Vendor upgrade swap servers
Old nodes remain until wipe/destroy certificates produced under SR-12 — vendor may not take live ePHI disks.
SR-12 requires disposing of data, documentation, tools, or system components using organization-defined techniques and methods. From a supply-chain lens, vendor returns and upgrade swaps are high-risk disposal paths for drives that still hold ePHI.
Dispose of components and related supply-chain artifacts through methods that prevent ePHI recovery, including when vendors, recyclers, or affiliates take custody.
How this control shows up in healthcare and HIPAA-covered environments.
Old nodes remain until wipe/destroy certificates produced under SR-12 — vendor may not take live ePHI disks.
Only approved recycler with witnessed destruction for EHR disks.
Sensitive admin docs destroyed/shredded as supply-chain/tool disposal hygiene.
Supply-chain disposal gaps are where ePHI leaves quietly. SR-12 evidence proves vendor-facing exit paths are controlled like internal surplus.
How this NIST control supports HIPAA Security Rule expectations.
Both address component disposal; SR-12 emphasizes supply-chain disposal channels — unify procedures and map both IDs.
Sanitize before return per contract; destroy media if sanitization cannot be assured.
Dispose/delete cloud data objects and keys with evidence as the cloud analog of component disposal.
Related controls that commonly accompany SR-12.
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.