MP-7 Media Protection

Media Use

High Risk Moderate Medium Cost

MP-7 requires prohibiting or restricting the use of organization-defined types of system media on systems or system components using organization-defined controls. Restricting removable media use reduces malware introduction and ePHI exfiltration via USB, SD cards, optical discs, and similar devices on EHR workstations, clinical PCs, and servers.

Control Objective

Limit removable and other high-risk media use on ePHI systems to authorized, controlled exceptions so data does not leave — and malware does not enter — unchecked.

Implementation Guidance

  1. Define prohibited vs restricted media types (e.g., personal USB storage prohibited; approved encrypted HIM drives allowed).
  2. Enforce with endpoint device control / MDM on workstations that access ePHI; default-deny USB storage where feasible.
  3. Create an exception process with business justification, encryption requirements, owner, and expiration.
  4. Allow read-only or specific device IDs when clinical equipment legitimately needs media (legacy ultrasound exports, etc.).
  5. Monitor and alert on blocked or anomalous media use attempts.
  6. Align user rules of behavior (PL-4) with technical enforcement.
  7. Cover servers and admin jump hosts — not only clinic desktops.
  8. Review exceptions quarterly; remove stale approvals.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Default-deny on EHR clinics

USB storage is blocked organization-wide; only asset-tagged encrypted drives issued by HIM work for ROI exports — MP-7 restricts media use.

Biomed ultrasound export

A time-bound exception allowlists a specific device ID for a modality PC; transfers are logged and the exception expires after the project.

Admin laptop malware via USB

After an incident, jump hosts gain the same device-control policy as clinical endpoints; personal phone USB tethering storage is blocked.

Best Practices

  • Default deny USB storage on ePHI endpoints.
  • Encrypted, inventoried exception media only.
  • Time-bound exceptions with owners.
  • Monitor block events.
  • Include servers and privileged workstations.
  • Quarterly exception cleanup.

Common Gaps & Violations

  • Policy bans USB but no technical enforcement.
  • Permanent global exceptions for convenience.
  • Clinical 'shared' USB stick passed between units.
  • Servers excluded from device control.
  • No monitoring of media insertion events.

Required Documentation

  • Media use policy (prohibited/restricted types)
  • Device control configuration standards
  • Exception request/approval process
  • Inventory of approved removable media
  • Monitoring / review records

How to Test & Validate

  1. Insert an unauthorized USB on a sample EHR workstation and confirm block.
  2. Review active exceptions for business need and expiration.
  3. Verify approved encrypted drives still function.
  4. Check servers/jump hosts for equivalent controls.
  5. Sample alerts on media insertion attempts.

Audit Considerations

Paper USB policies without enforcement are common findings. MP-7 evidence is technical device control, exception governance, and monitoring on systems with ePHI.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.310(d) Device and Media Controls — govern use of electronic media with ePHI.
  • 164.308(a)(1) Risk Analysis / Risk Management — removable media is a frequent exfiltration and malware vector.
  • 164.312(a) Access Control — technical controls limit how ePHI can be copied off systems.
  • 164.312(c) Integrity — restrict media that could introduce malware altering ePHI systems.

Compliance Tips

  • Ship device control with EHR workstation images by default.
  • Issue a small pool of approved encrypted drives rather than many one-off exceptions.
  • Report top blocked-media users to managers monthly as a behavior signal.

Frequently Asked Questions

Must all USB be banned?

MP-7 allows prohibit or restrict. Many healthcare orgs default-deny storage and allow tightly controlled exceptions.

How does MP-7 relate to MP-2?

MP-2 controls who may access media; MP-7 controls whether media can be used on systems.

What about smartphone USB connections?

Include them in scope — phones can appear as storage devices and bypass casual 'thumb drive' bans.

References & Resources

  • NIST SP 800-53 Rev. 5 — MP-7
  • Related controls: MP-2, MP-5, SI-3, AC-19, PL-4

Need Help Implementing MP-7?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.