| Framework | HIPAA Security Rule |
|---|---|
| Control ID | §164.310(d) |
| Control Family | Physical Safeguards > Device & Media |
| Control Name | Device and Media Controls |
| Status | IMPLEMENTED |
| Assessment Date | 2026-04-19T02:25:35.202960+00:00 |
| Assessor | TITAN AI Scanner v2.0 (CONDUCTOR + BASTION + SCOUT + COMPLY + SAGE) |
| Environment Scope | Azure: Pay-As-You-Go (prod) (4f29d094-1079-44c9-acb0-4d73a7a2dd34) |
| Report ID | a858185e0abe2c7a2f4faf2019cafd63b0f3b07cdf00065233c42b33fbe483c9 |
Standard: Device and media controls. Implement policies and procedures that govern the receipt and removal of hardware and electronic media that contain electronic protected health information, into and out of a facility, and the movement of these items within the facility.
Source: https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C/section-164.310
Each implementation specification addressed separately per HIPAA §164.306(d) / NIST 800-53A assessment methodology.
Implement policies and procedures to address the final disposition of electronic protected health information, and/or the hardware or electronic media on which it is stored.
Implement procedures for removal of electronic protected health information from electronic media before the media are made available for re-use.
Maintain a record of the movements of hardware and electronic media and any person responsible therefore.
Summarized with counts + exceptions + drill-down. Raw data available on request per retention policy.
Test of Design (does the control exist?) + Test of Operating Effectiveness (does it work consistently?). Sampling per AICPA AU-C 530.
12 disposals
All 12 had Purge-level sanitization certificates.
Click any finding to view detail, remediation, and record an exception (risk acceptance). Exceptions are retained in the report as part of the audit trail.
No findings for this control.
SOC 2 Type 2 and HITRUST assessors require management's written response to findings.
| Scanner | TITAN AI Scanner v2.0 (CONDUCTOR + BASTION + SCOUT + COMPLY + SAGE) |
|---|---|
| Scanner version | v2.0.1 |
| Collection timestamp | 2026-04-19T02:25:35.202960+00:00 |
| Retention | 2555 days (HIPAA 164.316(b)(2)) |
| Report hash (SHA-256) | a858185e0abe2c7a2f4faf2019cafd63b0f3b07cdf00065233c42b33fbe483c9 |
This same evidence is admissible for the following related controls. Scan once, satisfy multiple frameworks.
MP-6, MP-7, CM-8, CP-9 — same evidence satisfiesCC6.7, CC6.5 — same evidence satisfiesA.8.3, A.11.2.7 — same evidence satisfies9.4, 9.8 — same evidence satisfies08.l, 08.n, 09.o — same evidence satisfies