Laptop leaves campus geofence
MDM alert under PE-20 triggers remote lock/wipe investigation within minutes of a stolen nursing laptop.
PE-20 requires employing organization-defined asset location technologies to track and monitor the location and status of systems and system components, ensuring location data is protected, and using data to define geofencing or alerting as appropriate. Lost clinical laptops and wandering biomedical tablets with ePHI caches are high-frequency healthcare incidents.
Track and monitor location/status of prioritized ePHI-bearing assets so loss, theft, or unexpected movement triggers rapid response and inventory accuracy.
How this control shows up in healthcare and HIPAA-covered environments.
MDM alert under PE-20 triggers remote lock/wipe investigation within minutes of a stolen nursing laptop.
RFID last-seen location narrows search to a wing; device recovered before discharge with local ePHI studies.
Check-in/out tracking shows devices never returned from a clinic. PE-20 reporting recovers assets and closes inventory gaps.
Lost device breaches are a top HIPAA theme. PE-20 shows proactive tracking — not only post-loss paperwork.
How this NIST control supports HIPAA Security Rule expectations.
No. Define organization-prioritized components — focus on assets that store/process ePHI or enable access to it.
MDM geolocation often satisfies laptop tiers; add RFID/check-out for devices that cannot run agents.
PE-20 targets organizational systems/components; BYOD is handled via AC-19/MDM enrollment rules when used for ePHI.
Related controls that commonly accompany PE-20.
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.