Media Re-use
Media re-use refers to preparing electronic storage media (such as hard drives, USB devices, or backup tapes) for reassignment or reuse after they have held protected health information. The general idea is that any sensitive data must be removed before the media is used again for another purpose. This helps prevent someone who later uses that device from accidentally accessing information left behind on it.
Within the HIPAA Security Rule, Media Re-use is a required implementation specification under the Device and Media Controls standard of the physical safeguards. It generally requires covered entities and business associates to implement procedures for the removal of electronic protected health information (ePHI) from electronic media before those media are made available for re-use. It is distinct from the Disposal specification, which addresses final disposition of media rather than continued use; re-use assumes the media will be retained and repurposed. As a required (not addressable) specification, it must be implemented rather than treated as optional. Note that the specific regulatory text, citation, and any related guidance should be verified against the current HIPAA Security Rule, and that state law or other frameworks may impose additional requirements. The evidence packet provided did not include HIPAA-specific source material defining this term; readers should confirm details against the applicable regulatory text at 45 CFR Part 164 and current HHS OCR guidance.
Why it matters
Media re-use addresses a common but easily overlooked risk in healthcare operations: the tendency to redeploy hardware such as hard drives, USB devices, and backup tapes without fully accounting for the sensitive data those devices may still contain. When a workstation is reassigned to a new employee, or a backup tape is placed back into rotation, any protected health information left on the media can become accessible to someone who has no authorization or business need to see it. The HIPAA Security Rule treats this as a required implementation specification under the Device and Media Controls standard, meaning covered entities and business associates are generally expected to implement procedures for removing electronic protected health information (ePHI) before media are made available for re-use.
The distinction between re-use and disposal matters in practice. Disposal concerns the final disposition of media that will leave the organization or be destroyed, while re-use assumes the device is being retained and repurposed within the organization. Because it is a required rather than an addressable specification, an organization cannot treat sanitization before re-use as optional or something to be documented away; it must actually be implemented. Failing to sanitize repurposed media can leave residual ePHI that surfaces long after the original context has been forgotten.
Readers should note that the evidence available for this entry did not include HIPAA-specific source material, so the specific regulatory text, citation, and any related guidance should be confirmed against the current HIPAA Security Rule at 45 CFR Part 164 and current HHS OCR guidance. State law, the HITECH Act, or other frameworks may impose additional or more stringent requirements beyond the baseline described here.
Who it's relevant to
Inside Media Re-use
Common questions
Answers to the questions practitioners most commonly ask about Media Re-use.