← HIPAA · Physical safeguards

164.310(d)(1) — Device and media controls (R)

high media-disposalasset-management

Requirement

Implement policies and procedures that govern the receipt and removal of hardware and electronic media that contain electronic protected health information into and out of a facility, and the movement of these items within the facility, including disposal, media re-use, accountability and data backup and storage.

What the engine looks for

Every group below must be satisfied — by an affirmative statement, not a plan, a hedge or a denial — for the control to count as covered. A term ending in … matches any word it begins. Supporting terms do not change the verdict — they raise confidence and distinguish a policy that names a mechanism from one that gestures at a category.

Required element 1 — any one of
mediahardwaredevice
Required element 2 — any one of
disposalre-usereuseaccountabilitytrackinginventorydispose
Supporting terms — specificity signals
sanitis…sanitiz…wipecertificate of destructionchain of custodyasset lognist 800-88

Equivalent controls elsewhere

Matched on shared topics. Satisfying this control usually moves these too.

FrameworkControlTitleShared topics
SOC 2 CC6.5 Disposal of physical and logical assets media-disposal
ISO 27001 A.5.9 Inventory of information and other associated assets asset-management
ISO 27001 A.7.10 Storage media media-disposal
ISO 27001 A.7.14 Secure disposal or re-use of equipment media-disposal
PCI DSS 4.0.1 9.4 Media with cardholder data is secured and destroyed media-disposal
GLBA 314.4(c)(2) Inventory of data, personnel, devices and systems asset-management
NIST CSF 2.0 ID.AM-01 Inventories of hardware are maintained asset-management
NIST CSF 2.0 ID.AM-05 Assets are prioritised by criticality asset-management