HIPAA data disposal: erasing ePHI
For healthcare organisations, a drive isn't just a drive — it's a container of protected health information. HIPAA has rules about what happens to it.
The HIPAA Security Rule requires covered entities and business associates to implement policies for the disposal of electronic protected health information (ePHI). The US Department of Health & Human Services explicitly recognises clearing, purging, and destruction of media as compliant methods.
What HIPAA requires
HIPAA doesn't mandate a specific tool — it requires that ePHI be disposed of so it cannot be reconstructed. For storage media, that maps cleanly onto the same Clear / Purge / Destroy ladder in NIST 800-88:
- Clear — overwrite or ATA Secure Erase for media staying in use.
- Purge — Enhanced Secure Erase, NVMe Sanitize, or cryptographic erase for media leaving the organisation.
- Destroy — shredding or disintegration where erasure isn't possible.
Documentation matters
HIPAA compliance is enforced through documentation. If a breach or audit occurs, you need to show what happened to specific devices. A report that ties a serial-numbered drive to a date, a method, and a final status — backed by pre-wipe SMART data — is exactly the evidence auditors and OCR (the Office for Civil Rights) expect.
How tScrub supports HIPAA disposal
- Purge-level erasure for drives leaving your control, with the method recorded per drive.
- A chain-of-custody report including serial numbers and pre/post-wipe SMART health.
- A certificate of destruction for every sanitised device.
FAQ
Does HIPAA require a specific number of overwrite passes?
No. HIPAA specifies outcomes, not techniques. A single firmware-level Purge is stronger than any multi-pass overwrite, and far easier to document.
What about drives that can't be erased?
Failed or locked drives must be physically destroyed — and you still want a record of their serial numbers and disposition, so the audit trail has no gaps.