MP-1 Media Protection

Media Protection Policy and Procedures

High Risk Moderate Medium Cost

MP-1 requires media protection policy and procedures addressing purpose, scope, roles, management commitment, coordination, and compliance, plus procedures to implement the Media Protection family. Healthcare MP-1 covers laptops, USB drives, backup tapes, reusable devices, film, and paper printouts — aligning device encryption, re-use, and destruction with HIPAA device and media controls.

Control Objective

Establish policy and procedures that protect ePHI on digital and physical media throughout storage, transport, reuse, and disposal.

Implementation Guidance

  1. Publish MP-1 policy covering electronic media, removable media, printed PHI, and backup media.
  2. Require encryption of portable devices and media storing ePHI where feasible.
  3. Define approval for removable media use in clinical and research settings.
  4. Specify chain-of-custody for media leaving facilities (couriers, repair, offsite backup).
  5. Mandate sanitization/destruction standards before reuse or disposal (NIST SP 800-88 aligned).
  6. Address paper PHI storage, transport, and shredding.
  7. Review policy annually and after major endpoint or backup technology changes.
  8. Align with MP-2 through MP-7 operational procedures and breach assessment for lost media.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Clinic ships drives for research collation

MP-1 procedures require encrypted drives, logged shipment, and BA agreements before ePHI leaves the site.

Copier end-of-lease

Policy mandates certified sanitization of multifunction printer HDDs that cached patient documents.

Nurse uses personal USB for education slides

Removable media ban/exception process under MP-1 blocks unapproved USB on EHR workstations.

Best Practices

  • Full-disk encryption on portable endpoints.
  • Least use of removable media; DLP where needed.
  • Documented destruction certificates.
  • Paper PHI handling in the same policy family.
  • Offsite backup media encryption and custody.
  • Clear lost-media incident path to IR.

Common Gaps & Violations

  • Unencrypted laptops with cached EHR data.
  • Copiers/printers disposed without sanitization.
  • Backup tapes in unlocked transport.
  • Shadow USB use on nursing units.
  • Paper shred bins overflowing in public areas.

Required Documentation

  • Media protection policy (MP-1)
  • Encryption and removable media procedures
  • Sanitization/disposal standards
  • Chain-of-custody forms/process
  • Policy review records

How to Test & Validate

  1. Verify MP-1 policy covers electronic and paper media.
  2. Sample laptops for encryption compliance.
  3. Review destruction certificates for recent disposals.
  4. Inspect removable media exception logs.
  5. Trace one offsite backup media movement.

Audit Considerations

Lost unencrypted devices remain a top HIPAA breach pattern. MP-1 is the policy foundation assessors expect before sampling encryption and disposal evidence.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.310(d) Device and Media Controls — receipt, final disposition, reuse, accountability, and data backup/storage.
  • 164.312(a)(2)(iv) Encryption and Decryption — address encryption of ePHI where reasonable and appropriate.
  • 164.312(c) Integrity — protect ePHI from improper alteration or destruction on media.
  • 164.316 Policies and procedures — document media protection policy.

Compliance Tips

  • Treat multifunction printers as media devices in inventory.
  • Require encryption status in the asset offboarding checklist.
  • Put MP-1 reminders in biomed and facilities vendor packets.

Frequently Asked Questions

Does MP-1 apply to cloud object storage?

Frame “media” broadly in procedures; cloud storage is often covered under SC/AU, but portable and backup media remain classic MP scope — clarify boundaries in policy.

Is paper PHI in scope?

Yes — HIPAA media/device controls and privacy safeguards expect protection of physical PHI; include paper in MP-1 procedures.

Are encrypted USB drives automatically approved?

No. Policy should still require business need, approval, and logging even when encryption is used.

References & Resources

  • NIST SP 800-53 Rev. 5 — MP-1
  • NIST SP 800-88 Media Sanitization
  • HIPAA § 164.310(d)
  • Related controls: MP-2, MP-4, MP-5, MP-6, SC-28

Need Help Implementing MP-1?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.