Provider leaves the medical group
Corporate phone is fully wiped the same day HR terminates; clinical apps and mail caches are sanitized under AC-19(2).
AC-19(2) addresses sanitization of information from mobile devices before reassignment, disposal, repair, or after authorized use ends. Healthcare fleets recycle tablets between units, send phones for warranty repair, and collect devices at termination — without sanitization, prior patients’ messages, downloads, and cached charts can follow the hardware. Combine remote wipe, selective wipe, and media sanitization procedures aligned with MP-6.
Remove or render unrecoverable ePHI on mobile devices when custody changes, devices are lost, repaired, or retired.
How this control shows up in healthcare and HIPAA-covered environments.
Corporate phone is fully wiped the same day HR terminates; clinical apps and mail caches are sanitized under AC-19(2).
Device is wiped and re-enrolled so oncology patient lists do not remain in local storage.
SSD is sanitized or retained; loaner issued — vendor never receives a drive with readable ePHI.
Device and media control auditors sample surplus and terminated-user devices. Missing wipe evidence for mobile ePHI endpoints is a frequent finding.
How this NIST control supports HIPAA Security Rule expectations.
Not if the device is offline or wipe is blocked — encryption and rapid reporting reduce residual risk; document the process.
It may for some flash devices if done correctly, but prefer MDM-verified wipe and follow 800-88 for storage removed from devices.
MP-6 is the general media sanitization control; AC-19(2) emphasizes sanitization in the mobile-device access-control context.
Related controls that commonly accompany AC-19(2).
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.