HIPAA Device and IoT Inventory

You cannot protect ePHI on a device you have never written down. A current inventory of every device that stores, receives, or transmits ePHI is the quiet foundation under your risk analysis, your technical safeguards, and your incident response.

HIPAA never uses the phrase "device inventory." What it requires is device and media controls under 45 CFR § 164.310(d)(1), and an accurate and thorough risk analysis under 45 CFR § 164.308(a)(1)(ii)(A). Both are hard to satisfy honestly without a list of what you actually have.

That gap is where most small practices lose time during an audit or a breach investigation. The question is rarely "do you have a policy." It is "which devices held ePHI, and where are they now."

What Belongs in Your Device Inventory

The obvious entries are workstations, laptops, servers, phones, and tablets. The entries organizations miss are the ones nobody thinks of as computers:

A useful test: if the device disappeared tomorrow, would you need to determine whether it held ePHI? If yes, it belongs in the inventory today, not after it goes missing.

What to Record for Each Device

A list of device names is not an inventory. These are the fields that make it useful when something goes wrong:

Why the IoT Side Is Harder

Traditional IT assets arrive through a process. Connected devices frequently do not. A vendor installs a camera system, a landlord adds a smart thermostat, a manufacturer ships an imaging unit with a default password and a network port. None of it passes through the person who maintains your device list.

These devices also tend to lag on patching and rarely support the access controls described at 45 CFR § 164.312. That combination, unmanaged and hard to secure, is exactly what a risk analysis is meant to surface.

How This Connects to the Rest of Your Program

The inventory is not a standalone deliverable. It feeds your Security Risk Assessment, since you cannot assess risk to assets you have not identified. It sets the scope for your IT audit. It tells your incident response process which devices to check first. And when a device is retired, 45 CFR § 164.310(d)(2) expects a record of how ePHI was removed before disposal.

Kept current, it turns a frantic question into a lookup.

Common Questions

Does HIPAA actually require a device inventory?

HIPAA does not use the words "device inventory." It does require device and media controls at 45 CFR 164.310(d)(1) and an accurate, thorough risk analysis at 45 CFR 164.308(a)(1)(ii)(A). Both are difficult to satisfy without knowing which devices touch ePHI, which is why an inventory is commonly treated as foundational.

Do personal phones belong in the inventory?

If a personal phone accesses email, records, or any system containing ePHI, it is in scope. Many organizations handle this through a BYOD policy that defines what is allowed and what controls apply.

What about printers, cameras, and connected medical equipment?

These are the devices most often missed. Multifunction printers store scanned images, and networked medical equipment can hold or transmit ePHI. If a device stores, receives, or transmits ePHI, it belongs in the inventory.

How often should the inventory be updated?

Update it whenever a device is added, reassigned, or retired, and review the whole list at least once a year alongside your risk analysis. A list that is only correct once a year is not much use during an incident.

What happens to a device when we retire it?

45 CFR 164.310(d)(2) addresses disposal and media re-use. Record the disposal method and date in the inventory so you can show ePHI was removed before the device left your control.

This content is for educational and informational purposes only and should not be construed as legal advice. Organizations should consult legal counsel about their specific obligations.

Not sure what is on your network?

Most organizations find devices they forgot about. Book a 30-minute review and we will walk through it with you.