Device and Media Controls - Disposal Policies, v1.0

Specifies that a health care related organization must have policies to address the final disposition of electronic protected health information, and/or the hardware or electronic media on which it is stored.

Assessment Step

1
Media Disposal Policies (MediaDisposalPolicies)
Does the covered entity or business associate have policies to address the final disposition of electronic protected health information, and/or the hardware or electronic media on which it is stored?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) that support the assessor's response to this assessment step.
Standard: Device and media controls. Implement policies and procedures that govern the receipt and removal of hardware and electronic media that contain electronic protected health information into and out of a facility, and the movement of these items within the facility.


A covered entity or business associate must perform these requirements in accordance with Section 164.306 (Security standards: General rules).

Conformance Criteria (1)

Media Disposal Policies
The covered entity or business associate must have policies to address the final disposition of electronic protected health information, and/or the hardware or electronic media on which it is stored.
Citations
HIPAA-Security-Rule
45 CFR Section 164.310(d)(2)(i)
HIPAA-Security-Rule
45 CFR Section 164.306