sanitization or paper shredding is under a current BAA.
  • No improper-disposal incidents are sitting open from the last twelve months.
  • Both addressable decisions are finalized and recorded.
  • The policy is active, adopted, reviewed within twelve months, and its facts have not drifted.

The exclusions are deliberate. Staff-owned devices are outside the sanitization requirement, because you do not dispose of a device you never owned. Lost and stolen assets are excluded too, since those route to incident handling rather than disposal.

With no assets on record at all, this control reports that it cannot be evaluated rather than showing green. An empty inventory does not earn a pass here.

What this is, and what it is not

A sanitization record means someone entered that the device was sanitized, referencing the standard they followed. The system does not wipe the device, and it does not check that the certificate matches a real shredding event. It tracks whether the record exists for every asset that needs one, and tells you which assets are missing theirs.

One thing it does not compute: wiping a device before reassigning it to a new hire. That obligation lives in your policy and in your accountability decision, not in a tracked requirement, so the reassignment checklist stays a human discipline.

What an investigator gets

A dated, adopted policy. A list of every clinic-controlled storage device that left service, each with a sanitization record or a visible gap. Certificates of destruction for paper. Current BAAs on the vendors handling both. The answer to “prove that tablet was wiped,” which is usually the question with no answer.

The regulation: read the rule behind this control.

Ready to get your HIPAA program in order?

No pressure, no pitch. Book a 20-minute call, or just email a question and we'll point you the right way.