HIPAA-compliant device inventory for small medical practices
Your dental practice just received a Business Associate Agreement request from a new dental insurance partner. Or your physical therapy clinic added two new tablets for patient intake. Or your veterinary practice put a controlled-substance module on the practice-management server. In every one of these moments, HIPAA quietly puts one specific question in front of you: do you have a record of every device that has ever touched electronic protected health information (ePHI), who has it, where it lives, and what happened to it when you retired it?
HIPAA does not use the phrase "asset register" the way ISO 27001 does. But it demands one — in §164.310(d)(2)(iii), the Accountability implementation specification of the Security Rule. Combined with the disposal and media re-use specifications above it, the rule is unambiguous: a documented, maintained inventory of every device and electronic medium that stored ePHI in your practice.
This article breaks down what HIPAA actually requires of your inventory register, what the top OCR audit findings look like, and how to build a register that survives a Breach Notification Rule investigation without a scramble.
The HIPAA sections that touch inventory
The HIPAA Security Rule sits at 45 CFR §164.302–318. Four implementation specifications inside §164.310 (Physical Safeguards) apply directly to inventory.
§164.310(d)(1) — Device and Media Controls (Standard)
> "Implement policies and procedures that govern the receipt and removal of hardware and electronic media that contain electronic protected health information (ePHI), into and out of a facility, and the movement of these items within the facility."
This is the umbrella. Every laptop, tablet, workstation, phone, USB drive, backup tape or external hard drive that has ever touched ePHI is covered. The iPad in the operatory. The tablet at reception. The server in the back room. The backup drive the practice manager takes home on a Friday.
§164.310(d)(2)(i) — Disposal (Required)
> "Implement policies and procedures to address the final disposition of ePHI, and/or the hardware or electronic media on which it is stored."
Every retired device that ever held ePHI needs a disposal record. Not "we gave it to the IT vendor." A dated document, a wipe method (NIST 800-88 clear, purge or destroy), and a certificate of destruction if a vendor performed it.
§164.310(d)(2)(ii) — Media Re-use (Required)
> "Implement procedures for removal of ePHI from electronic media before the media are made available for re-use."
A tablet used by the dental hygienist cannot pass to the new receptionist without documented ePHI removal — even if it stays inside the same practice.
§164.310(d)(2)(iii) — Accountability (Addressable)
> "Maintain a record of the movements of hardware and electronic media and any person responsible therefore."
**This is the sentence that requires an inventory register.** "Addressable" in HIPAA does not mean optional — it means implement it, implement an equivalent alternative, or document in writing why it is not reasonable and appropriate. For a covered entity of any size, the equivalent alternative is almost always more work than just keeping the register.
§164.310(d)(2)(iv) — Data Backup and Storage (Addressable)
> "Create a retrievable, exact copy of ePHI, when needed, before movement of equipment."
Every planned move — server relocation, workstation replacement, laptop return from a departing employee — needs a backup step recorded before the move.
What the register must contain
HIPAA does not spell out fields word for word. Between the four specifications above and the OCR audit protocol published by HHS, a workable minimum is:
Required fields
**Device ID** — serial number for hardware, MAC address or an internal asset tag. Must be unique across the practice.
**Device type** — desktop, laptop, tablet, phone, server, USB drive, external HDD, backup tape, removable medium.
**ePHI status** — does this device store, process or transmit ePHI? Yes / No / Unknown is not acceptable — "unknown" leaves you unable to answer the auditor. Every device has a dated decision on file.
**Physical location** — right now, in specifics: "Operatory 2", "Front desk", "Employee home — Dr. Patel", "Colocation rack, RackAI Chicago", "Vendor cloud — Practice Fusion".
**Assigned to** — the person or role currently responsible. For shared devices (front-desk workstation) it is the role. For personal or take-home devices it is the individual.
**Movement history** — every location or ownership change, from receipt to disposal. Date, from, to, who authorized the move. This is what §164.310(d)(2)(iii) literally requires: "a record of the movements of hardware and electronic media and any person responsible therefore."
**Encryption status** — at-rest encryption enabled? Yes / No, with method (BitLocker, FileVault, LUKS, iPadOS full-device). Unencrypted devices storing ePHI are a red flag on any OCR audit.
Required for retired devices
**Disposal date and method** — the date the device left service, the destruction or wipe method, and the certificate of destruction if performed by a vendor.
**Backup verification before disposal** — for devices covered by §164.310(d)(2)(iv), evidence that ePHI was backed up before the equipment moved to disposal.
Recommended fields
**Purchase date and warranty end** — supports replacement planning; not strictly HIPAA, but auditors prefer a register that is also useful to the practice.
**Business Associate** — if the device is managed by a BA (the practice-management vendor manages your on-prem server, or a Managed Services Provider handles workstation refresh), the BA's name and the BAA reference number.
**Risk category** — high (server, workstations with heavy ePHI access), medium (shared tablets), low (guest wifi router, printer with no ePHI storage). Ties the register to §164.308(a)(1)(ii)(A) Risk Analysis.
OCR audit findings — what actually trips small practices
The HHS Office for Civil Rights publishes summaries of settlements. The inventory-related findings keep repeating at small practices.
Finding 1: Unknown device count
Practice has 12 workstations, 4 tablets and a server. Register lists 10 workstations and 2 tablets. Auditor asks about the missing devices. "We replaced them last year." Where are the retired devices? "In the back closet." Certificates of destruction? None.
Every device in the register — active or retired. Retired devices stay in the register with status "retired" and a disposal record. The back closet does not count as a disposal method.
Finding 2: BYOD without inventory
A dentist reviews radiographs at home on their personal iPhone. The phone stores images. It is not in the register. During a breach investigation OCR discovers the device, and the practice is answering questions about a device it did not know it had to track.
Any personal device that touches ePHI — even a phone reviewing X-rays — belongs in the register. BYOD policies must require the device be enrolled. No exceptions for the practice owner.
Finding 3: Retired device disappears
Practice retires a front-desk PC. The register has the entry. Six months later, during a mock audit, "where is that PC?" Nobody knows. Was it wiped? "The IT vendor took it." Do you have the certificate? "…"
Retired hardware that stored ePHI needs a certificate of destruction or documented in-place wipe. §164.310(d)(2)(i) does not accept "the vendor said they would handle it".
Finding 4: No encryption record
Every device is in the register. None has an encryption column. Auditor: "Which of these are encrypted at rest?" Silence.
Encryption is technically addressable in HIPAA — but if a device is lost or stolen and it was unencrypted and contained ePHI, that is a reportable breach under §164.404. Encrypted devices, if lost, may qualify for the safe harbor. Track encryption status per device, dated.
Finding 5: BAA gap for cloud tools
Practice uses a cloud-hosted inventory system whose notes field contains patient identifiers. No BAA with the inventory vendor. That is a §164.502(e) violation the moment ePHI enters the notes field.
Either the inventory system has a signed BAA, or the practice's policy prohibits entering ePHI in inventory metadata — and staff audits verify it.
Sample register entry
A dental operatory tablet at a two-chair practice:
- 2026-03-15 — received from Apple; provisioned by IT vendor NorthStar
- 2026-03-16 — moved to Operatory 2
That one row answers every §164.310 question in a single glance. When OCR asks "show me your device inventory," it is the same document.
Excel vs a dedicated register
Excel gets you to about 25 devices before it starts to break. Then the practice manager forgets to log a movement, deletes a retired row instead of tagging it retired, or hands the file to a new hire who cannot tell what half the columns mean.
A dedicated inventory register solves five things Excel does not:
How [Asseto](/for/medical-clinics) helps with §164.310(d)(2)(iii)
Asseto was built as an asset register with a first-class movement history. Every field the HIPAA Physical Safeguards want has a place in the system:
**On BAAs:** Asseto's design keeps ePHI *out of the inventory system* — you track *devices*, not patient records. If your practice needs a signed BAA with Asseto because of how you plan to use the notes fields, [contact office@asseto.app](/contact?tier=hipaa) to discuss. For most practices that use Asseto strictly for device metadata, no BAA is required — but that call is yours and your compliance officer's, not ours to make on your behalf.
Build the register before OCR calls
The worst time to build a HIPAA inventory register is after a breach. Retired devices from three years ago have no disposal records. Personal phones storing radiographs are undocumented. BAA references are scattered across three email folders and one whiteboard.
Start today. Walk the practice with a clipboard. Every device that has touched ePHI in any way — write it down. Assign an owner or role. Set the ePHI status. Note the encryption. In one afternoon a two-chair dental practice has a register. In a week a five-provider clinic has one. In a month you have the register OCR expects and the file your cyber-insurance broker asked for.
[Try Asseto free](/signup) and stand up a HIPAA-supporting device register in an afternoon. CSV import from your existing spreadsheet in five minutes. Owner assignments, encryption columns, movement history — all there. You keep the register. HIPAA covers your back. And when the next BAA request lands, you have an answer that is not "let me get back to you".
Related articles
DEA controlled-substance log for small veterinary practices
US vet clinics must keep 21 CFR 1304 records for every controlled substance received, dispensed, or destroyed. Required fields, biennial inventory rules, top DEA-inspection findings, and a log format that survives audit.
CLIA equipment register for small US clinical laboratories
US clinical labs under CLIA (42 CFR 493) must document every instrument, reagent lot and calibration. Required fields, top CMS/COLA/CAP inspection findings, and a register format that passes survey.
HIPAA vs GDPR device inventory: two laws, one register
Most compliance guides pick a side. This one maps HIPAA §164.310(d)(2)(iii) directly to GDPR Article 30 and 32, then shows how a single device register satisfies both — for practices that see US and EU patients.
Ready to streamline your inventory?
Start free today and see the difference organized inventory makes.