PE-20 Physical Protection

Asset Monitoring and Tracking

High Risk Complex Medium Cost

PE-20 requires employing organization-defined asset location technologies to track and monitor the location and status of systems and system components, ensuring location data is protected, and using data to define geofencing or alerting as appropriate. Lost clinical laptops and wandering biomedical tablets with ePHI caches are high-frequency healthcare incidents.

Control Objective

Track and monitor location/status of prioritized ePHI-bearing assets so loss, theft, or unexpected movement triggers rapid response and inventory accuracy.

Implementation Guidance

  1. Tier assets for tracking (EPHI laptops, portable imaging viewers, loaner devices, removable bulk media).
  2. Deploy location technologies appropriate to tier (MDM geolocation, RFID, Bluetooth tags, check-in/out).
  3. Protect location telemetry as sensitive operational data.
  4. Define alerts for off-hours removal, geofence exits, or prolonged offline.
  5. Integrate with CM-8 inventory and incident response for lost devices.
  6. Cover remote clinicians and traveling specialists.
  7. Review tracking coverage quarterly against high-risk asset lists.
  8. Ensure BA-owned devices onsite meet contractual tracking/return expectations.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Laptop leaves campus geofence

MDM alert under PE-20 triggers remote lock/wipe investigation within minutes of a stolen nursing laptop.

Ultrasound tablet missing

RFID last-seen location narrows search to a wing; device recovered before discharge with local ePHI studies.

Loaner pool drift

Check-in/out tracking shows devices never returned from a clinic. PE-20 reporting recovers assets and closes inventory gaps.

Best Practices

  • Risk-tiered tracking technologies.
  • Alerts for anomalous movement.
  • Protect location data.
  • Integrate with lost-device IR.
  • Cover loaners and portable clinical devices.
  • Reconcile to CM-8 regularly.

Common Gaps & Violations

  • Inventory spreadsheet with no location capability.
  • MDM installed but geofence alerts ignored.
  • Biomed tablets unmanaged.
  • Location data readable by too many staff.
  • No process when tracking says device left campus.

Required Documentation

  • Asset monitoring and tracking procedure (PE-20)
  • Tiered asset list and technology mapping
  • Alert/response playbooks
  • Location data protection rules
  • Reconciliation reports to inventory

How to Test & Validate

  1. Sample high-risk assets for active tracking clients/tags.
  2. Review a geofence or missing-asset alert response.
  3. Confirm location data access is restricted.
  4. Reconcile tracked assets to CM-8 sample.
  5. Interview loaner desk on check-in/out controls.

Audit Considerations

Lost device breaches are a top HIPAA theme. PE-20 shows proactive tracking — not only post-loss paperwork.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.310(d) Device and Media Controls — track movements of hardware and electronic media.
  • 164.308(a)(1) Risk Management — portable asset loss is a primary risk requiring treatment.
  • 164.312(a) Access Control — remote wipe/lock depends on timely loss detection.
  • 164.402/404 Breach Notification — faster tracking reduces investigation time and exposure.

Compliance Tips

  • Start PE-20 with ePHI laptops and loaners before low-risk peripherals.
  • Put tracking alerts on the IR on-call roster.
  • Report chronically offline tracked devices as open risks.

Frequently Asked Questions

Must every mouse and monitor be RFID-tagged?

No. Define organization-prioritized components — focus on assets that store/process ePHI or enable access to it.

Is MDM enough for PE-20?

MDM geolocation often satisfies laptop tiers; add RFID/check-out for devices that cannot run agents.

Does tracking patient-owned devices apply?

PE-20 targets organizational systems/components; BYOD is handled via AC-19/MDM enrollment rules when used for ePHI.

References & Resources

  • NIST SP 800-53 Rev. 5 — PE-20
  • Related controls: CM-8, MP-5, AC-19, PE-3, SI-4

Need Help Implementing PE-20?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.