← All guides

Building a HIPAA Technology Asset Inventory

Vulnerabilities7 min read

Building a HIPAA Technology Asset Inventory

You cannot analyze risk to ePHI you do not know you hold, and you cannot act on a vulnerability advisory without knowing whether you run the product. The 2025 Security Rule proposal makes this explicit: a written technology asset inventory and a network map of the movement of ePHI, both reviewed at least every 12 months and after material changes, as prerequisites of the risk analysis.

A useful inventory is structured, not a spreadsheet of hostnames. For every asset record the vendor, product and version, where it sits in the network map, what ePHI it touches, who owns it, and how it is supported. Vendor, product and version are the fields that let advisories from CISA, recalls from the FDA and CVE records be matched to your environment automatically instead of by someone reading a feed.

Medical devices deserve their own track. They are often on old operating systems, updated only by the manufacturer, and named in FDA recalls and CISA medical advisories by model. Capturing the manufacturer and model at the same level of detail as servers is what makes those advisories actionable.

Key points

  • Fields that matter

    Asset identifier, vendor, product, version, asset class, location or network zone, ePHI relationship, owner, support status and end-of-life date. Versions change; record the date of each observation.

  • Sources of truth

    Endpoint management, cloud consoles, the EHR vendor's component list, biomedical engineering's device register, and procurement. Reconcile them; do not pick one.

  • Network map

    A diagram or dataset showing where ePHI is created, received, maintained and transmitted, including third parties. It is the basis for segmentation decisions and for scoping the risk analysis.

  • Naming for matching

    Use vendor and product names as they appear in CISA advisories and the National Vulnerability Database, so a match is a string comparison rather than a judgment call.

  • Review cadence

    At least annually and after material change, per the proposal. Continuous discovery tools help, but the written record with a review date is what an auditor asks for.

  • Turning it into alerts

    With vendor and product recorded, a vulnerability feed becomes a filter over your inventory: new CVE for product X, you run X, alert the owner. That matching is the next capability planned for this site's DueCare subscribers.

Common mistakes

  • Inventory versus discovery scan

    A scan finds what answers on the network today. An inventory records what you own, including offline devices, vendor-managed systems and cloud services a scan never sees.

  • Asset versus data flow

    The proposal asks for both the inventory and the map. Knowing you own a server is not the same as knowing which ePHI passes through it and to whom.

  • Version once versus version now

    An inventory with the version captured at purchase is wrong within months. Record versions with dates and refresh them from management tools.

Sources

;

See it in the live data.

Browse device advisories and recalls