HIPAA Device and IoT Inventory
You cannot protect ePHI on a device you have never written down. A current inventory of every device that stores, receives, or transmits ePHI is the quiet foundation under your risk analysis, your technical safeguards, and your incident response.
HIPAA never uses the phrase "device inventory." What it requires is device and media controls under 45 CFR § 164.310(d)(1), and an accurate and thorough risk analysis under 45 CFR § 164.308(a)(1)(ii)(A). Both are hard to satisfy honestly without a list of what you actually have.
That gap is where most small practices lose time during an audit or a breach investigation. The question is rarely "do you have a policy." It is "which devices held ePHI, and where are they now."
What Belongs in Your Device Inventory
The obvious entries are workstations, laptops, servers, phones, and tablets. The entries organizations miss are the ones nobody thinks of as computers:
- Multifunction printers and copiers. Most have internal drives that retain scanned images long after the job finishes.
- Connected medical equipment. Imaging systems, monitors, and diagnostic devices that store patient data or push it to a network share.
- Network hardware. Routers, firewalls, and access points that carry ePHI even though they never store it.
- Backup media and external drives. Including the ones in a drawer that nobody has touched in two years.
- Personal devices under BYOD. If a phone reaches email containing ePHI, it is in scope regardless of who paid for it.
- Cameras, smart displays, and building systems. The genuinely "IoT" end of the list, often installed by a vendor and never inventoried.
A useful test: if the device disappeared tomorrow, would you need to determine whether it held ePHI? If yes, it belongs in the inventory today, not after it goes missing.
What to Record for Each Device
A list of device names is not an inventory. These are the fields that make it useful when something goes wrong:
- Device type and model. Laptop, workstation, phone, tablet, printer, server, or connected medical device.
- Owner and location. Who is responsible for it and where it normally lives. A device with no owner is a device nobody patches.
- Does it touch ePHI. Stores it, transmits it, or neither. This is the field that drives everything else.
- Encryption status. Whether the drive is encrypted, and how that was confirmed. Relevant to the encryption addressable specification.
- Access controls. Which accounts can reach it, and whether unique user IDs are in place.
- Acquired and retired dates. Including how it was disposed of, so the record survives the device.
Why the IoT Side Is Harder
Traditional IT assets arrive through a process. Connected devices frequently do not. A vendor installs a camera system, a landlord adds a smart thermostat, a manufacturer ships an imaging unit with a default password and a network port. None of it passes through the person who maintains your device list.
These devices also tend to lag on patching and rarely support the access controls described at 45 CFR § 164.312. That combination, unmanaged and hard to secure, is exactly what a risk analysis is meant to surface.
How This Connects to the Rest of Your Program
The inventory is not a standalone deliverable. It feeds your Security Risk Assessment, since you cannot assess risk to assets you have not identified. It sets the scope for your IT audit. It tells your incident response process which devices to check first. And when a device is retired, 45 CFR § 164.310(d)(2) expects a record of how ePHI was removed before disposal.
Kept current, it turns a frantic question into a lookup.
Common Questions
Does HIPAA actually require a device inventory?
HIPAA does not use the words "device inventory." It does require device and media controls at 45 CFR 164.310(d)(1) and an accurate, thorough risk analysis at 45 CFR 164.308(a)(1)(ii)(A). Both are difficult to satisfy without knowing which devices touch ePHI, which is why an inventory is commonly treated as foundational.
Do personal phones belong in the inventory?
If a personal phone accesses email, records, or any system containing ePHI, it is in scope. Many organizations handle this through a BYOD policy that defines what is allowed and what controls apply.
What about printers, cameras, and connected medical equipment?
These are the devices most often missed. Multifunction printers store scanned images, and networked medical equipment can hold or transmit ePHI. If a device stores, receives, or transmits ePHI, it belongs in the inventory.
How often should the inventory be updated?
Update it whenever a device is added, reassigned, or retired, and review the whole list at least once a year alongside your risk analysis. A list that is only correct once a year is not much use during an incident.
What happens to a device when we retire it?
45 CFR 164.310(d)(2) addresses disposal and media re-use. Record the disposal method and date in the inventory so you can show ePHI was removed before the device left your control.
This content is for educational and informational purposes only and should not be construed as legal advice. Organizations should consult legal counsel about their specific obligations.
Not sure what is on your network?
Most organizations find devices they forgot about. Book a 30-minute review and we will walk through it with you.