Cloud region move blocked
A team tries to replicate EHR analytics to an unapproved region; CM-12 location controls require privacy/security approval first.
CM-12 identifies and documents the location of system components and the information processed, stored, or transmitted—and may change location for defined circumstances. Hospitals must know which data center, clinic closet, laptop, or cloud region holds ePHI to support breach scope, warrants, and residency commitments.
Maintain accurate location information for ePHI-bearing components and data sets, and control location changes per policy.
How this control shows up in healthcare and HIPAA-covered environments.
A team tries to replicate EHR analytics to an unapproved region; CM-12 location controls require privacy/security approval first.
Ransomware hits one clinic VLAN; location inventory quickly lists which servers and backups for that site hold ePHI.
Closing a clinic uses CM-12 records to find every on-site server and backup tape before decommission.
CM-12 is know-where-it-is control. Assessors use it when testing breach readiness and data residency claims.
How this NIST control supports HIPAA Security Rule expectations.
Includes physical and logical/cloud locations of components and information.
CM-8 inventories components; CM-12 emphasizes documenting and managing information/component locations.
No—site/OU/cloud tags and controlled movement of ePHI stores are the practical focus.
Related controls that commonly accompany CM-12.
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.