Phonecheck
博客

HIPAA Data Destruction Requirements, and the Gap Most Guidance Misses

A hospital IT store room with retired laptops and tablets tagged for secure disposition

HIPAA does not tell you how to destroy data. It tells you that you must, that you must document how, and that the choice is yours to justify.

The HHS Office for Civil Rights states the position plainly: the Privacy and Security Rules do not require a particular disposal method, and covered entities must review their own circumstances to determine what steps are reasonable to safeguard PHI through disposal [2]. That is not a loophole. It is a burden shift. A prescribed method would let you point at a rulebook. Instead you have to defend a decision.

What the regulation actually requires

Two implementation specifications sit under the Device and Media Controls standard at 45 CFR 164.310(d), and both are Required, not Addressable [1]. That distinction matters, because Addressable specifications allow a documented alternative where the standard one is not reasonable. Required ones do not.

Disposal, 164.310(d)(2)(i): "Implement policies and procedures to address the final disposition of electronic protected health information, and/or the hardware or electronic media on which it is stored" [1].

Media Re-use, 164.310(d)(2)(ii): "Implement procedures for removal of electronic protected health information from electronic media before the media are made available for re-use" [1].

The parent standard at 164.310(d)(1) requires policies and procedures governing the receipt and removal of hardware and electronic media containing ePHI into and out of a facility, and the movement of those items within it [1].

Read together, they describe a chain of custody obligation, not a shredding obligation. Where the device came from, where it went, what was removed before it moved, and what proves it.

Media re-use is the specification that catches device resale programmes. The moment a device leaves for resale rather than destruction, you are in (d)(2)(ii), and the requirement is removal of ePHI before it becomes available for re-use.

Where HHS points you next

HHS does not leave method selection unsupported. Its disposal guidance directs readers to NIST for the practical layer: "For practical information on how to handle sanitization of PHI throughout the information life cycle, readers may consult NIST SP 800-88, Guidelines for Media Sanitization" [2].

So the operating model for a healthcare disposition programme is a two-document stack. The regulation sets the obligation and the documentation duty. NIST SP 800-88 supplies the method framework and the assurance levels.

The gap most guidance misses

Here is the part worth slowing down for.

The HHS disposal guidance offers examples of acceptable approaches, and describes purging as "degaussing or exposing the media to a strong magnetic field in order to disrupt the recorded magnetic domains" [2].

That description belongs to an earlier generation of storage. Degaussing works by disrupting magnetic domains, which is what hard disk platters and tape use. Flash storage does not store data in magnetic domains, so a magnetic field does nothing to a phone, a tablet, or a solid-state drive. Following that example literally on a modern device produces a device that has been through a process and still holds its data.

The NIST document HHS points to has also moved. NIST SP 800-88 Rev. 1 was published in December 2014 and withdrawn on 26 September 2025, superseded by Rev. 2 [4]. Under Rev. 2, at the time of its writing, degaussing is not considered an approved destroy sanitization technique, and readers are directed to IEEE 2883 and NSA/CSS Policy Manual 9-12 for clarification [3].

None of this makes HHS wrong. The guidance names the correct downstream reference, and that reference is where current technique guidance lives. But a compliance programme that copied the illustrative examples out of the guidance, rather than following the pointer to NIST, can end up applying a method that suits neither its media nor the current revision.

If your estate is phones, tablets, and laptops, the practical implication is short: the assurance categories in NIST SP 800-88 are what to design against, and Rev. 2 defers technology-specific technique to standards such as IEEE 2883 [3]. We cover that framework in what data sanitization requires.

Want to see how per-device erasure evidence works across a mixed healthcare fleet? Request a demo.

What documentation has to survive

Because HIPAA requires you to justify your own method rather than follow a prescribed one, the documentation is the compliance position. There is no rulebook citation that substitutes for it.

NIST SP 800-88 Rev. 2 recommends completing a certificate of sanitization for each device, recording the method, the technique, the tool and its version, the verification performed, and a signature [3]. Per device.

That granularity maps onto what an OCR investigation or a business associate audit tends to ask: not whether you have a disposal policy, but what happened to a specific device on a specific date and who attests to it. The fields are broken down in certificate of data destruction.

If your disposition runs through a certified vendor, their facility scope is a separate question from your obligation, and worth checking directly. We cover how that scoping works in R2v3 certification.

Business associates and the transfer of risk

Sending devices to an ITAD vendor does not move the obligation off the covered entity. The vendor relationship is governed by a business associate agreement, and the covered entity retains its own Required specifications under 164.310(d)(2) [1].

In practice this means the evidence your vendor returns is your evidence. If it arrives as a batch certificate covering a pallet, you hold a document that does not answer the question an investigator asks about one device.

Building the evidence into device processing

For healthcare estates moving devices at volume, the constraint is producing per-device records at throughput, in a form that holds up when someone reads it eighteen months later.

Phonecheck erasure produces a signed certificate of erasure and a Device History Report for every device processed, and those reports are recognised by major resale marketplaces [5]. The compliance record and the resale record are the same artefact, generated when the device is handled.

The standards page sets out what the platform aligns to, the Device History Report shows how per-device evidence is presented, and workflow automation routes device types down different paths.

Request a demo to see the evidence trail on your own device mix.

A note on scope: this article describes obligations under US federal HIPAA regulation. State law may impose additional requirements, and nothing here is legal advice. Obligations attach to the covered entity, not to any software product.

Frequently asked questions

Does HIPAA require a specific data destruction method?

No. HHS states that the Privacy and Security Rules do not require a particular disposal method, and that covered entities must review their own circumstances to determine what steps are reasonable [2].

Are the HIPAA disposal specifications Required or Addressable?

Both Disposal, 164.310(d)(2)(i), and Media Re-use, 164.310(d)(2)(ii), are Required implementation specifications [1].

Does a factory reset satisfy HIPAA media re-use requirements?

HIPAA does not name methods, so the question becomes whether your risk analysis can defend it. In the NIST framework HHS points to, a factory reset is the example given for Clear, the lowest assurance level, and Rev. 2 states purge should be used instead of clear when possible [3].

Can we degauss phones to meet HIPAA disposal requirements?

Degaussing disrupts magnetic domains, which flash storage does not use. Separately, under NIST SP 800-88 Rev. 2, at the time of its writing degaussing is not considered an approved destroy sanitization technique, with readers directed to IEEE 2883 and NSA/CSS Policy Manual 9-12 [3].

Does using an ITAD vendor transfer our HIPAA obligation?

No. The Required specifications under 164.310(d)(2) attach to the covered entity [1]. A business associate agreement governs the relationship, but the documentation burden remains yours.

Which NIST revision should we follow?

Rev. 2. Rev. 1 was published December 2014 and withdrawn 26 September 2025, superseded by Rev. 2 [4].

Sources

  1. 45 CFR 164.310, Physical safeguards (Device and Media Controls), Code of Federal Regulations, eCFR current edition.
  2. FAQs About the Disposal of Protected Health Information, U.S. Department of Health and Human Services, Office for Civil Rights.
  3. NIST SP 800-88 Rev. 2, Guidelines for Media Sanitization, NIST, September 2025.
  4. NIST SP 800-88 Rev. 1, Guidelines for Media Sanitization (December 2014; withdrawn 26 September 2025), NIST CSRC.
  5. Phonecheck internal product marketing context, source of truth for product claims (updated 2026-07-02).

相关文章

借助 Phonecheck 大规模认证设备

诊断、数据擦除与设备历史报告 —— 二手设备企业的黄金标准平台。

申请演示