Certified Data Erasure

Standards Explainer

NIST 800-88 vs HIPAA — What Standard Does HIPAA Require?

Short answer: HIPAA does not name a standard — it requires an outcome. HHS guidance points to NIST SP 800-88. Below, what that means for you in practice.

✓ NIST SP 800-88 Rev.1 ✓ HHS Guidance ✓ 45 CFR §164.310 ✓ IEEE 2883

The Core Question

Does HIPAA name a specific standard? No.

The media-disposal provision of the HIPAA Security Rule (45 CFR §164.310(d)(2)(i)) is technology-neutral and outcome-based: electronic media holding Protected Health Information (PHI) must be disposed of so that PHI cannot be read or reconstructed. The rule imposes no specific algorithm — it asks you to reliably achieve, and document, that outcome.

The Accepted Method

Why everyone points to NIST SP 800-88

HHS guidance for the HIPAA Security Rule and its breach-notification interpretations explicitly reference NIST SP 800-88 for media sanitization. Because the standard has become the de-facto reference in practice, implementing NIST 800-88 is the most defensible way to say "we destroyed PHI using an accepted method." Meet NIST 800-88 and you meet HIPAA's outcome requirement.

Two Levels

NIST 800-88: Clear vs Purge, by device type

Device Recommended Level Method
HDDClear / PurgeVerified overwrite; DoD 3-pass + HPA/DCO removal for Purge
SSD (SATA)PurgeATA Secure Erase / Sanitize (hardware)
NVMePurgeNVMe Sanitize / Cryptographic Erase (IEEE 2883)
USB / Memory CardClear / PurgeVerified overwrite
iPhone / AndroidPurgeCryptographic erase + factory reset

PIWIPE detects the device type and auto-recommends the correct NIST 800-88 level. All 18+ standards →

Mapping

HIPAA requirement → NIST 800-88 + PIWIPE

  • Render PHI unreadable — NIST 800-88 Clear/Purge; PIWIPE applies per device.
  • Cover hidden areas — HPA/DCO and over-provisioning are cleared.
  • Documentation — Per-device tamper-proof PDF certificate (hash + signature).
  • 6-year retention — Indefinite cloud archive, audit-ready.

Frequently Asked

NIST 800-88 & HIPAA

Does HIPAA require NIST 800-88?
HIPAA does not mandate a standard by name. §164.310(d)(2)(i) is outcome-based: PHI must be unreadable and unrecoverable. HHS guidance cites NIST SP 800-88 as the authoritative method, so implementing NIST 800-88 is the accepted way to meet it.
What is the difference between Clear and Purge?
Clear is a single-pass logical overwrite (lower-risk reuse). Purge is multi-pass overwrite, ATA/NVMe Sanitize, or cryptographic erase, defeating laboratory recovery. For PHI leaving your control, Purge is recommended.
Is NIST 800-88 enough for SSDs?
Yes, when applied correctly. On SSDs a software overwrite is unreliable due to wear-leveling; NIST 800-88 Purge via the hardware Sanitize command (IEEE 2883) reaches all NAND including over-provisioned cells.
Does a NIST 800-88 wipe satisfy a HIPAA audit?
A NIST 800-88 wipe plus a tamper-proof certificate (device serial, method, date, hash, signature) documents that PHI was destroyed to an accepted standard — exactly what an auditor looks for. HIPAA compliant disk wipe →

Apply NIST 800-88, audit-ready.

PIWIPE applies the right level per device and issues a tamper-proof certificate.

HIPAA Compliant Disk Wipe Request a Demo

Or call us: +90 212 916 12 22