The hipaa device and media control requirements microsoft 365 means a covered entity or business associate must control how devices and electronic media containing ePHI are received, moved, removed, reused, backed up when appropriate, and permanently disposed of. Microsoft 365 can help document and enforce many parts of the control through Intune, Microsoft Purview, BitLocker, Entra ID, and audit logs, but it does not replace written procedures or a record of who handled a device or media item. Compliance means you can show an assessor what devices held ePHI, where they went, who was responsible, and how data was protected or removed at each point.
What does the official HIPAA requirement actually say?
HIPAA Security Rule standard 45 CFR § 164.310(d)(1), Device and Media Controls, requires covered entities and business associates to:
“Implement policies and procedures that govern the receipt and removal of hardware and electronic media that contain electronic protected health information, into and out of a facility, and the movement of these items within the facility.”
That sentence has several practical parts that matter during a merger, office move, hardware refresh, or staff transition.
- “Policies and procedures” means more than a technical configuration. Your organization needs documented rules describing approval, custody, records, secure transport, wiping, disposal, and exceptions.
- “Receipt and removal” covers devices arriving at or leaving an office. A laptop issued to a new employee, a mobile phone returned by a departing employee, and a damaged drive sent to a repair vendor all count.
- “Hardware and electronic media” includes laptops, desktops, tablets, phones, removable USB drives, external disks, server drives, backup media, scanners with local storage, and multifunction printers that retain documents.
- “That contain ePHI” is the key scope decision. A device is in scope when it stores, can cache, synchronizes, downloads, or otherwise contains ePHI. An Intune-enrolled laptop that syncs OneDrive files containing patient records is in scope even when files are primarily stored in SharePoint Online.
- “Into and out of a facility” includes home offices, satellite offices, acquired locations, repair centers, storage facilities, and disposal vendor locations when those places are part of your operational workflow.
- “Movement within the facility” includes relocating a workstation from a reception desk to a billing office, moving a printer to another floor, or transferring an old laptop from a clinician to IT for reissue.
The standard has four implementation specifications. Two are required: disposal under § 164.310(d)(2)(i) and media re-use under § 164.310(d)(2)(ii). Two are addressable: accountability under § 164.310(d)(2)(iii) and data backup and storage under § 164.310(d)(2)(iv). “Addressable” does not mean optional; it means you must assess whether the specification is reasonable and appropriate, implement it when it is, or document an equivalent safeguard or a justified alternative.
Who must meet HIPAA device and media control requirements in Microsoft 365?
These requirements apply to HIPAA covered entities and business associates that create, receive, maintain, or transmit ePHI. For a small provider integrating another organization, the control applies to both legacy environments until systems, devices, records, and responsibilities are fully consolidated.
In a Microsoft 365 environment, the control is triggered whenever ePHI could be present on an endpoint or removable medium, including when a user:
- Downloads a patient document from SharePoint Online or OneDrive for Business to a Windows or macOS device.
- Synchronizes a Teams channel or SharePoint document library that contains ePHI.
- Uses Outlook to download email attachments containing patient information.
- Uses a mobile device to access Exchange Online, Teams, or Microsoft 365 files.
- Exports reports from an EHR, billing system, or scheduling application to an encrypted laptop or USB drive.
- Moves, repairs, returns, reassigns, retires, or disposes of a device that may have stored ePHI.
Microsoft 365 tenant ownership also matters in an acquisition. If Organization A migrates mailboxes and OneDrive content from Organization B, both organizations should identify which party owns each device, who approves transfers, how old devices are wiped, and which audit records are retained. The migration project itself does not eliminate device and media control responsibilities.
What do compliant device and media controls look like in practice?
An assessor is generally looking for evidence that your written process matches actual operations. The following examples show the kind of evidence that can support the hipaa device and media control requirements microsoft 365 control in a small organization.
| Situation | Practical control | Evidence an assessor can review |
|---|---|---|
| New laptop issued to an employee | Enroll the laptop in Microsoft Intune, require BitLocker encryption, deploy Microsoft Defender for Endpoint, require Entra ID sign-in with MFA, and restrict local administrator rights. | Asset record, Intune device record, BitLocker recovery-key escrow record, assignment acknowledgment, and configuration policy reports. |
| Employee changes roles or leaves | Record return of the laptop and phone, block sign-in, remove Microsoft 365 licenses as appropriate, review OneDrive ownership, and use an Intune wipe or retire action under the documented offboarding process. | Offboarding ticket, chain-of-custody log, Intune action log, asset status change, and sanitization or reissue approval. |
| Device is sent for repair or disposal | Back up required business data, remove or cryptographically erase ePHI before vendor transfer, and use a qualified destruction vendor for failed drives that cannot be sanitized. | Repair authorization, serial number log, wipe certificate or destruction certificate, vendor agreement, and pickup receipt. |
| Staff need to transport records | Prohibit ordinary USB drives for ePHI unless specifically approved; use encrypted, organization-issued media with a named custodian and a documented return date. | Exception approval, encrypted-media inventory, transfer log, and documented confirmation of return or secure destruction. |
Example: merging two small practices without losing device accountability
Consider Northside Family Care, a 22-person primary care practice, acquiring Lakeshore Endocrinology, a 9-person specialty practice. Northside uses Microsoft 365 Business Premium, Intune, Microsoft Defender for Business, and SharePoint Online; Lakeshore has unmanaged Windows laptops and staff OneDrive accounts containing exported referral and lab documents.
Before migration, the integration lead creates a combined device register with owner, serial number, location, encryption status, Microsoft 365 tenant, assigned user, and whether the device can access ePHI. Each Lakeshore laptop is checked into IT custody, photographed or tagged with an asset label, enrolled in Intune, and evaluated for BitLocker status. Devices that cannot meet the new baseline are removed from service. For every retired device, the practice records whether it was wiped, reissued, physically destroyed, or retained for legal reasons.
The practice also preserves relevant Microsoft Purview Audit records and migration documentation. The objective is not to prove that Microsoft 365 stored every patient record locally; it is to show that the organization understood which endpoints could contain synchronized or downloaded ePHI and controlled them accordingly.
Example: moving a workstation inside an office
A 14-person clinic moves a front-desk workstation to a new billing area after combining reception teams. The workstation runs the EHR through a browser, receives Outlook messages, and has a OneDrive sync client. The office manager opens an IT ticket identifying the asset tag, prior location, new location, responsible employee, and move date. IT confirms that BitLocker is active, updates the asset inventory, and verifies that the workstation remains assigned to the correct Intune compliance policy.
This is a modest process, but it satisfies the accountability objective better than relying on informal knowledge. If the workstation later goes missing, the organization can identify who was responsible and when the device moved.
How should Microsoft 365 support disposal, reuse, accountability, and backup?
Microsoft 365 is most useful when its technical records are connected to your physical asset process. A strong procedure normally assigns responsibility to IT, the privacy or security officer, department managers, and employees receiving devices.
- Disposal: Require documented sanitization or destruction before hardware or media is discarded. For encrypted Windows devices, a properly performed cryptographic erase may be appropriate when keys are destroyed and the method is documented; failed or unverified drives should be physically destroyed by an approved vendor.
- Media re-use: Before a laptop, phone, external drive, printer storage component, or USB media is reassigned, remove ePHI using a defined sanitization method. Intune’s
Wipeaction can support mobile-device and Windows reset workflows, but your process should verify completion and record the device’s serial number and new assignee. - Accountability: Maintain a movement log for devices and media that may contain ePHI. Intune reports, Entra ID device records, service tickets, courier receipts, and asset-management records can collectively support this requirement, provided they identify the asset, movement, date, location, and responsible person.
- Data backup and storage: Before moving equipment, create a retrievable, exact copy of needed ePHI when appropriate. Do not assume Microsoft 365 retention policies alone are a complete backup strategy. Retention can preserve content in place, while a separate Microsoft 365 backup service or documented export-and-restore process may be needed to meet recovery objectives.
For Microsoft 365 endpoints, common policy settings include requiring BitLocker through an Intune endpoint security disk-encryption policy, requiring compliant devices through Conditional Access, blocking unmanaged device downloads where feasible, and using Microsoft Purview Audit to investigate file access or administrative actions. These controls reduce exposure, but they do not excuse an undocumented disposal or custody process.
FAQ: HIPAA device and media controls
Does HIPAA require Microsoft Intune?
No. HIPAA does not mandate Intune or any specific product. Intune is a practical way to inventory devices, enforce encryption, apply compliance policies, and remotely wipe managed devices, which can help demonstrate reasonable safeguards.
Are OneDrive and SharePoint files considered electronic media under HIPAA?
They are electronic information systems that may maintain ePHI, but the device and media control standard is especially relevant when ePHI is stored on or synchronized to physical devices and removable media. Your overall HIPAA program must also address cloud access, vendor agreements, access controls, and audit controls.
Do we need to track every keyboard, monitor, and charger?
Not usually. Track hardware and electronic media that contain, can store, or provide access to ePHI as determined by your risk analysis. A monitor without storage generally is not the same risk as a laptop, encrypted USB drive, multifunction printer hard drive, or mobile phone.
What is the difference between wiping a device and retiring it in Intune?
A wipe resets or removes managed data from a device, depending on the action and platform. Retiring generally removes organizational management and some corporate data while leaving personal content intact. Your procedure should choose the action appropriate to device ownership, confirm completion, and document whether ePHI was fully removed before reuse or disposal.
Next step: During the M&A integration, create one combined ePHI device inventory and require every transferred, reassigned, repaired, or retired device to have a documented custody and sanitization record.