Workstations, imaging servers, copiers, and lab equipment all hold ePHI. When they retire, HIPAA expects that data to be gone — and expects you to be able to show how.
Patient data ends up in more places than the EHR: front-desk PCs, exam-room workstations, PACS and imaging servers, lab instruments, backup drives, and the hard drive inside the office copier. Each one is a reportable breach waiting to happen if it's recycled or resold with data intact.
EndByte handles medical-practice and clinic hardware the same way as everything else we do: logged by serial on pickup, sanitized to NIST 800-88 or physically destroyed, verified, and certified drive by drive. The certificate is the record your disposal policy points to when someone asks what happened to a device.
If policy says drives can't leave your facility, we'll do the work on site with your staff watching.
Covered entities and business associates must have policies for the final disposal of ePHI and the hardware or media it's stored on, and procedures for removing ePHI before media is re-used. HHS guidance points to NIST 800-88 as the reference for doing it properly.
General information, not legal advice. Your compliance obligations depend on your organization — check with your counsel or compliance lead.
Every drive logged by serial before it moves, so your asset records and ours match.
Every wiped drive is read back in full. Anything that fails is physically destroyed.
Model, serial, method, date, and result — formatted for the people who audit you.
Witnessed destruction at your facility when media can't leave.
We'll help you find the drives hiding inside printers, copiers, and lab equipment.
Batch reports reconcile every drive received to its final disposition.
Tell us what you have. We'll quote it and schedule around your clinic hours.