MP-6 Media Protection

Media Sanitization

High Risk Moderate Low Cost

MP-6 requires sanitizing system media containing organizational information before disposal, release out of organizational control, or reuse. For healthcare that means drives, tapes, USB media, copiers, and devices that may retain ePHI must be cleared, purged, or destroyed per NIST SP 800-88-aligned methods — not just deleted in the Recycle Bin.

Control Objective

Ensure no recoverable ePHI leaves organizational control on media through improper disposal, vendor return, or reuse.

Implementation Guidance

  1. Inventory media types that may hold ePHI (HDD/SSD, tapes, USB, copier drives, medical device storage).
  2. Select sanitization methods by media type and disposition (clear/purge/destroy) referencing SP 800-88.
  3. Require chain-of-custody tickets from decommission to wipe/destruction certificate.
  4. Verify sanitization (sample validate wipes; keep destruction certificates for shredded drives).
  5. Cover cloud/decommissioned VMs and encrypted volume key destruction where applicable.
  6. Train staff that formatting alone is not enough for release from control.
  7. Extend to leased copiers and failed drives under warranty RMA — use purge or destroy policies.
  8. Retain sanitization records for HIPAA documentation periods.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Copier lease return with patient scans

A multifunction printer is returned without drive removal. MP-6 requires purge/removal and certification before pickup — preventing a classic ePHI disclosure.

Failed SSD sent for warranty RMA

Instead of shipping raw, the clinic destroys the drive under policy or uses vendor certified purge options documented for ePHI media.

Clinic closure surplus PCs

Surplus laptops are crypto-erased (keys destroyed) or physically shredded with logged asset tags before donation.

Best Practices

  • Follow NIST SP 800-88 media-specific methods.
  • Certificates of destruction from vetted vendors.
  • Asset-tag linkage in sanitization records.
  • Special process for warranty returns.
  • Include copier/biomed storage in scope.
  • Prefer encrypt-then-crypto-erase when viable.

Common Gaps & Violations

  • Recycle Bin / quick format as 'wipe.'
  • Copiers and scanners forgotten.
  • No records of what was destroyed.
  • RMA shipments of unsanitized drives.
  • Cloud volumes deleted without considering snapshots.

Required Documentation

  • Media sanitization procedure (methods by media)
  • Chain-of-custody / ticket workflow
  • Destruction vendor agreements and certificates
  • Sample sanitization records
  • Staff training acknowledgment

How to Test & Validate

  1. Walk a decommissioned drive through the full MP-6 process.
  2. Confirm certificates match asset tags.
  3. Interview facilities staff about copier returns.
  4. Review recent RMA cases for sanitization steps.
  5. Spot-check surplus inventory for pending wipes.

Audit Considerations

HIPAA device and media controls assess disposal practices. Missing destruction evidence for drives that held ePHI is a frequent finding.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.310(d)(2)(i) Disposal — policies for final disposition of ePHI and/or hardware/electronic media.
  • 164.310(d)(2)(ii) Media Re-use — procedures for removal of ePHI before reuse.
  • 164.310(d)(1) Device and Media Controls — overall standard covering receipt and removal tracking.
  • 164.312(c) Integrity — improper disposal can lead to unauthorized alteration/disclosure risks.

Compliance Tips

  • Put MP-6 steps on the IT asset retirement checklist with required fields.
  • Maintain an approved destruction vendor and keep certificates centrally.
  • Ask copier vendors for drive-retention or certified purge options in contracts.

Frequently Asked Questions

Is deleting files enough before donating a PC?

No. Use approved clear/purge/destroy methods so ePHI is not recoverable.

Do encrypted drives need physical destruction?

Crypto-erase (destroying keys) can be acceptable when encryption was strong and keys are truly gone — document the method per SP 800-88.

Are cloud disks in scope?

Yes — include volume deletion, snapshot removal, and key management in sanitization procedures.

References & Resources

  • NIST SP 800-53 Rev. 5 — MP-6
  • NIST SP 800-88 Guidelines for Media Sanitization
  • HIPAA § 164.310(d)
  • Related controls: MP-5, MP-4, CM-8, CP-9

Need Help Implementing MP-6?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.