Failed SSD RMA
Drive cannot be wiped reliably. SA-25 variant mandates destroy-in-place rather than shipping potentially recoverable ePHI to the vendor.
SA-25 appears in the knowledge base as Component Disposal alongside SA-24. Treat it as the disposal-variant emphasizing complete end-of-life coverage for components — including failed RMA returns, leased equipment handbacks, and affiliate transfers — so no alternate channel bypasses sanitization.
Ensure every end-of-life path for ePHI-capable components (RMA, lease return, affiliate transfer, scrap) applies equivalent disposal/sanitization controls with records — closing gaps left by primary disposal workflows.
How this control shows up in healthcare and HIPAA-covered environments.
Drive cannot be wiped reliably. SA-25 variant mandates destroy-in-place rather than shipping potentially recoverable ePHI to the vendor.
Leasing company pickup blocked until certificates show crypto-erase completed and verified.
Used clinic PCs move campuses. Transfer checklist records sanitization state so ePHI from campus A does not travel silently.
Duplicate-titled disposal controls often exist to catch channel gaps. Enriching SA-25 as the alternate-path variant strengthens end-of-life coverage for assessors.
How this NIST control supports HIPAA Security Rule expectations.
The KB lists both as Component Disposal; SA-25 is implemented here as the variant covering non-surplus exit channels while SA-24 covers primary disposal methods.
Yes — a unified disposal program can map to both IDs if all channels are covered and referenced.
Focus on components/media holding ePHI; revoke access/keys as part of disposal hygiene.
Related controls that commonly accompany SA-25.
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.