This entry is part 23 of 59 in the series Complete Guide to HIPAA Security Final Rule

(d)(1) Standard: Device and media controls. Implement policies and procedures that govern the receipt and removal of hardware and electronic media that contain electronic protected health information into and out of a facility, and the movement of these items within the facility.

The Device and media controls standard has four (4) Implementation specifications:

  • (i) Disposal (Required). I
  • (ii) Media re-use (Required).
  • (iii) Accountability (Addressable).
  • (iv) Data backup and storage (Addressable).
Series Navigation<< 164.316 Policies and procedures and documentation requirements164.312(e)(1) Technical safeguards – Standard: Transmission security >>

Michelle Caswell

Senior Director, Legal & Compliance at Clearwater Compliance
Michelle Caswell has over 14 years legal and healthcare experience and worked as a HIPAA Investigator for the U.S. Department of Health and Human Services, Office for Civil Rights where she ensured covered entities were in compliance with HIPAA, conducted complaint investigations and educated entities on HIPAA compliance. Michelle brings that experience to Clearwater Compliance as Senior Director, Legal and Compliance.