HIPAA hard drive disposal: what the rules actually require
Every practice, clinic and health-tech company eventually retires devices that held patient data. Here's what HIPAA actually requires when those drives leave your hands — in plain English.
The rule itself
The HIPAA Security Rule's device and media controls require covered entities and business associates to have policies and procedures for:
- Disposal — the final disposition of electronic protected health information (ePHI) and the hardware or media it's stored on (45 CFR 164.310(d)(2)(i)).
- Media re-use — removing ePHI before media is made available for re-use (45 CFR 164.310(d)(2)(ii)).
HIPAA doesn't name a single required tool. It requires that ePHI be made unreadable and unrecoverable, and that you can show how you did it.
Methods HHS recognizes
| Method | What it means |
|---|---|
| Clearing | Overwriting media with non-sensitive data using software or hardware tools. |
| Purging | Degaussing magnetic media — or, for SSDs and flash, the drive's built-in sanitize or cryptographic-erase commands. |
| Destroying | Shredding, disintegration, pulverization, melting or incineration. |
These line up with the three levels in NIST 800-88, the standard HHS points to for media sanitization.
It's not just computers
ePHI hides in more places than laptops and servers: copiers and multifunction printers with internal drives, imaging and diagnostic equipment, external drives, USB sticks, phones and tablets. Your disposal procedure should cover all of them.
Using a disposal vendor
A vendor that handles devices containing ePHI on your behalf is generally a business associate, so you'll want a business associate agreement (BAA) in place before drives leave your custody. Ask the vendor:
- Will you sign a BAA?
- Is custody documented by serial number from pickup to destruction?
- Is every drive verified — and what happens to drives that fail?
- Do we get a certificate per drive, tied to its serial number?
- Is any of the work subcontracted?
Keep the records
HIPAA expects your security policies and documentation to be retained for six years. In practice that means keeping your disposal procedure, the asset list, and the destruction certificates for every device that held ePHI — and training the staff who handle retired equipment.
This guide is general information, not legal advice. Your compliance officer or counsel should confirm what your organization's policies require.
How we handle healthcare drives
EndByte works with Bay Area practices and health-tech companies: secure pickup with serial-level intake, NIST 800-88 wiping with full verification or physical destruction, and a per-drive certificate your compliance team can verify online. See data destruction for healthcare.