Any covered entity (including healthcare providers, health plans, and healthcare clearinghouses) must prepare and maintain a risk assessment in order to comply with the requirements of the HIPAA Security Rule. And to do this, an IT asset inventory is a vital starting point.
What is an IT asset inventory?
An IT asset inventory is a complete, comprehensive, and current list of all an organization's information technology (IT) assets. These assets include endpoints like computer workstations and mobile devices, and infrastructure including file servers, network routers, and firewalls. But hardware is only part of the equation. IT assets also include software, including operating systems, email applications, databases, virtual and remote access programs, and the various administrative tools used to manage the overall system. Finally, and most relevant to HIPAA, an IT asset inventory must include data assets: member or customer information, payment and financial information, and electronic protected health information (ePHI). While the definition is clear, the effort and expertise required to create an IT inventory are not insignificant. Indeed, the Office for Civil Rights (OCR), which investigates HIPAA violations, finds that many organizations lack sufficient understanding of where all of the ePHI that's entrusted to their care is located.What's included in an IT asset inventory?
According to the U.S. Department of Health and Human Services (HHS):Generally, an enterprise-wide IT asset inventory is a comprehensive listing of an organization’s IT assets with corresponding descriptive information, such as data regarding identification of the asset (e.g., vendor, asset type, asset name/number), version of the asset (e.g., application or OS version), and asset assignment (e.g., person accountable for the asset, location of the asset).An IT asset inventory frequently separates entries into three categories:
- Hardware assets: physical components, including electronic devices and media, which make up an organization’s networks and systems.
- Software assets: programs and applications that run on an organization’s electronic devices.
- Data assets: information (including ePHI) that an organization creates, receives, maintains, or transmits on its network, electronic devices, and media.
