SR-12 Supply Chain Risk Management

Component Disposal

High Risk Moderate Low Cost

SR-12 requires disposing of data, documentation, tools, or system components using organization-defined techniques and methods. From a supply-chain lens, vendor returns and upgrade swaps are high-risk disposal paths for drives that still hold ePHI.

Control Objective

Dispose of components and related supply-chain artifacts through methods that prevent ePHI recovery, including when vendors, recyclers, or affiliates take custody.

Implementation Guidance

  1. Define disposal techniques for components leaving via surplus, RMA, recycler, or vendor swap.
  2. Require sanitization or destruction before supplier custody when ePHI may remain.
  3. Use BAAs/contracts with destruction/recycling vendors.
  4. Retain certificates and serial evidence.
  5. Dispose of documentation/tools that reveal sensitive configs when obsolete (coordinate SR-7).
  6. Audit disposal vendors.
  7. Align with SA-24/SA-25 and MP-6.
  8. Include failed components that cannot be wiped — destroy instead of return when needed.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Vendor upgrade swap servers

Old nodes remain until wipe/destroy certificates produced under SR-12 — vendor may not take live ePHI disks.

Recycler pickup

Only approved recycler with witnessed destruction for EHR disks.

Obsolete runbooks with credentials

Sensitive admin docs destroyed/shredded as supply-chain/tool disposal hygiene.

Best Practices

  • Sanitization before vendor custody.
  • Destroy when wipe fails.
  • Contracts with recyclers.
  • Certificates retained.
  • Include sensitive docs/tools.
  • Align SA-24/MP-6.

Common Gaps & Violations

  • RMA with live patient data disks.
  • Unknown recycler.
  • No serials on certificates.
  • Docs with passwords in dumpsters.
  • Assuming vendor wipe is sufficient without evidence.

Required Documentation

  • Supply-chain component disposal procedure (SR-12)
  • Method standards and vendor list
  • Sanitization-before-return rules
  • Certificates of destruction samples
  • Vendor audit records

How to Test & Validate

  1. Sample vendor returns for pre-custody sanitization evidence.
  2. Review recycler contracts/BAAs.
  3. Verify certificates match serials.
  4. Check failed-media destroy-vs-return decisions.
  5. Confirm sensitive document disposal samples.

Audit Considerations

Supply-chain disposal gaps are where ePHI leaves quietly. SR-12 evidence proves vendor-facing exit paths are controlled like internal surplus.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.310(d)(2)(i) Disposal — final disposition of ePHI and hardware/media.
  • 164.308(b) BA requirements — recyclers/vendors receiving media may be BAs.
  • 164.310(d)(2)(ii) Media Re-use — remove ePHI before return/reuse pathways.
  • 164.530(c) Safeguards — protect PHI through disposition.

Compliance Tips

  • Default ticketing to destroy-in-place for failed ePHI media.
  • Ban unapproved recyclers at the dock.
  • Cross-train PE-16 staff on SR-12 holds.

Frequently Asked Questions

How does SR-12 relate to SA-24?

Both address component disposal; SR-12 emphasizes supply-chain disposal channels — unify procedures and map both IDs.

Must we destroy vendor-owned loaner gear?

Sanitize before return per contract; destroy media if sanitization cannot be assured.

Are cloud snapshots SR-12?

Dispose/delete cloud data objects and keys with evidence as the cloud analog of component disposal.

References & Resources

  • NIST SP 800-53 Rev. 5 — SR-12
  • Related controls: SA-24, SA-25, MP-6, PE-16, SR-8

Need Help Implementing SR-12?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.