Certified Data Erasure

Compliance Guide

HIPAA Hard Drive & Media Disposal Requirements

HIPAA §164.310(d)(2)(i) requires controlled disposal of every device holding PHI. Below, exactly what the rule requires, which devices are in scope, and how to stay audit-ready — explained clearly.

✓ 45 CFR §164.310 ✓ NIST SP 800-88 ✓ 6-Year Retention ✓ HHS Guidance

The Rule

What §164.310(d)(2)(i) actually says

The HIPAA Security Rule requires "policies and procedures to address the final disposition of electronic PHI and the hardware or electronic media on which it is stored," and "removal of electronic PHI from electronic media before re-use." The rule is outcome-based — it mandates no algorithm; it requires PHI to be reliably rendered unreadable, and the act documented.

Two Obligations

"Disposal" and "re-use" — two distinct cases

Final Disposal

When a device is scrapped, sold or returned: PHI must be permanently destroyed. Software wipe (NIST Purge) or physical destruction + documentation.

Media Re-use

When a device is reassigned internally: PHI must be removed BEFORE re-use. NIST Clear/Purge + record.

In Scope

Which devices can hold PHI?

Not just server drives — easily-overlooked devices are in scope too:

  • ✓ Server & workstation hard drives (HDD/SSD)
  • ✓ Laptop SSD / NVMe
  • ✓ Backup USB drives & external disks
  • ✓ Copier/printer hard drives
  • ✓ Diagnostic & medical device storage
  • ✓ Staff phones/tablets (holding PHI)
  • ✓ Memory cards (SD/microSD)
  • ✓ Leased devices (before return!)

Regulators have penalized cases where leased copier or computer drives were returned without sanitizing PHI — include the easily-forgotten devices in your inventory.

The Common Mistake

Why format, delete and repartition are not enough

Standard OS delete, quick format and repartition only remove file pointers — the data remains and can be recovered with free tools. On SSDs, wear-leveling and over-provisioning mean even a software overwrite may miss reserved cells. For HIPAA, this does not meet the "PHI rendered unreadable" bar. The right path: NIST 800-88 Clear/Purge (hardware Sanitize for SSD/NVMe) + verification. NIST 800-88 vs HIPAA →

Documentation & Penalties

Retain the record for 6 years — and why it matters

HIPAA requires disposal documentation to be retained for 6 years (§164.316(b)(2)). A "we ran format" statement is not enough for an audit. HIPAA violations carry $100–$50,000 per violation, with an annual cap up to $1.5M; PHI leakage from decommissioned devices is one of the most typical breach scenarios. A per-device tamper-proof certificate + inventory record enables both compliance and, in an incident, the "low probability of compromise" defense (§164.404).

How to Meet It

Requirement → met with PIWIPE

  • Render PHI unreadable — NIST 800-88 Clear/Purge, auto per device.
  • Inventory record — Device identity auto-recorded on connection.
  • Auditable certificate — Serial, method, date, SHA-256 hash, signature, QR verification.
  • 6-year retention — Indefinite, searchable cloud archive.

Frequently Asked

HIPAA Media Disposal

What does HIPAA require for hard drive disposal?
§164.310(d)(2)(i): written policies and procedures for the final disposition of hardware/media containing PHI. Outcome: PHI must be unreadable and unrecoverable; HHS guidance points to NIST SP 800-88.
Is physical destruction or degaussing required?
No. If reused, software-based NIST 800-88 is sufficient; if fully destroyed, physical destruction/degaussing (magnetic media) also qualifies. What matters is the outcome and the record.
How long must we keep disposal records?
HIPAA requires documentation to be retained for 6 years (§164.316(b)(2)). Certificates and inventory records must be producible during an audit.
Does HIPAA require a certificate of destruction?
It does not mandate a certificate verbatim but requires you to prove disposal. A per-device tamper-proof certificate is the strongest form of that evidence. HIPAA compliant disk wipe →

Make your media disposal audit-ready.

PIWIPE applies NIST 800-88 per device and issues certificates you can retain for 6 years.

HIPAA Compliant Disk Wipe Checklist (PDF)

Or call us: +90 212 916 12 22