SA-24 System Acquisition

Component Disposal

High Risk Moderate Low Cost

SA-24 requires disposing of system components using organization-defined techniques and methods. Retired EHR servers, clinic PCs, and medical devices with storage must leave through controlled disposal so residual ePHI is not recoverable from surplus channels.

Control Objective

Dispose of ePHI-capable system components through authorized methods that sanitize or destroy storage and document chain of custody through final disposition.

Implementation Guidance

  1. Define disposal methods by component type (disk destroy, crypto-erase, degauss where applicable, certified vendor).
  2. Require tickets linking CM-8 assets to disposal jobs.
  3. Complete MP-6 sanitization before transfer to recycler when destroying onsite is not used.
  4. Use certified destruction vendors under BA/HIPAA terms when they handle ePHI media.
  5. Capture certificates of destruction and serials.
  6. Prohibit curb-side e-waste for ePHI devices.
  7. Include clinical devices with onboard storage.
  8. Audit disposal vendors periodically.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

EHR storage array retirement

Array disks are shredded with filmed serial capture under SA-24; certificates filed with asset records.

Clinic PC surplus attempt

Manager tries to donate PCs to a school. Disposal process intercepts, wipes/destroys drives first.

Ultrasound with local studies

Device disposal checklist requires verifying study storage cleared or disk removed before vendor trade-in.

Best Practices

  • Method standards by media type.
  • Chain of custody to destruction.
  • Certificates retained.
  • BA terms for destruction vendors.
  • Block informal donation/surplus.
  • Include biomed devices.

Common Gaps & Violations

  • Surplus without wipe.
  • No certificates of destruction.
  • Staff taking home old PCs.
  • Vendor trade-ins with live drives.
  • Unknown final disposition.

Required Documentation

  • Component disposal procedure (SA-24)
  • Approved methods and vendors
  • Disposal tickets and serial logs
  • Certificates of destruction
  • Vendor audit records

How to Test & Validate

  1. Sample recent disposals for sanitization/destruction evidence.
  2. Verify serials match certificates.
  3. Review destruction vendor contract/BAA.
  4. Check biomed device disposal path.
  5. Confirm surplus/donation gates.

Audit Considerations

Improper disposal remains a classic HIPAA breach pattern. SA-24 evidence should prove controlled final disposition of ePHI components.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.310(d)(2)(i) Disposal — address final disposition of ePHI and/or the hardware or electronic media on which it is stored.
  • 164.310(d) Device and Media Controls — policies for disposal and re-use.
  • 164.530(c) Safeguards — reasonable safeguards through end of component life.
  • 164.308(a)(1) Risk Management — disposal risk is foreseeable and treatable.

Compliance Tips

  • Make facilities/IT surplus routes impossible without SA-24 clearance.
  • Film high-value destructions when practical.
  • Cross-link SA-24 with MP-6 and SR-12.

Frequently Asked Questions

Is SA-24 the same as MP-6?

MP-6 is media sanitization; SA-24 addresses disposing of system components using defined techniques — typically implemented together in healthcare asset retirement.

Do cloud resources need SA-24?

Dispose/deprovision cloud volumes and snapshots with sanitization analogs; retain evidence of deletion per provider capabilities.

Can we donate equipment?

Only after approved sanitization/destruction of ePHI storage and documented clearance.

References & Resources

  • NIST SP 800-53 Rev. 5 — SA-24
  • Related controls: MP-6, MP-7, SR-12, CM-8, PE-16

Need Help Implementing SA-24?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.