EHR storage array retirement
Array disks are shredded with filmed serial capture under SA-24; certificates filed with asset records.
SA-24 requires disposing of system components using organization-defined techniques and methods. Retired EHR servers, clinic PCs, and medical devices with storage must leave through controlled disposal so residual ePHI is not recoverable from surplus channels.
Dispose of ePHI-capable system components through authorized methods that sanitize or destroy storage and document chain of custody through final disposition.
How this control shows up in healthcare and HIPAA-covered environments.
Array disks are shredded with filmed serial capture under SA-24; certificates filed with asset records.
Manager tries to donate PCs to a school. Disposal process intercepts, wipes/destroys drives first.
Device disposal checklist requires verifying study storage cleared or disk removed before vendor trade-in.
Improper disposal remains a classic HIPAA breach pattern. SA-24 evidence should prove controlled final disposition of ePHI components.
How this NIST control supports HIPAA Security Rule expectations.
MP-6 is media sanitization; SA-24 addresses disposing of system components using defined techniques — typically implemented together in healthcare asset retirement.
Dispose/deprovision cloud volumes and snapshots with sanitization analogs; retain evidence of deletion per provider capabilities.
Only after approved sanitization/destruction of ePHI storage and documented clearance.
Related controls that commonly accompany SA-24.
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.