Default-deny on EHR clinics
USB storage is blocked organization-wide; only asset-tagged encrypted drives issued by HIM work for ROI exports — MP-7 restricts media use.
MP-7 requires prohibiting or restricting the use of organization-defined types of system media on systems or system components using organization-defined controls. Restricting removable media use reduces malware introduction and ePHI exfiltration via USB, SD cards, optical discs, and similar devices on EHR workstations, clinical PCs, and servers.
Limit removable and other high-risk media use on ePHI systems to authorized, controlled exceptions so data does not leave — and malware does not enter — unchecked.
How this control shows up in healthcare and HIPAA-covered environments.
USB storage is blocked organization-wide; only asset-tagged encrypted drives issued by HIM work for ROI exports — MP-7 restricts media use.
A time-bound exception allowlists a specific device ID for a modality PC; transfers are logged and the exception expires after the project.
After an incident, jump hosts gain the same device-control policy as clinical endpoints; personal phone USB tethering storage is blocked.
Paper USB policies without enforcement are common findings. MP-7 evidence is technical device control, exception governance, and monitoring on systems with ePHI.
How this NIST control supports HIPAA Security Rule expectations.
MP-7 allows prohibit or restrict. Many healthcare orgs default-deny storage and allow tightly controlled exceptions.
MP-2 controls who may access media; MP-7 controls whether media can be used on systems.
Include them in scope — phones can appear as storage devices and bypass casual 'thumb drive' bans.
Related controls that commonly accompany MP-7.
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.