Unknown imaging PC on the clinical VLAN
Discovery finds a Windows box not in the CMDB storing local studies. It is inventoried, encrypted, patched, or removed — closing a blind spot.
CM-8 requires developing and documenting an inventory of system components that accurately reflects the current system, includes all components within the authorization boundary, is at the level of granularity deemed necessary, and is reviewed/updated for accuracy. You cannot protect, patch, or risk-assess ePHI systems you do not know exist.
Maintain an accurate, current inventory of hardware, software, and cloud components that create, receive, maintain, or transmit ePHI — or support those systems.
How this control shows up in healthcare and HIPAA-covered environments.
Discovery finds a Windows box not in the CMDB storing local studies. It is inventoried, encrypted, patched, or removed — closing a blind spot.
Marketing buys a form SaaS on a credit card. CM-8 + procurement review adds it to inventory, triggers BAA and security review.
Old devices linger with ePHI offline. Inventory reconciliation catches missing return/sanitization tickets (MP-6).
Assessors compare floor reality to inventory lists. Missing assets undermine every other control claim.
How this NIST control supports HIPAA Security Rule expectations.
Enough to manage risk — typically identity, owner, location, ePHI impact, and software/hardware type. Increase granularity for critical systems.
Yes. Include them in the authorization boundary inventory.
Inventory lists what you have; baselines define how each class should be built.
Related controls that commonly accompany CM-8.
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.