HIPAA requires healthcare providers to safeguard protected health information through its entire lifecycle including disposal. Here's the ITAD framework that meets HIPAA's technical safeguards.
Healthcare providers, hospitals, physician practices, long-term care facilities, health plans, and business associates, are subject to HIPAA's Security Rule, which requires that electronic protected health information (ePHI) be protected from unauthorized access including at the point of disposal. The HIPAA Security Rule's technical safeguards explicitly require that media containing ePHI be cleared, purged, or physically destroyed prior to reuse or disposal. Non-compliance can trigger HHS Office for Civil Rights investigations with civil penalties that range from $100 to $50,000 per violation, with annual caps up to $1.9 million.
Best-practice ITAD for healthcare providers includes several specific requirements beyond standard business practices. First, the inventory must capture all devices that may have touched ePHI, not just computers and servers, but also networked printers, copiers, fax machines, mobile devices, medical imaging equipment, and point-of-care devices. Second, data destruction must be documented with HIPAA-compliant records: serialized certificates listing each device by make, model, and serial number, destruction method, and date. Third, the ITAD provider should be willing to serve as a business associate under HIPAA, meaning they sign a Business Associate Agreement (BAA) accepting responsibility for ePHI they handle.
Healthcare providers should ask prospective ITAD providers whether they will sign a Business Associate Agreement, how their destruction process addresses NIST 800-88 guidance, and whether records are detailed enough for HIPAA reviews. Contact Chicago Lamp Recycling at 866-770-2650 to discuss a healthcare ITAD program.