Clinic PC blocks personal USB
Unmanaged flash drives cannot copy charts from an EHR workstation.
AC-20(2) enhances AC-20 by focusing on portable storage devices — non-organizationally owned systems. Restrict use of portable storage on non-owned systems and block ePHI copy to unmanaged USB/personal devices without encryption and approval. Covered entities and business associates should implement this with clear ownership, technical enforcement where feasible, and audit evidence aligned to HIPAA Security Rule expectations.
Restrict portable storage device use involving non-organizationally owned systems that could expose ePHI.
How this control shows up in healthcare and HIPAA-covered environments.
Unmanaged flash drives cannot copy charts from an EHR workstation.
Non-owned vendor laptops barred from writing ePHI to USB without loaner encrypted media.
Public-facing devices deny portable storage entirely to prevent casual PHI exfil.
Assessors look for operating evidence of Portable Storage Devices — Non-Organizationally Owned Systems on systems touching ePHI — screenshots, logs, and failed-test results — not only a policy paragraph referencing AC-20(2).
How this NIST control supports HIPAA Security Rule expectations.
Risk-based — at least block unmanaged portable storage from writing ePHI on clinical endpoints.
Treat as non-owned; prefer loaner managed devices for ePHI.
Only if organizationally approved and controlled.
Related controls that commonly accompany AC-20(2).
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.