Device and Media Controls - Removal Procedures, v1.0

Specifies that a health care related organization must implement procedures that govern the removal of hardware and electronic media that contain electronic protected health information out of a facility.

Assessment Step

1
Media Removal Procedures (MediaRemovalProcedures)
Does the covered entity or business associate implement procedures that govern the removal of hardware and electronic media that contain electronic protected health information out of a facility?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) that support the assessor's response to this assessment step.
A covered entity or business associate must perform these requirements in accordance with Section 164.306 (Security standards: General rules).

Conformance Criteria (1)

Media Removal Procedures
The covered entity or business associate must implement procedures that govern the removal of hardware and electronic media that contain electronic protected health information out of a facility.
Citations
HIPAA-Security-Rule
45 CFR Section 164.310(d)(1)
HIPAA-Security-Rule
45 CFR Section 164.306