Offsite tape vault run
Nightly tapes go to a vault vendor in locked cases with logged pickup, encrypted tapes, and dual custody — MP-5 evidence for auditors.
MP-5 requires protecting and controlling digital and non-digital media during transport outside controlled areas, using cryptography unless otherwise protected, and documenting activities associated with transport. Lost backup tapes and shipped drives remain classic healthcare breach scenarios.
Ensure media containing ePHI is authorized, tracked, and protected (typically encrypted) whenever it leaves controlled areas.
How this control shows up in healthcare and HIPAA-covered environments.
Nightly tapes go to a vault vendor in locked cases with logged pickup, encrypted tapes, and dual custody — MP-5 evidence for auditors.
A laptop with local ePHI is driven by staff without encryption enabled. Policy now requires BitLocker and a transport ticket before movement.
Evidence drive is encrypted, sealed, tracked overnight, and logged end-to-end to the forensics lab.
Lost media breaches are heavily scrutinized. Show encryption plus custody logs — either alone is weaker.
How this NIST control supports HIPAA Security Rule expectations.
That is usually transmission (SC-8). MP-5 focuses on physical/digital media being moved as objects.
Portable systems with ePHI fall under device/media protections; apply encryption, authorization, and loss reporting — often overlapping AC-19 and MP-5 expectations.
If complete, controlled, and retained — yes for many clinics; larger orgs often use ticketing/CMDB workflows.
Related controls that commonly accompany MP-5.
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.