Skip to content
The WesternTechSystems facility at dusk

Compliance · HIPAA

HIPAA media disposal: what the rule requires, and what it does not

Two Required implementation specifications, one safe harbour, and a great deal of vendor marketing that does not survive contact with either. This page separates your legal obligation from the evidence a disposal provider can actually give you.

In one paragraph

The short version

HIPAA requires you to have policies and procedures for the final disposition of electronic protected health information and for removing it from media before re-use. Both are Required specifications. Neither names a method, and no part of the rule certifies a disposal vendor.

What makes the rule commercially interesting is the breach safe harbour sitting next to it: media sanitized consistent with NIST SP 800-88 is no longer unsecured protected health information, and losing it does not trigger notification. That is the outcome worth buying. It is also the outcome you can only claim if the evidence exists at the level of the individual device.

1 · The obligation

What the rule actually says

Cited to the eCFR and to HHS's own published guidance. Quoted rather than paraphrased, because the paraphrases in circulation are where most of the confusion starts.

45 CFR 164.310(d)(2)(i) — Disposal (Required)

Implement policies and procedures to address the final disposition of electronic protected health information, and/or the hardware or electronic media on which it is stored.

This is a Required implementation specification, not an Addressable one. Accountability and Data backup and storage, sitting beside it at (iii) and (iv), are Addressable — vendor summaries routinely blur the two, which matters because Required means implement it, and Addressable means implement it or document why an equivalent is reasonable.

https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C/section-164.310

HHS Breach Notification Guidance — the safe harbour

Electronic media have been cleared, purged, or destroyed consistent with NIST Special Publication 800-88, Guidelines for Media Sanitization such that the PHI cannot be retrieved.

This is the most commercially significant sentence in the whole set, and it is frequently misquoted. Sanitizing to NIST 800-88 is one of the two conditions under which PHI stops being unsecured — and PHI that is not unsecured does not trigger breach notification. It is a safe harbour, not a certification.

https://www.hhs.gov/hipaa/for-professionals/breach-notification/guidance/index.html

2 · The misreading

What the rule does not say

This is the section most vendor pages omit, and it is the one that decides whether the rest of the page can be trusted.

  • It does not certify, approve or accredit any disposal vendor. HHS states this directly: it does not certify any persons or products as HIPAA compliant, and private certifications do not absolve a covered entity of its obligations under the Security Rule.

  • The phrase “HIPAA-compliant ITAD vendor” has no legal referent. A disposal provider handling PHI is a business associate — a status created by a contract under 45 CFR 164.308(b) and 164.502(e), not by a badge.

  • It does not mandate a method. Neither 164.310(d)(2)(i) nor (ii) names shredding, degaussing, overwriting or any specific technology. NIST 800-88 is referenced by HHS guidance; it is not written into the rule as a requirement.

  • It does not transfer your liability. Engaging a business associate does not move the obligation. It creates a second party who also carries one.

  • It says nothing about how long you may keep the media. HIPAA sets no general retention period for electronic protected health information — that comes from state law, from your own policy, and from any outstanding legal hold.

3 · The evidence

What an auditor actually asks for

Your policy and procedure for final disposition

The rule asks for policies and procedures, so that is the first document requested. A vendor's certificate does not satisfy a control that is defined as your written procedure.

Evidence at the level of the device, not the shipment

A pallet-level certificate answers that something was processed. It does not answer what happened to the laptop assigned to a named clinician, which is the question that actually gets asked in an enquiry.

The sanitization method, named

Clear, Purge or Destroy — and which was applied to which media type. Flash and magnetic media do not behave the same way, and a method that is adequate for one can be inadequate for the other.

An unbroken custody record

From the point the device left your control to the point it was sanitized. Gaps in that record are where an enquiry stops being routine.

The business associate agreement

Executed, current, and covering the services actually performed. An expired BAA, or one covering a narrower scope than the work, is a finding on its own.

Evidence covering redeployed devices too

Media re-use is a Required specification. Auditors who know the rule ask for the redeployment records specifically, because most organizations only prepared the disposal ones.

4 · Our part

What our documentation provides against it

Artefact What it answers
Per-serial erasure certificate Device identity, make, model, method applied and date, against the serial rather than the consignment. This is the artefact that answers a question about one clinician's laptop.
Chain-of-custody record Every transfer from collection to sanitization, timestamped, reconciled against the manifest at intake rather than afterwards.
Method statement Which NIST 800-88 category was applied to which media class, and why — including where Purge is used in place of Destroy and what makes that defensible.
Intake reconciliation report What you said you sent against what physically arrived. Discrepancies surface here, in writing, at the start — which is the only useful time for them to surface.
Business associate agreement Executed before any PHI-bearing asset moves. Scoped to the services actually performed rather than to a generic template.
Facility and process access Walkthroughs and records reviews by appointment, so your compliance officer can evidence vendor diligence with something more than a logo.

5 · Your part

What remains your obligation

No vendor can discharge these for you. Any vendor implying otherwise is selling you a risk you will still be holding.

  • Writing and maintaining the disposal and media re-use policies. The rule asks for yours, and no vendor document substitutes for them.
  • Executing and keeping current a business associate agreement before PHI-bearing assets move.
  • Performing and documenting your own diligence on us — including reading what we give you rather than filing it.
  • Identifying which devices hold electronic protected health information in the first place. This is where most programmes actually fail: the machine nobody classified is the one that turns up later.
  • Applying legal holds, and telling us before collection rather than after sanitization.

FAQ

HIPAA disposal questions

Is there such a thing as a HIPAA-certified data destruction company?
No. HHS states plainly that it does not certify any persons or products as HIPAA compliant, and that private certifications do not absolve a covered entity of its obligations. A disposal provider that handles protected health information is a business associate — a contractual status under 45 CFR 164.308(b) and 164.502(e). When you see the claim on a vendor site, what is being described is marketing rather than legal standing.
Does sanitizing to NIST 800-88 mean a lost device is not a breach?
It can, and this is the single most valuable thing to understand about the rule. HHS guidance treats media cleared, purged or destroyed consistent with NIST SP 800-88 as rendering protected health information unusable, unreadable and indecipherable — and information in that state is not unsecured PHI, so its loss does not trigger the breach notification requirements. The condition is that the sanitization actually happened and that you can evidence it against that device.
Which revision of NIST 800-88 applies?
NIST published Revision 2 as final in September 2025, superseding Revision 1, which is now withdrawn. HHS guidance still links the Revision 1 PDF, so you will see both cited. In practice: work to the current revision, and cite NIST SP 800-88 without a revision number when describing what HHS points to.
Do we need a certificate for devices we redeployed internally?
Under 164.310(d)(2)(ii), yes in substance — media re-use is a Required implementation specification, and the obligation to remove PHI before a device is made available for re-use is the same obligation whether the device leaves the building or moves to another department. Most organizations have disposal evidence and no redeployment evidence, which is exactly the gap an informed auditor looks for.
Our BAA is with a broker who subcontracts the processing. Is that a problem?
It is worth understanding precisely, because your evidence chain is only as good as its weakest link. Ask who physically holds the media, where, under whose certification, and whether your BAA reaches that party. If the answer takes more than one email to establish, that is itself the finding.

Send us your auditor's request.

Tell us what has been asked for and we will tell you which of it we can evidence — and which of it is yours to produce.