Skip to main content
Category: Physical and Technical Safeguards

Media Re-use

Also known as: Media Reuse, Electronic Media Re-use
Simply put

Media re-use refers to preparing electronic storage media (such as hard drives, USB devices, or backup tapes) for reassignment or reuse after they have held protected health information. The general idea is that any sensitive data must be removed before the media is used again for another purpose. This helps prevent someone who later uses that device from accidentally accessing information left behind on it.

Formal definition

Within the HIPAA Security Rule, Media Re-use is a required implementation specification under the Device and Media Controls standard of the physical safeguards. It generally requires covered entities and business associates to implement procedures for the removal of electronic protected health information (ePHI) from electronic media before those media are made available for re-use. It is distinct from the Disposal specification, which addresses final disposition of media rather than continued use; re-use assumes the media will be retained and repurposed. As a required (not addressable) specification, it must be implemented rather than treated as optional. Note that the specific regulatory text, citation, and any related guidance should be verified against the current HIPAA Security Rule, and that state law or other frameworks may impose additional requirements. The evidence packet provided did not include HIPAA-specific source material defining this term; readers should confirm details against the applicable regulatory text at 45 CFR Part 164 and current HHS OCR guidance.

Why it matters

Media re-use addresses a common but easily overlooked risk in healthcare operations: the tendency to redeploy hardware such as hard drives, USB devices, and backup tapes without fully accounting for the sensitive data those devices may still contain. When a workstation is reassigned to a new employee, or a backup tape is placed back into rotation, any protected health information left on the media can become accessible to someone who has no authorization or business need to see it. The HIPAA Security Rule treats this as a required implementation specification under the Device and Media Controls standard, meaning covered entities and business associates are generally expected to implement procedures for removing electronic protected health information (ePHI) before media are made available for re-use.

The distinction between re-use and disposal matters in practice. Disposal concerns the final disposition of media that will leave the organization or be destroyed, while re-use assumes the device is being retained and repurposed within the organization. Because it is a required rather than an addressable specification, an organization cannot treat sanitization before re-use as optional or something to be documented away; it must actually be implemented. Failing to sanitize repurposed media can leave residual ePHI that surfaces long after the original context has been forgotten.

Readers should note that the evidence available for this entry did not include HIPAA-specific source material, so the specific regulatory text, citation, and any related guidance should be confirmed against the current HIPAA Security Rule at 45 CFR Part 164 and current HHS OCR guidance. State law, the HITECH Act, or other frameworks may impose additional or more stringent requirements beyond the baseline described here.

Who it's relevant to

Security Officers and IT Asset Managers
Those responsible for provisioning, reassigning, and retiring hardware are typically the front line for media re-use compliance. They generally need documented sanitization procedures that trigger before any device known to have held ePHI is repurposed, along with a way to track which assets fall into that category.
Covered Entities and Business Associates
Both covered entities and business associates are generally subject to the Device and Media Controls standard under the HIPAA Security Rule. For business associates, these obligations typically flow through business associate agreements as well as the Security Rule's direct application, and both should confirm their procedures against current regulatory text.
Compliance and Privacy Officers
These professionals generally oversee whether required implementation specifications are actually in place rather than assumed. Because media re-use is a required specification, they should confirm that sanitization procedures exist, are followed, and are documented, and remain alert to any additional obligations imposed by state law or other frameworks.
Auditors and Assessors
Those evaluating an organization's physical safeguards typically review whether media re-use procedures address the removal of ePHI before repurposing, and whether re-use is properly distinguished from disposal. Assessors should verify findings against the current HIPAA Security Rule and current HHS OCR guidance.

Inside Media Re-use

Media Re-use (Security Rule Context)
Media re-use refers to the practice of making electronic media available for use again after it has previously stored electronic protected health information (ePHI). Under the HIPAA Security Rule, this is addressed within the Device and Media Controls standard among the physical safeguards, which governs the receipt and removal of hardware and electronic media that contain ePHI into, out of, and within a facility.
Media Re-use Implementation Specification
Within the Device and Media Controls standard, the media re-use implementation specification is generally classified as a required specification. It obligates covered entities and business associates to implement procedures for removal of ePHI from electronic media before the media are made available for re-use. Readers should verify the current classification against the applicable regulatory text.
Electronic Media Scope
The concept applies to electronic media such as hard drives, removable storage, and other devices capable of storing ePHI. Because the Security Rule governs only ePHI, media re-use as a Security Rule requirement does not by itself address paper records or other non-electronic formats, which fall under the broader Privacy Rule for disposal and safeguarding.
Relationship to Disposal
Media re-use is distinct from but related to the disposal implementation specification within the same Device and Media Controls standard. Disposal addresses the final disposition of media and ePHI, while re-use addresses preparing media for continued use. Both aim to prevent unauthorized access to residual ePHI.
Who Is Obligated
The obligation applies to covered entities and to business associates and their subcontractors when they create, receive, maintain, or transmit ePHI. For business associates, these obligations typically flow through business associate agreements and the direct applicability of the Security Rule established under the HITECH Act.

Common questions

Answers to the questions practitioners most commonly ask about Media Re-use.

Is media re-use only a concern for hard drives and computers?
No. Under the HIPAA Security Rule, the media re-use concept applies broadly to electronic media that may store ePHI, which can include items such as removable storage, backup media, mobile devices, and other electronic hardware. The common assumption that only servers or workstation hard drives are relevant understates the scope. Covered entities and business associates should generally consider any electronic media that has held ePHI before it is reused. Note that the Security Rule addresses electronic media specifically; paper and other physical PHI records are handled under the Privacy Rule's disposal considerations rather than the media re-use specification. You should verify the specific media in your environment against the current regulatory text.
Is media re-use an addressable specification I can skip if it seems inconvenient?
No. Media re-use is a required implementation specification within the device and media controls of the Security Rule's physical safeguards, not an addressable one. It is important to distinguish these categories: required specifications must be implemented, while addressable specifications must be assessed and either implemented, addressed through a reasonable alternative, or documented as not reasonable and appropriate. Even where a specification is addressable, addressable does not mean optional. Because media re-use is generally treated as required, an organization is expected to have a process ensuring ePHI is removed before media is reused. Confirm the current classification against the applicable regulatory text.
What does a media re-use process typically need to address before hardware is reassigned?
In most cases, a media re-use process focuses on ensuring that ePHI is removed from electronic media before that media is made available for reuse. Organizations generally document who is responsible, what methods are used to remove data, how removal is verified, and how the action is recorded. This entry does not prescribe specific technical sanitization methods; the appropriate approach depends on media type and organizational risk analysis. Readers should confirm details against the current Security Rule text and consult recognized technical guidance for sanitization practices.
How does media re-use relate to media disposal?
The Security Rule addresses both disposal and re-use as distinct implementation specifications within device and media controls. Disposal generally concerns the final disposition of media and any ePHI on it, while re-use concerns removing ePHI before the same media is used again rather than discarded. Both aim to prevent unauthorized retention or exposure of ePHI. Organizations typically maintain policies covering each scenario. You should verify how each specification is defined and classified in the current regulatory text.
Should re-use handling be documented, and if so, how?
Documentation is generally advisable to demonstrate that ePHI removal occurred and that the process was followed. Organizations often maintain records identifying the media, the removal method used, the date, and the responsible individual. Such records can support an organization's ability to show its safeguards were applied, though no documentation practice by itself guarantees HIPAA compliance. The level and format of documentation should reflect your risk analysis and internal policies, and you should confirm expectations against current HHS OCR guidance.
Do business associates have media re-use obligations too?
Business associates that create, receive, maintain, or transmit ePHI are generally subject to the Security Rule's requirements, which include device and media controls covering re-use. These obligations typically flow through the business associate agreement and apply directly to business associates and their subcontractors under the relevant relationships. It is important not to assume every vendor is automatically bound; obligations attach through the defined business associate relationship. Confirm each party's responsibilities in the applicable agreements and against the current regulatory text.

Common misconceptions

Deleting files or performing a standard operating-system format is sufficient before re-using media.
Standard deletion or a quick format generally does not remove the underlying data and may leave recoverable ePHI. Effective media re-use procedures typically require methods that render ePHI unreadable, indecipherable, or otherwise unrecoverable before the media is made available for re-use. Practitioners should consult current guidance on appropriate sanitization methods.
Media re-use is an addressable specification, so organizations can skip it if inconvenient.
The removal of ePHI from media before re-use is generally treated as a required implementation specification under the Device and Media Controls standard, not addressable. Even where a specification is addressable, addressable does not mean optional; it means the entity must assess whether the measure is reasonable and appropriate and document its decision. Verify the current classification against the applicable regulatory text.
Media re-use requirements cover all records, including paper files.
The Security Rule media re-use specification applies specifically to electronic media containing ePHI. Handling of paper and other non-electronic PHI is governed by the Privacy Rule's safeguarding and disposal provisions. State law or other frameworks may impose additional requirements on either format.

Best practices

Establish and document written procedures for removing ePHI from electronic media before that media is made available for re-use, consistent with the Device and Media Controls standard.
Use sanitization methods designed to render ePHI unrecoverable rather than relying on simple file deletion or a standard format, and confirm chosen methods against current guidance on media sanitization.
Maintain an inventory of hardware and electronic media that store ePHI so re-use, movement, and disposal can be tracked accountably.
Verify and log that ePHI removal was completed for each device before re-assignment or transfer, retaining documentation to demonstrate the procedure was followed.
Extend media re-use obligations to business associates and subcontractors through business associate agreements and confirm their sanitization practices where they handle your ePHI.
Review media re-use and disposal procedures against current HIPAA Security Rule text, any applicable state law, and, if pursuing HITRUST CSF certification, the current CSF version, recognizing that certification does not by itself establish HIPAA compliance.