Compliance Guide
HIPAA Hard Drive & Media Disposal Requirements
HIPAA §164.310(d)(2)(i) requires controlled disposal of every device holding PHI. Below, exactly what the rule requires, which devices are in scope, and how to stay audit-ready — explained clearly.
The Rule
What §164.310(d)(2)(i) actually says
The HIPAA Security Rule requires "policies and procedures to address the final disposition of electronic PHI and the hardware or electronic media on which it is stored," and "removal of electronic PHI from electronic media before re-use." The rule is outcome-based — it mandates no algorithm; it requires PHI to be reliably rendered unreadable, and the act documented.
Two Obligations
"Disposal" and "re-use" — two distinct cases
Final Disposal
When a device is scrapped, sold or returned: PHI must be permanently destroyed. Software wipe (NIST Purge) or physical destruction + documentation.
Media Re-use
When a device is reassigned internally: PHI must be removed BEFORE re-use. NIST Clear/Purge + record.
In Scope
Which devices can hold PHI?
Not just server drives — easily-overlooked devices are in scope too:
- ✓ Server & workstation hard drives (HDD/SSD)
- ✓ Laptop SSD / NVMe
- ✓ Backup USB drives & external disks
- ✓ Copier/printer hard drives
- ✓ Diagnostic & medical device storage
- ✓ Staff phones/tablets (holding PHI)
- ✓ Memory cards (SD/microSD)
- ✓ Leased devices (before return!)
Regulators have penalized cases where leased copier or computer drives were returned without sanitizing PHI — include the easily-forgotten devices in your inventory.
The Common Mistake
Why format, delete and repartition are not enough
Standard OS delete, quick format and repartition only remove file pointers — the data remains and can be recovered with free tools. On SSDs, wear-leveling and over-provisioning mean even a software overwrite may miss reserved cells. For HIPAA, this does not meet the "PHI rendered unreadable" bar. The right path: NIST 800-88 Clear/Purge (hardware Sanitize for SSD/NVMe) + verification. NIST 800-88 vs HIPAA →
Documentation & Penalties
Retain the record for 6 years — and why it matters
HIPAA requires disposal documentation to be retained for 6 years (§164.316(b)(2)). A "we ran format" statement is not enough for an audit. HIPAA violations carry $100–$50,000 per violation, with an annual cap up to $1.5M; PHI leakage from decommissioned devices is one of the most typical breach scenarios. A per-device tamper-proof certificate + inventory record enables both compliance and, in an incident, the "low probability of compromise" defense (§164.404).
How to Meet It
Requirement → met with PIWIPE
- ✓Render PHI unreadable — NIST 800-88 Clear/Purge, auto per device.
- ✓Inventory record — Device identity auto-recorded on connection.
- ✓Auditable certificate — Serial, method, date, SHA-256 hash, signature, QR verification.
- ✓6-year retention — Indefinite, searchable cloud archive.
Frequently Asked
HIPAA Media Disposal
Make your media disposal audit-ready.
PIWIPE applies NIST 800-88 per device and issues certificates you can retain for 6 years.
Or call us: +90 212 916 12 22