Skip to main content
Category: Physical and Technical Safeguards

Media Disposal

Also known as: Media Disposition, Disposal of Media, Hardware and Electronic Media Disposal
Simply put

Media disposal is the process of getting rid of storage media, whether physical (such as paper) or electronic (such as hard drives, disks, and other devices), in a way that ensures any sensitive information they contain cannot be recovered by others. In healthcare compliance, this typically means destroying, wiping, or otherwise sanitizing media before it is discarded, resold, recycled, donated, or reused. The goal is to protect data, including protected health information, from unauthorized access after the media is no longer needed.

Formal definition

Media disposal refers to the controlled end-of-life handling of information media, encompassing destruction, sanitization, or disposition (reselling, reassignment, recycling, donation, or discarding) of physical and electronic media. Under the HIPAA Security Rule, media disposal is addressed within the Physical Safeguards, which include a Device and Media Controls standard covering the disposal and reuse of hardware and electronic media containing electronic protected health information (ePHI). Practitioners should note that the Security Rule applies only to ePHI, while the HIPAA Privacy Rule imposes broader obligations for the safeguarding and proper disposal of PHI in all forms, including paper and other physical media. In general practice, a disposal decision distinguishes media that contains sensitive data, requiring sanitization or destruction before release, from media determined never to have contained, or no longer to contain, sensitive data. The specific implementation approach (e.g., degaussing, physical destruction, cryptographic erasure, or overwriting) should be selected based on media type, data sensitivity, and reuse intent, and documented in policy. Covered entities and business associates should confirm current regulatory requirements, and be aware that state law, the HITECH Act, and frameworks such as the HITRUST CSF may impose additional or more specific media disposal controls. HITRUST certification and adherence to any single disposal standard do not by themselves establish HIPAA compliance.

Why it matters

Storage media routinely accumulate protected health information over their working lives, and that data does not automatically disappear when a device reaches end-of-life. Hard drives, disks, backup tapes, and even paper records can retain recoverable information long after they are decommissioned. If media are resold, recycled, donated, or discarded without proper sanitization or destruction, sensitive data, including ePHI, may become accessible to unauthorized parties, potentially resulting in an impermissible disclosure. Under the HIPAA Security Rule, the Physical Safeguards include a Device and Media Controls standard that specifically addresses the disposal and reuse of hardware and electronic media containing ePHI, making media disposal a defined compliance obligation rather than an operational afterthought.

Who it's relevant to

Security Officers and IT Asset Managers
Those responsible for implementing the Security Rule's Physical Safeguards, and specifically the Device and Media Controls standard, must establish and enforce disposal and reuse procedures for hardware and electronic media containing ePHI. This typically includes selecting appropriate sanitization or destruction methods based on media type and data sensitivity, and documenting those choices in policy.
Privacy Officers
Because the Privacy Rule covers PHI in all forms, including paper and other physical media, privacy officers should ensure that disposal practices extend beyond electronic devices. Coordinating with security staff helps avoid gaps where physical records are handled outside of ePHI-focused controls.
Business Associates and Their Subcontractors
Vendors and subcontractors that handle ePHI on behalf of covered entities generally carry media disposal obligations through their business associate agreements. This includes any downstream destruction or recycling services engaged to sanitize or destroy media, whose handling should be governed by appropriate contractual and documented controls.
Compliance and Audit Professionals
Auditors and compliance staff assessing an organization's safeguards should verify that documented disposal policies exist, that sanitization or destruction methods are appropriate to the media and data, and that disposal decisions are recorded. They should also confirm whether state law, the HITECH Act, or a targeted framework such as the HITRUST CSF imposes additional disposal requirements beyond the baseline HIPAA obligations.

Inside Media Disposal

Scope Under the Security Rule
Media disposal in the HIPAA context refers to the destruction or final disposition of media containing electronic protected health information (ePHI). It is addressed within the physical safeguards of the HIPAA Security Rule, which governs only ePHI. Disposal of PHI in paper or other non-electronic forms is instead addressed under the HIPAA Privacy Rule.
Device and Media Controls Standard
Disposal is generally treated as an implementation specification within the physical safeguard standard commonly referred to as Device and Media Controls. This standard typically also addresses media re-use, accountability, and data backup and storage. Readers should verify the specific citation and text against the current Security Rule.
Required Implementation Specification
Under the Security Rule's device and media controls, the disposal specification is generally classified as required rather than addressable, meaning covered entities and business associates are expected to implement policies and procedures addressing the final disposition of ePHI and the hardware or electronic media on which it is stored.
Media Re-Use Distinction
Disposal is distinct from media re-use. Disposal concerns removing media from service and destroying data, while re-use concerns removing ePHI before media is repurposed. Both aim to prevent unauthorized access to residual ePHI but apply in different lifecycle situations.
Applicability to Business Associates
Media disposal obligations extend to business associates and their subcontractors that handle ePHI, with responsibilities typically flowing through business associate agreements. HIPAA does not directly regulate every vendor; obligations attach through these defined relationships.
Relationship to Breach Risk
Improper media disposal can result in impermissible disclosure of ePHI, which may trigger analysis under the Breach Notification Rule. Proper disposal reduces this risk but no measure guarantees prevention of all breaches.

Common questions

Answers to the questions practitioners most commonly ask about Media Disposal.

Does deleting files or reformatting a drive satisfy HIPAA media disposal requirements?
Generally, no. Standard file deletion and quick reformatting typically leave the underlying data recoverable, so they are not considered adequate for rendering ePHI unusable and unreadable. The Security Rule addresses disposal of media containing ePHI under its physical safeguards, and covered entities and business associates are generally expected to use methods such as clearing, purging, or physical destruction appropriate to the media and the sensitivity of the data. You should confirm your chosen method against current HHS OCR guidance and recognized standards for media sanitization.
Does obtaining HITRUST certification automatically mean my media disposal practices are HIPAA compliant?
No. HITRUST is a private organization and the HITRUST CSF is a certifiable control framework; certification is not a legal requirement and does not by itself establish HIPAA compliance. While the CSF may include controls relevant to media disposal, HIPAA compliance is determined by adherence to the HIPAA rules as enforced by HHS OCR. HITRUST certification can support and demonstrate a control program, but you should still verify that your disposal practices meet the applicable Security Rule requirements independently.
What types of media should a media disposal process cover?
A disposal process should generally account for all media that may store ePHI, which can include hard drives, solid-state drives, backup tapes, USB and other portable storage, mobile devices, and multifunction devices such as printers and copiers that retain data internally. Note that the Security Rule governs only electronic protected health information; disposal of PHI in paper or other physical forms falls under the Privacy Rule and typically requires separate safeguards such as shredding. The specific media in scope depend on your environment, so an accurate inventory is generally a prerequisite.
How should responsibilities be handled when a vendor performs media disposal?
When a vendor destroys or sanitizes media containing ePHI on your behalf, that vendor generally functions as a business associate, and the relevant obligations typically attach through a business associate agreement. The agreement generally should address how media is handled, the sanitization or destruction methods used, and expectations for safeguarding data until disposal is complete. Responsibility for ensuring appropriate disposal does not simply disappear once media is handed off, so oversight and documentation of the vendor's process are generally advisable.
Should media disposal be documented, and what might that documentation include?
Documentation is generally advisable to demonstrate that ePHI was disposed of appropriately. In most cases this can include records identifying the media, the disposal or sanitization method used, the date, the personnel or vendor involved, and any certificates of destruction provided by a vendor. Maintaining such records generally helps support accountability and can be useful if practices are ever reviewed. The specific retention and content expectations should be confirmed against current HIPAA requirements and any applicable state law.
Is media disposal addressed by a required or addressable implementation specification under the Security Rule?
Disposal is addressed within the Security Rule's device and media controls. Keep in mind that where an implementation specification is designated as addressable, addressable does not mean optional; it generally means an entity must assess whether the specification is reasonable and appropriate for its environment and either implement it, implement an equivalent alternative, or document why it is not applicable. You should verify the current designation and exact requirements against the applicable regulatory text rather than assuming any element is discretionary.

Common misconceptions

Deleting files or reformatting a drive is sufficient to dispose of ePHI.
Standard deletion or reformatting often leaves recoverable data. Effective media disposal generally involves methods that render ePHI unreadable and unrecoverable, such as those described in recognized media sanitization guidance. Organizations should verify their methods against current authoritative guidance.
Media disposal requirements apply only to covered entities.
Business associates and their subcontractors that create, receive, maintain, or transmit ePHI are also expected to implement appropriate disposal safeguards, with obligations typically flowing through business associate agreements.
Because the disposal specification is a required item, addressing it once satisfies the obligation permanently.
Disposal is an ongoing operational responsibility requiring documented policies, consistent execution, and accountability across the full media lifecycle. Additionally, state law or other frameworks may impose further requirements beyond HIPAA.

Best practices

Develop and document written policies and procedures for the final disposition of ePHI and the hardware and electronic media on which it is stored, and review them periodically.
Use disposal or sanitization methods appropriate to the media type that render ePHI unreadable and unrecoverable, and verify chosen methods against current authoritative media sanitization guidance.
Maintain accountability by tracking media through disposal, including logs or records of what was destroyed, when, by whom, and by what method.
Distinguish disposal from media re-use in your procedures, ensuring ePHI is removed before any device or media is repurposed.
Extend disposal expectations to business associates and subcontractors through business associate agreements and, where appropriate, verify their disposal practices.
Confirm applicable requirements against the current HIPAA Security Rule text, and check whether state law or other frameworks impose additional disposal obligations beyond HIPAA.