HIPAA data disposal: erasing ePHI

For healthcare organisations, a drive isn't just a drive — it's a container of protected health information. HIPAA has rules about what happens to it.

t tScrub Team Last updated 22 Sep 2026 5 min read

The HIPAA Security Rule requires covered entities and business associates to implement policies for the disposal of electronic protected health information (ePHI). The US Department of Health & Human Services explicitly recognises clearing, purging, and destruction of media as compliant methods.

What HIPAA requires

HIPAA doesn't mandate a specific tool — it requires that ePHI be disposed of so it cannot be reconstructed. For storage media, that maps cleanly onto the same Clear / Purge / Destroy ladder in NIST 800-88:

Documentation matters

HIPAA compliance is enforced through documentation. If a breach or audit occurs, you need to show what happened to specific devices. A report that ties a serial-numbered drive to a date, a method, and a final status — backed by pre-wipe SMART data — is exactly the evidence auditors and OCR (the Office for Civil Rights) expect.

How tScrub supports HIPAA disposal

FAQ

Does HIPAA require a specific number of overwrite passes?

No. HIPAA specifies outcomes, not techniques. A single firmware-level Purge is stronger than any multi-pass overwrite, and far easier to document.

What about drives that can't be erased?

Failed or locked drives must be physically destroyed — and you still want a record of their serial numbers and disposition, so the audit trail has no gaps.

Keep reading

Dispose of ePHI with a record to show

tScrub wipes drives to Purge and writes a verifiable report for every device.

Get tScrub