SA-25 System Acquisition

Component Disposal

High Risk Moderate Low Cost

SA-25 appears in the knowledge base as Component Disposal alongside SA-24. Treat it as the disposal-variant emphasizing complete end-of-life coverage for components — including failed RMA returns, leased equipment handbacks, and affiliate transfers — so no alternate channel bypasses sanitization.

Control Objective

Ensure every end-of-life path for ePHI-capable components (RMA, lease return, affiliate transfer, scrap) applies equivalent disposal/sanitization controls with records — closing gaps left by primary disposal workflows.

Implementation Guidance

  1. Map all exit channels beyond standard surplus: RMA, lease return, inter-facility transfer, vendor upgrade swap.
  2. Apply SA-24-equivalent sanitization/destruction gates to each channel.
  3. Require pre-return wipe evidence for RMAs when destruction is not used.
  4. Control affiliate transfers with custody and sanitization state documented.
  5. Reconcile missing assets that never hit disposal queues.
  6. Train depot and biomed staff on alternate channels.
  7. Spot-audit RMAs quarterly.
  8. Cross-reference SR-12 supply-chain disposal expectations.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Failed SSD RMA

Drive cannot be wiped reliably. SA-25 variant mandates destroy-in-place rather than shipping potentially recoverable ePHI to the vendor.

Lease return servers

Leasing company pickup blocked until certificates show crypto-erase completed and verified.

Affiliate hospital transfer

Used clinic PCs move campuses. Transfer checklist records sanitization state so ePHI from campus A does not travel silently.

Best Practices

  • Inventory all exit channels.
  • Equivalent controls for RMA/lease/transfer.
  • Prefer destroy when wipe uncertain.
  • Quarterly channel audits.
  • Custody documentation.
  • Align with SA-24/SR-12.

Common Gaps & Violations

  • RMA ships live disks.
  • Lease returns unchecked.
  • Transfers treated as not disposal.
  • Only surplus process controlled.
  • No audit of alternate channels.

Required Documentation

  • End-of-life channel matrix (SA-25)
  • RMA/lease/transfer procedures
  • Sample wipe/destroy evidence for alternate channels
  • Quarterly audit reports
  • Training for depot/biomed

How to Test & Validate

  1. List exit channels; confirm procedures exist for each.
  2. Sample an RMA for sanitization/destruction evidence.
  3. Review a lease return package.
  4. Trace an affiliate transfer.
  5. Check quarterly audit findings closure.

Audit Considerations

Duplicate-titled disposal controls often exist to catch channel gaps. Enriching SA-25 as the alternate-path variant strengthens end-of-life coverage for assessors.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.310(d)(2)(i) Disposal — final disposition applies regardless of exit channel.
  • 164.310(d)(2)(ii) Media Re-use — transfers and returns are re-use/relocation events requiring ePHI removal.
  • 164.308(b) BA requirements — vendors receiving returned media may be BAs.
  • 164.530(c) Safeguards — continuous protection through every disposition path.

Compliance Tips

  • Put RMA holds in the ticketing system by default for storage media.
  • Give leasing returns the same checklist as destruction jobs.
  • Report channel exceptions as open risks.

Frequently Asked Questions

Why enrich both SA-24 and SA-25?

The KB lists both as Component Disposal; SA-25 is implemented here as the variant covering non-surplus exit channels while SA-24 covers primary disposal methods.

Can one procedure satisfy both?

Yes — a unified disposal program can map to both IDs if all channels are covered and referenced.

Are software license retirements in scope?

Focus on components/media holding ePHI; revoke access/keys as part of disposal hygiene.

References & Resources

  • NIST SP 800-53 Rev. 5 — SA-25 (catalog variant) / SA-24 / SR-12
  • Related controls: SA-24, MP-6, SR-12, PE-16

Need Help Implementing SA-25?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.