CM-12 Configuration Management

Information Location

Medium Risk Moderate Low Cost

CM-12 identifies and documents the location of system components and the information processed, stored, or transmitted—and may change location for defined circumstances. Hospitals must know which data center, clinic closet, laptop, or cloud region holds ePHI to support breach scope, warrants, and residency commitments.

Control Objective

Maintain accurate location information for ePHI-bearing components and data sets, and control location changes per policy.

Implementation Guidance

  1. Extend CMDB/asset inventory with physical site, cloud region/account, and data classification.
  2. Tag EHR databases, backups, imaging archives, and endpoints that store ePHI.
  3. Require approval for moving ePHI to new regions/SaaS.
  4. Update location after clinic openings/closures and cloud migrations.
  5. Align with SI-12 information management and MP media tracking.
  6. Support breach risk assessment with location-aware inventories.
  7. Include BA-hosted locations in contracts and inventories.
  8. Audit high-risk portable ePHI locations (laptops, USB—discourage).

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Cloud region move blocked

A team tries to replicate EHR analytics to an unapproved region; CM-12 location controls require privacy/security approval first.

Breach scoping by location

Ransomware hits one clinic VLAN; location inventory quickly lists which servers and backups for that site hold ePHI.

Clinic closure media hunt

Closing a clinic uses CM-12 records to find every on-site server and backup tape before decommission.

Best Practices

  • Location fields mandatory in CMDB for ePHI assets.
  • Approve cross-region/SaaS moves.
  • Include BA-hosted locations.
  • Refresh after M&A and clinic changes.
  • Link to breach playbooks.
  • Minimize uncontrolled portable ePHI.

Common Gaps & Violations

  • CMDB without location or cloud region.
  • Shadow SaaS holding ePHI unknown to inventory.
  • Backups in unknown offsite facilities.
  • Laptop ePHI with no tracking.
  • Stale locations after moves.

Required Documentation

  • Information location standard (CM-12)
  • CMDB location data model
  • Location change approval workflow
  • BA location inventory extracts
  • Sample breach-scope location report

How to Test & Validate

  1. Sample 20 ePHI assets for accurate location fields.
  2. Attempt unapproved cloud region replicate in test—expect block/ticket.
  3. Verify BA-hosted systems appear in inventory.
  4. Reconcile clinic closure checklist to CMDB.
  5. Review last location-change approvals.

Audit Considerations

CM-12 is know-where-it-is control. Assessors use it when testing breach readiness and data residency claims.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.310(d) Device and Media Controls — accountability for hardware/media locations.
  • 164.308(a)(1) Risk Analysis — location affects threat and impact.
  • 164.308(a)(7) Contingency — recovery needs to know where copies live.
  • 164.530 Administrative — organizational oversight of where PHI resides.

Compliance Tips

  • Make cloud region a required tag on ePHI stores.
  • Include imaging and backup appliances, not only EHR DB.
  • Feed CM-12 into BA risk tiers.

Frequently Asked Questions

Is CM-12 only physical location?

Includes physical and logical/cloud locations of components and information.

How related to CM-8?

CM-8 inventories components; CM-12 emphasizes documenting and managing information/component locations.

Do we need GPS on every PC?

No—site/OU/cloud tags and controlled movement of ePHI stores are the practical focus.

References & Resources

  • NIST SP 800-53 Rev. 5 — CM-12
  • Related controls: CM-8, SI-12, MP-5, CP-6

Need Help Implementing CM-12?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.