Device and Media Controls - Movement Policies, v1.0

Specifies that a health care related organization must document policies that govern the movement of hardware and electronic media that contain electronic protected health information within a facility.

Assessment Step

1
Media Movement Policy (MediaMovementPolicy)
Does the organization document policies that govern the movement of hardware and electronic media that contain electronic protected health information within a facility?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) that support the assessor's response to this assessment step.
A covered entity or business associate must perform these requirements in accordance with Section 164.306 (Security standards: General rules).

Conformance Criteria (1)

Media Movement Policy
The covered entity or business associate must document policies that govern the movement of hardware and electronic media that contain electronic protected health information within a facility.
Citations
HIPAA-Security-Rule
45 CFR Section 164.310(d)(1)
HIPAA-Security-Rule
45 CFR Section 164.306