Copier lease return with patient scans
A multifunction printer is returned without drive removal. MP-6 requires purge/removal and certification before pickup — preventing a classic ePHI disclosure.
MP-6 requires sanitizing system media containing organizational information before disposal, release out of organizational control, or reuse. For healthcare that means drives, tapes, USB media, copiers, and devices that may retain ePHI must be cleared, purged, or destroyed per NIST SP 800-88-aligned methods — not just deleted in the Recycle Bin.
Ensure no recoverable ePHI leaves organizational control on media through improper disposal, vendor return, or reuse.
How this control shows up in healthcare and HIPAA-covered environments.
A multifunction printer is returned without drive removal. MP-6 requires purge/removal and certification before pickup — preventing a classic ePHI disclosure.
Instead of shipping raw, the clinic destroys the drive under policy or uses vendor certified purge options documented for ePHI media.
Surplus laptops are crypto-erased (keys destroyed) or physically shredded with logged asset tags before donation.
HIPAA device and media controls assess disposal practices. Missing destruction evidence for drives that held ePHI is a frequent finding.
How this NIST control supports HIPAA Security Rule expectations.
No. Use approved clear/purge/destroy methods so ePHI is not recoverable.
Crypto-erase (destroying keys) can be acceptable when encryption was strong and keys are truly gone — document the method per SP 800-88.
Yes — include volume deletion, snapshot removal, and key management in sanitization procedures.
Related controls that commonly accompany MP-6.
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.