
October 2, 2026 · 7 min
HIPAA compliant data destruction: what a covered entity should get from the vendor
Forty searches a month at $29.90 a click. The reader is a healthcare organization or a contractor to one, with drives that held patient data, and the question is what the destruction vendor has to hand over.
Search for HIPAA compliant data destruction and every result is a vendor claiming to provide it. The claim is not quite coherent. Compliance is a property of your organization’s program, judged against the regulation and its guidance, and a vendor can contribute evidence to it but cannot supply it as a product. What a covered entity or a business associate can reasonably expect from a destruction vendor is the subject here, written as our reading and not as legal advice. The regulation and your counsel decide what applies to you.
What the regulation appears to ask, in outline
As we read the privacy and security rules, they require covered entities and their business associates to have policies for the disposal of protected health information and of the hardware and media on which it is stored, to address the removal of that information from media before the media is reused or disposed of, and to document what they do. The rules describe outcomes and obligations rather than naming a method. Which methods your policy adopts, and what it has to say, is a decision your organization makes with its counsel and its security officer, and a vendor should fit into that policy rather than define it.
Whether the vendor is a business associate
A vendor who takes custody of media holding protected health information may be a business associate under the regulation, which, if so, brings the requirement for a written agreement setting out the vendor’s obligations. Whether that applies to a given engagement, and what the agreement has to contain, is a question for counsel. What we can say from our side is that a destruction vendor should be prepared to sign such an agreement, should have signed them before, and should be able to explain what they commit to under one. A vendor who has never been asked has not worked for many covered entities.
Documentation: the record you will need to produce
Whatever your policy requires, it will need evidence that it was followed. From a destruction vendor that means, at minimum, a record per device: serial number, media type, the source it came from, the method applied, the standard or category claimed, the date, the operator, the witness if any, and the outcome including exceptions. The certificate that summarises the job is not the record; the per-device report behind it is. What a certificate can and cannot carry is set out in the certificate article, and it applies with more force here because the eventual audience for the record may be a regulator.
Chain of custody from the ward to the machine
Healthcare estates are dispersed: drives in servers, but also in imaging equipment, in workstations at nursing stations, in printers and copiers, in laboratory instruments, in devices returned from home users. The custody chain has to start where the device was, not at the loading dock, and it has to be unbroken: a manifest at the point of collection, numbered seals, documented handovers, reconciliation on arrival. A gap in custody is an interval during which your organization cannot say where the information was, and that interval is what an incident review will ask about.
Media beyond the server room
The same point from the other side. A destruction engagement that only covers the data center has missed the devices that hold the most protected health information per unit: the imaging modality with an internal drive, the multifunction printer with a hard disk, the ultrasound cart. Your inventory of media holding protected health information should be the scope of the engagement, and the vendor should be able to handle media types outside the standard server population, including embedded drives that require the device to be opened.
Method and standard, stated per device
The regulation does not prescribe a method, so your policy will name one or refer to a published guideline. Most policies we see refer to NIST SP 800-88 for the categories of sanitization, and what that guideline does and does not establish has its own article. The vendor should state, per device, the method and the category claimed, and should be able to show how the result was verified. Whether the category chosen satisfies your policy is your call; whether it was actually achieved on each device is the vendor’s evidence to provide.
What to put in the contract, and what we provide
The written scope should name the media types covered, the custody discipline, whether the work is on site or at a facility and whether it is witnessed, the standard applied, the content and timing of the per-device report, the downstream fate of destroyed material, and the business associate terms if counsel says they apply. Ask us for our blank report and for the agreement terms that should apply. What each stage involves, and the record it should produce, is described on the secure data destruction page; whether it satisfies your program is a question we answer with your counsel, not instead of them.
Ask for our blank report and our agreement terms
Both before pricing. Your counsel reads them against your program; we answer their questions directly.
Data Center Exit is an independent reference on buying a data hall decommission. It decommissions nothing, destroys no media and holds no certifications of its own. It explains what a defensible chain of custody has to contain, which certificates are verifiable and how, and what to specify before a vendor quotes.