← HIPAA · Physical safeguards
164.310(d)(1) — Device and media controls (R)
Requirement
Implement policies and procedures that govern the receipt and removal of hardware and electronic media that contain electronic protected health information into and out of a facility, and the movement of these items within the facility, including disposal, media re-use, accountability and data backup and storage.
What the engine looks for
Every group below must be satisfied — by an affirmative statement, not a plan, a hedge or a denial — for the control to count as covered. A term ending in … matches any word it begins. Supporting terms do not change the verdict — they raise confidence and distinguish a policy that names a mechanism from one that gestures at a category.
Equivalent controls elsewhere
Matched on shared topics. Satisfying this control usually moves these too.
| Framework | Control | Title | Shared topics |
|---|---|---|---|
| SOC 2 | CC6.5 | Disposal of physical and logical assets | media-disposal |
| ISO 27001 | A.5.9 | Inventory of information and other associated assets | asset-management |
| ISO 27001 | A.7.10 | Storage media | media-disposal |
| ISO 27001 | A.7.14 | Secure disposal or re-use of equipment | media-disposal |
| PCI DSS 4.0.1 | 9.4 | Media with cardholder data is secured and destroyed | media-disposal |
| GLBA | 314.4(c)(2) | Inventory of data, personnel, devices and systems | asset-management |
| NIST CSF 2.0 | ID.AM-01 | Inventories of hardware are maintained | asset-management |
| NIST CSF 2.0 | ID.AM-05 | Assets are prioritised by criticality | asset-management |