PE-16 Physical Protection

Delivery and Removal

Medium Risk Moderate Low Cost

PE-16 requires authorizing and controlling systems and system components entering and exiting the facility and maintaining records of those items. Unlogged servers, loaner laptops, and vendor test gear walking in and out of hospitals are a supply-chain and ePHI exfiltration pathway.

Control Objective

Authorize, inspect, and record delivery and removal of system components at facilities housing ePHI so rogue or departing hardware cannot bypass inventory and media controls.

Implementation Guidance

  1. Define intake/egress points for IT and clinical equipment (loading docks, data center, biomed).
  2. Require authorization tickets before equipment enters secure IT spaces.
  3. Log serials/asset tags for arrivals and removals; reconcile to CM-8.
  4. Inspect for tampering on critical receipts (SR-11).
  5. Control removal of devices that may contain ePHI — gate on MP sanitization or custody.
  6. Escort vendor deliveries into sensitive areas (PE-3/MA-5).
  7. Prohibit staff from walking out with unmarked storage media/servers.
  8. Review logs periodically for anomalies (after-hours removals).

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Vendor rolls in an unknown server

Delivery lacks PO and asset ID. PE-16 dock process holds the box until IT authorizes and tags it — no silent rack install.

Night removal of a storage shelf

After-hours exit without ticket triggers security stop; PE-16 logs would have shown unauthorized ePHI media movement.

Biomed pump swap

Failed pump leaving the building is logged; storage checked for patient data caches before vendor pickup.

Best Practices

  • Authorized entry/exit points.
  • Logs tied to asset inventory.
  • Inspect critical deliveries.
  • Sanitize or custody-control removals with ePHI.
  • Escort into secure rooms.
  • Review anomalous movement.

Common Gaps & Violations

  • Loading dock open to any IT-looking cart.
  • No serial capture on egress.
  • Staff take home surplus PCs with drives intact.
  • Vendor gear left unattended in hallways.
  • CM-8 never updated after moves.

Required Documentation

  • Delivery and removal procedure (PE-16)
  • Authorization/ticket templates
  • Intake/egress logs
  • Inspection checklist for critical gear
  • Reconciliation reports to CM-8

How to Test & Validate

  1. Sample recent deliveries for authorization and log entries.
  2. Trace a removal of ePHI-capable media through sanitization gate.
  3. Observe dock process for escort rules.
  4. Reconcile a week of logs to inventory changes.
  5. Review after-hours movement exceptions.

Audit Considerations

Physical chain-of-custody for hardware is frequently weak in hospitals. PE-16 evidence supports both theft prevention and media control narratives.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.310(d) Device and Media Controls — control receipt and removal of hardware and electronic media containing ePHI.
  • 164.310(a) Facility Access Controls — control physical access and movement of equipment.
  • 164.308(a)(1) Risk Management — unauthorized hardware movement is a tangible risk.
  • 164.312(c) Integrity — tampered components introduced via delivery threaten integrity.

Compliance Tips

  • Integrate PE-16 tickets with the asset management system.
  • Train security officers on what IT gear needs stop-and-check.
  • Pair PE-16 with SR-11 authenticity checks for critical components.

Frequently Asked Questions

Do medication deliveries fall under PE-16?

PE-16 targets systems/components; pharmacy may have parallel controls. Apply PE-16 to IT/clinical system hardware and media.

Are cloud hardware shipments in scope?

On-premises receipt of servers, appliances, and storage that will process ePHI is in scope.

How long keep logs?

Align to your documentation retention (often six years for HIPAA-related documentation) and investigation needs.

References & Resources

  • NIST SP 800-53 Rev. 5 — PE-16
  • Related controls: PE-3, CM-8, MP-5, MA-2, SR-11

Need Help Implementing PE-16?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.