MP-5 Media Protection

Media Transport

High Risk Moderate Low Cost

MP-5 requires protecting and controlling digital and non-digital media during transport outside controlled areas, using cryptography unless otherwise protected, and documenting activities associated with transport. Lost backup tapes and shipped drives remain classic healthcare breach scenarios.

Control Objective

Ensure media containing ePHI is authorized, tracked, and protected (typically encrypted) whenever it leaves controlled areas.

Implementation Guidance

  1. Define what 'transport' includes: courier to offsite storage, staff carrying drives between clinics, shipping devices for repair, and hand-carrying backup media.
  2. Require approval before ePHI media leaves a controlled site.
  3. Encrypt portable media by default; manage keys separately from the shipment.
  4. Use chain-of-custody forms/logs: who, what asset, destination, carrier, timestamps.
  5. Prefer network backup replication over physical tape transport when feasible.
  6. Vet couriers and track packages; restrict unlabeled media.
  7. Train staff never to leave ePHI drives in vehicles overnight.
  8. Align with MP-6 if transport ends in disposal or vendor RMA.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Offsite tape vault run

Nightly tapes go to a vault vendor in locked cases with logged pickup, encrypted tapes, and dual custody — MP-5 evidence for auditors.

Clinic-to-clinic PC move

A laptop with local ePHI is driven by staff without encryption enabled. Policy now requires BitLocker and a transport ticket before movement.

Drive shipped for forensics

Evidence drive is encrypted, sealed, tracked overnight, and logged end-to-end to the forensics lab.

Best Practices

  • Encrypt portable ePHI media by default.
  • Chain-of-custody for every transport.
  • Minimize physical media movement.
  • Separate encryption keys from packages.
  • Approved carriers only.
  • Vehicle and overnight storage rules.

Common Gaps & Violations

  • Unencrypted backup tapes in personal cars.
  • No logs of who took media offsite.
  • USB sticks with ePHI mailed casually.
  • Repair RMAs without protection.
  • Assuming 'it's just going next door' needs no controls.

Required Documentation

  • Media transport procedure
  • Encryption requirements for portable media
  • Chain-of-custody templates and samples
  • Approved courier list
  • Incident procedure for lost media in transit

How to Test & Validate

  1. Review recent transport logs for completeness.
  2. Verify encryption on a sample portable backup set.
  3. Tabletop a lost-package scenario.
  4. Confirm repair/RMA shipments follow MP-5.
  5. Interview staff who move equipment between sites.

Audit Considerations

Lost media breaches are heavily scrutinized. Show encryption plus custody logs — either alone is weaker.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.310(d)(2)(iii) Accountability — maintain records of movement of hardware and electronic media.
  • 164.310(d)(1) Device and Media Controls — protect hardware/electronic media containing ePHI.
  • 164.312(a)(2)(iv) Encryption — addressable encryption commonly applied to media in transit.
  • 164.312(e) Transmission Security — when media transport is an alternative to network transmission, protect confidentiality.

Compliance Tips

  • Default to encrypted portable drives issued by IT only.
  • Eliminate tape runs where cloud/immutable network replication is viable.
  • Add transport checks to multi-site equipment move tickets.

Frequently Asked Questions

Does emailing a file count as MP-5?

That is usually transmission (SC-8). MP-5 focuses on physical/digital media being moved as objects.

Are encrypted laptops 'media transport' when staff commute?

Portable systems with ePHI fall under device/media protections; apply encryption, authorization, and loss reporting — often overlapping AC-19 and MP-5 expectations.

Is a spreadsheet log enough?

If complete, controlled, and retained — yes for many clinics; larger orgs often use ticketing/CMDB workflows.

References & Resources

  • NIST SP 800-53 Rev. 5 — MP-5
  • HIPAA § 164.310(d)
  • Related controls: MP-6, MP-4, AC-19, SC-13

Need Help Implementing MP-5?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.