HIPAA Security Rule Update Get ahead of the rule.

    Back to platform overview
    Asset Manager

    One register for
    every device you
    own.

    The computers your security agent already sees, plus the printers, tablets, phones, and network gear it doesn’t. Signed records when equipment is issued, recovered, or destroyed. In the platform, this module is named Assets.

    Included with Professional and Enterprise.
    Not on Essentials.

    See which plan includes it →

    What it does

    Four things an auditor can actually look at

    Not a spreadsheet that rots. A living register tied to the people, the encryption status, and the paperwork.

    Every device in one list, found automatically

    Computers already running your security agent appear in the register with serial numbers. Printers, tablets, phones, and network gear are added by hand or spreadsheet — the things the agent cannot see.

    Know which ones are encrypted

    Each device shows encrypted, not encrypted, or unknown — and whether that status was verified by the agent or attested by your team. Unknown is never treated as encrypted.

    Get equipment back when staff leave

    Termination includes the real inventory: recovered, not recovered, or not applicable. Unreturned gear stays flagged instead of disappearing with the person.

    Read the termination guide

    Signed records, ready for an audit

    Issue equipment with an acceptable-use acknowledgment (PDF or eSign). When a device is destroyed or disposed, generate a certificate on your letterhead. The history is the file, not a recollection.

    How it works

    Nothing extra to install

    When it is on, monitored computers are already in the list. You only add what the agent cannot see.

    1. 1

      Monitored computers appear

      Nothing extra to install. Devices already running the security agent land in the register automatically.

    2. 2

      You fill the gaps

      Add printers, iPads, phones, and network gear yourself, or send a spreadsheet and we import it.

    3. 3

      Issue with a signature

      The person who receives the hardware signs an acknowledgment listing exactly what they were given.

    4. 4

      Recover, retire, or destroy

      When someone leaves, collect what they had. When media is done, record disposal with NIST SP 800-88 method language — Clear, Purge, or Destroy.

    Why this matters

    What the Security Rule actually asks for

    Tracking equipment is not housekeeping. Device and media controls are written into the HIPAA Security Rule. Here is the split that most “HIPAA-compliant inventory” pages get wrong.

    Standard · 45 CFR 164.310(d)(1)

    Device and media controls

    Implement policies and procedures that govern the receipt and removal of hardware and electronic media that contain ePHI into and out of a facility, and the movement of those items within the facility. (Source: 45 CFR 164.310)

    Required · 164.310(d)(2)(i) and (ii)

    Disposal and media re-use

    Disposal of ePHI and of the hardware or media it lives on is required. So is removing ePHI before media is reused. Asset Manager generates a Certificate of Destruction — or a Certificate of Disposal when the device was returned, sold, or donated — using NIST SP 800-88 method language (Clear, Purge, Destroy). That is sanitization vocabulary, not a HIPAA mandate. Live Compliance does not witness the destruction and does not attest to it. (Sources: 45 CFR 164.310(d)(2); NIST SP 800-88 Rev. 1)

    Addressable · 164.310(d)(2)(iii)

    Accountability is not “required” — and not optional

    The implementation specification is: maintain a record of the movements of hardware and electronic media and any person responsible therefore. Addressable, under 45 CFR 164.306(d), means implement it if reasonable and appropriate, or document why not and adopt an equivalent alternative. That record is the register plus the custody history. (Source: 45 CFR 164.310(d)(2)(iii))

    Addressable · 164.312(a)(2)(iv)

    Encryption, device by device

    Encryption of ePHI at rest is addressable, not a blanket “every laptop must.” Assess it. Where you encrypt, keep the evidence. Where you do not, write down why. Breach notification attaches to unsecured PHI — PHI not rendered unusable, unreadable, or indecipherable by a method specified in HHS guidance (45 CFR 164.402). A lost device is only as defensible as the record that it was encrypted. That is information, not legal advice. (Sources: 45 CFR 164.312(a)(2)(iv); 45 CFR 164.402; HHS breach-notification guidance)

    Accuracy & legal note. Plain-language summary of the HIPAA Security Rule (45 CFR 164.306, 164.310, 164.312) and Breach Notification definitions (45 CFR 164.402), plus NIST SP 800-88 Rev. 1 method language, accurate as of September 2026. Regulations change. This is general educational information, not legal advice — verify current requirements at hhs.gov/hipaa or with your compliance counsel. Last updated: September 2026.

    Professional & Enterprise

    See the register on a plan that includes it

    Protecting healthcare organizations since 2010 · 500+ clients served. When an auditor asks who had the laptop, the answer is a record. 500+ organizations. 100% audit success rate.

    FAQ

    Asset Manager questions