{"id":4472,"date":"2026-09-24T14:16:27","date_gmt":"2026-09-24T14:16:27","guid":{"rendered":"https:\/\/hummingbirdinternational.net\/blog\/?p=4472"},"modified":"2026-09-25T16:11:30","modified_gmt":"2026-09-25T16:11:30","slug":"hipaa-compliant-laptop-disposal-healthcare-organizations","status":"publish","type":"post","link":"https:\/\/hummingbirdinternational.net\/blog\/compliance-regulations\/hipaa-compliant-laptop-disposal-healthcare-organizations\/","title":{"rendered":"HIPAA-Compliant Laptop Disposal Checklists for Healthcare Organizations"},"content":{"rendered":"<p>Hospitals and health care facilities retire hundreds of old laptops every year as part of hardware refresh cycles, technology upgrades, and office relocations. These retired devices are kept in storage rooms, transferred for reuse, sent to an IT asset disposition (ITAD) provider, or given to those who wish to take them.<\/p>\n<p><a href=\"https:\/\/www.ncbi.nlm.nih.gov\/books\/NBK500019\/\" target=\"_blank\" rel=\"nofollow noopener\">HIPAA requires<\/a> healthcare organizations to implement appropriate safeguards for protected health information, including during the final disposition of devices and electronic media.<\/p>\n<div id=\"rtoc-mokuji-wrapper\" class=\"rtoc-mokuji-content frame3 preset1 animation-fade rtoc_open default\" data-id=\"4472\" data-theme=\"Hummingbird International LLC Blog Theme\">\n\t\t\t<div id=\"rtoc-mokuji-title\" class=\" rtoc_left\">\n\t\t\t<button class=\"rtoc_open_close rtoc_open\"><\/button>\n\t\t\t<span>Table of contents<\/span>\n\t\t\t<\/div><ul class=\"rtoc-mokuji mokuji_ul level-1\"><li class=\"rtoc-item\"><a href=\"#rtoc-1\">Why HIPAA Compliance Matters for Laptop Disposal<\/a><\/li><li class=\"rtoc-item\"><a href=\"#rtoc-2\">HIPAA-Compliant Laptop Disposal Process<\/a><ul class=\"rtoc-mokuji mokuji_ul level-2\"><li class=\"rtoc-item\"><a href=\"#rtoc-3\">1. Build a Complete Device Inventory<\/a><\/li><li class=\"rtoc-item\"><a href=\"#rtoc-4\">2. Select a Data Sanitization Method<\/a><\/li><li class=\"rtoc-item\"><a href=\"#rtoc-5\">3. Maintain Chain-of-Custody<\/a><\/li><li class=\"rtoc-item\"><a href=\"#rtoc-6\">4. Obtain Disposal Approval<\/a><\/li><li class=\"rtoc-item\"><a href=\"#rtoc-7\">5. Secure Asset Transportation<\/a><\/li><li class=\"rtoc-item\"><a href=\"#rtoc-8\">6. Verify ITAD Vendor Credentials<\/a><\/li><li class=\"rtoc-item\"><a href=\"#rtoc-9\">7. Verify Data Destruction<\/a><\/li><li class=\"rtoc-item\"><a href=\"#rtoc-10\">8. Archive Disposal Records<\/a><\/li><li class=\"rtoc-item\"><a href=\"#rtoc-11\">9. Reconcile Final Disposition<\/a><\/li><\/ul><\/li><li class=\"rtoc-item\"><a href=\"#rtoc-12\">Checklist for HIPAA-Compliant Laptop Disposal<\/a><\/li><li class=\"rtoc-item\"><a href=\"#rtoc-13\">Common HIPAA Compliance Failures in Laptop Disposal<\/a><ul class=\"rtoc-mokuji mokuji_ul level-2\"><li class=\"rtoc-item\"><a href=\"#rtoc-14\">Vendor Verification Checklist: What to Confirm Before You Sign<\/a><\/li><\/ul><\/li><li class=\"rtoc-item\"><a href=\"#rtoc-15\">Conclusion<\/a><\/li><li class=\"rtoc-item\"><a href=\"#rtoc-16\">Frequently Asked Questions (FAQs)<\/a><ul class=\"rtoc-mokuji mokuji_ul level-2\"><li class=\"rtoc-item\"><a href=\"#rtoc-17\">Does HIPAA require us to notify patients if a laptop is improperly disposed of?<\/a><\/li><li class=\"rtoc-item\"><a href=\"#rtoc-18\">Are employees personally liable if a laptop is improperly disposed of?<\/a><\/li><li class=\"rtoc-item\"><a href=\"#rtoc-19\">Can we donate old healthcare laptops after wiping?<\/a><\/li><li class=\"rtoc-item\"><a href=\"#rtoc-20\">What is the difference between degaussing and shredding?<\/a><\/li><li class=\"rtoc-item\"><a href=\"#rtoc-21\">What happens to HIPAA compliance obligations if our hospital merges with or is acquired by another organization?<\/a><\/li><\/ul><\/li><\/ul><\/div><h2 id=\"rtoc-1\" >Why HIPAA Compliance Matters for Laptop Disposal<\/h2>\n<p>Most hospitals treat laptop disposal as a routine IT task. It is not. Every retired laptop that leaves your facility without proper data destruction is a compliance risk and a potential HIPAA violation waiting to happen.<\/p>\n<p>One improper disposal can lead to an OCR (Office for Civil Rights) investigation and monetary violations that accumulate per violation.<\/p>\n<p><img decoding=\"async\" loading=\"lazy\" class=\"wp-image-4395\" title=\"Healthcare Data Breach Cost Per Incident\" src=\"https:\/\/hummingbirdinternational.net\/blog\/wp-content\/uploads\/2026\/09\/image-2.png\" alt=\"Healthcare data breaches cost $7.42 million per incident, the highest of any industry, per IBM's 2025 Cost of a Data Breach Report\" width=\"1200\" height=\"1200\"><\/p>\n<p>According to the <a href=\"https:\/\/www.hipaajournal.com\/hipaa-violation-fines\/\" target=\"_blank\" rel=\"nofollow noopener\">HHS Office for Civil Rights enforcement data,<\/a> the penalties range from $100 to $50,000 per violation. On top of that, legal fees cost between $50,000 and $500,000.<\/p>\n<p>Further, <a href=\"https:\/\/www.varonis.com\/blog\/data-breach-statistics\/\" target=\"_blank\" rel=\"nofollow noopener\">IBM&#8217;s 2025 Cost of a Data Breach Report<\/a> found that breaches in the healthcare industry alone cost $7.42 million per incident. This is the highest of any industry for 12 consecutive years.<\/p>\n<div align=\"center\">\n<table cellspacing=\"0\">\n<colgroup>\n<col width=\"40%\">\n<col width=\"30%\">\n<col width=\"30%\">\n<\/colgroup>\n<tbody>\n<tr>\n<td><strong>Cost Category<\/strong><\/td>\n<td><strong>If You Don&#8217;t Comply<\/strong><\/td>\n<td><strong>Certified Disposal<\/strong><\/td>\n<\/tr>\n<tr>\n<td>Per violation \/ per device<\/td>\n<td>$100 \u2013 $50,000<\/td>\n<td>$50 \u2013 $150 per device<\/td>\n<\/tr>\n<tr>\n<td>Annual exposure<\/td>\n<td>Up to $1.5 million\/year<\/td>\n<td>50 laptops = $2,500 \u2013 $7,500 total<\/td>\n<\/tr>\n<tr>\n<td>Legal defense<\/td>\n<td>$50,000 \u2013 $500,000+<\/td>\n<td>Minimal additional cost<\/td>\n<\/tr>\n<tr>\n<td>Breach notification<\/td>\n<td>Significant \u2014 staff time + mailing costs<\/td>\n<td>Included in vendor process<\/td>\n<\/tr>\n<tr>\n<td>Reputation<\/td>\n<td>Patient trust is difficult to rebuild<\/td>\n<td>Full audit trail provided<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<p>It&#8217;s not just about doing the right thing\u2013it\u2019s about safeguarding your organization against consequences that outweigh the cost of doing it right.<\/p>\n<p>Any healthcare organization that has a <a href=\"https:\/\/hummingbirdinternational.net\/blog\/data-destruction-security\/ultimate-data-destruction-guide\/\" target=\"_blank\" rel=\"nofollow noopener\">data destruction and device disposal guidelines<\/a> or policy can never be caught off-guard by compliance problems that lead to these penalties.<\/p>\n<h2 id=\"rtoc-2\" >HIPAA-Compliant Laptop Disposal Process<\/h2>\n<p><a href=\"https:\/\/hummingbirdinternational.net\/industries\/healthcare\/\" target=\"_blank\" rel=\"nofollow noopener\">HIPAA-compliant e-waste disposal<\/a> comes down to three things: destroying data properly, documenting every step, and using certified vendors. Work through each section below before disposing of any healthcare laptop.<\/p>\n<h3 id=\"rtoc-3\" >1. Build a Complete Device Inventory<\/h3>\n<p>Before anything else, create a full record of every laptop being disposed of. Write down:<\/p>\n<ul>\n<li>Serial number of each device<\/li>\n<li>Brand and model<\/li>\n<li>What type of data it contains (patient records, billing, etc.)<\/li>\n<li>Physical condition<\/li>\n<li>Total quantity<\/li>\n<\/ul>\n<p>This inventory is your starting point for everything that follows. Auditors will ask for it. You need it to verify that every device was properly destroyed at the end of the process.<\/p>\n<h3 id=\"rtoc-4\" >2. Select a Data Sanitization Method<\/h3>\n<p>Just deleting files is not sufficient. Forensic software can recover data from deleted and even &#8220;formatted&#8221; drives. According to <a href=\"https:\/\/csrc.nist.gov\/pubs\/sp\/800\/88\/r2\/final\" target=\"_blank\" rel=\"nofollow noopener\">NIST SP 800-88<\/a>, the federal reference standard for media sanitization, data must be sanitized before disposal. Here are three HIPAA-compliant data destruction methods:<\/p>\n<ul>\n<li><strong>Physical shredding:<\/strong> The hard drive is physically broken down into small pieces. Most commonly used. Very secure.<\/li>\n<li><strong>Incineration:<\/strong> The hard drive is burned at controlled temperatures. Fully secure.<\/li>\n<li><strong>Degaussing:<\/strong>A strong magnetic field that removes information from magnetic media. Compliant with ASTM D4572.<\/li>\n<\/ul>\n<p>Your vendor needs to follow the industry standard process of <a href=\"https:\/\/hummingbirdinternational.net\/data-destruction\/\" target=\"_blank\" rel=\"nofollow noopener\">NIST 800-88 data destruction<\/a>.<br \/>\nThis is the industry benchmark for media sanitization. This is what the auditors look for.<\/p>\n<h3 id=\"rtoc-5\" >3. Maintain Chain-of-Custody<\/h3>\n<p>A chain-of-custody is a document that records the movement of all devices from the time they leave your hospital until they are destroyed. It&#8217;s your <a href=\"https:\/\/hummingbirdinternational.net\/certificates\/HB-Cert-ChainofCustody.pdf\" target=\"_blank\" rel=\"nofollow noopener\">certificate of compliance.<\/a><br \/>\nIt should include:<\/p>\n<ul>\n<li>Each laptop&#8217;s serial number<\/li>\n<li>Name of the person or department who had it and when<\/li>\n<li>Transfer dates and locations<\/li>\n<li>The name of the vendor and contact<\/li>\n<li>Destruction method and date<\/li>\n<li>Authorized vendor personnel&#8217;s signature<\/li>\n<\/ul>\n<p>This document is your response to the regulators&#8217; question: What happened to this device? Maintain chain of custody for 6 years. Some states have longer retention requirements \u2013 see your local regulations.<\/p>\n<h3 id=\"rtoc-6\" >4. Obtain Disposal Approval<\/h3>\n<p>Before you get on with the <a href=\"https:\/\/hummingbirdinternational.net\/laptop-disposal\/\" target=\"_blank\" rel=\"nofollow noopener\">disposal of laptops<\/a>, make sure to notify the right people and get a written clearance:<\/p>\n<ul>\n<li><strong>Compliance officer:<\/strong> Get written approval via email. Keep it in your records.<\/li>\n<li><strong>IT director:<\/strong> Confirm disposal plan and timeline.<\/li>\n<li><strong>Legal team:<\/strong> Flag any active lawsuits, regulatory investigations, or ongoing audits. Legal holds can override disposal timelines entirely.<\/li>\n<\/ul>\n<p>These written approvals create a paper trail showing your organization acted deliberately and responsibly. They also protect individual IT staff if questions arise later.<\/p>\n<h3 id=\"rtoc-7\" >5. Secure Asset Transportation<\/h3>\n<p>Many organizations do not realize that moving laptops from their facility to the data destruction vendor is a component of the chain of custody process.<\/p>\n<ul>\n<li>Use locked and sealed containers<\/li>\n<li>If necessary, use a secure courier<\/li>\n<li>Monitor the shipment and have proof of delivery<\/li>\n<\/ul>\n<p>Record the person who carried it, the way it was carried, and the date it was delivered.<br \/>\nDevices containing patient data must be delivered by a regular delivery service or secured box. A breach can occur during transit as well as anywhere else.<br \/>\n<center><a class=\"cta btn ewaste-cta-btn\" href=\"https:\/\/calendly.com\/hummingbirdinterational\/30min\" target=\"_blank\" rel=\"noopener\">Schedule a Secure E-Waste Pickup<\/a><\/center><\/p>\n<h3 id=\"rtoc-8\" >6. Verify ITAD Vendor Credentials<\/h3>\n<p>When <a href=\"https:\/\/hummingbirdinternational.net\/blog\/buyer-enablement\/guide-to-finding-certified-itad-partner\/\" target=\"_blank\" rel=\"nofollow noopener\">finding a certified ITAD vendor<\/a>, ask for official paperwork.<br \/>\nConfirm they have:<\/p>\n<ul>\n<li>Compliance certification (written, not oral)<\/li>\n<li>The data destruction certifications R2v3, e-Stewards, or NAID AAA<\/li>\n<li>Written destruction methodology<\/li>\n<li>Evidence of data breach liability insurance coverage<\/li>\n<li>References from other organizations<\/li>\n<\/ul>\n<h3 id=\"rtoc-9\" >7. Verify Data Destruction<\/h3>\n<p>Send a staff member, if feasible, to supervise the destruction. If this is not possible, request photos or video of the vendor with the times stamped on them.<br \/>\nA <a href=\"https:\/\/hummingbirdinternational.net\/certificates\/HB-Cert-PhysicalDestruction.pdf\" target=\"_blank\" rel=\"nofollow noopener\">Certificate of Destruction<\/a> will be issued for each laptop that is destroyed, and will contain:<\/p>\n<ul>\n<li>Device serial number<\/li>\n<li>Destruction method used<\/li>\n<li>Date of destruction<\/li>\n<li>Authorized vendor representative&#8217;s name and signature<\/li>\n<\/ul>\n<p>This certificate is legal proof of proper destruction of the device. Have one per individual device.<\/p>\n<h3 id=\"rtoc-10\" >8. Archive Disposal Records<\/h3>\n<p>Once destruction is complete, make sure to archive all the documents, which include:<\/p>\n<ul>\n<li>Device inventory<\/li>\n<li>Chain of custody documents<\/li>\n<li>Transport records<\/li>\n<li>Vendor certifications<\/li>\n<li>Certificate of destruction for each device<\/li>\n<li>Written approvals from the compliance officer and legal<\/li>\n<\/ul>\n<p>Keep these records for a minimum of 6 years. Auditors can ask for documentation years after a disposal event. Without it, there is no proof of compliance.<\/p>\n<h3 id=\"rtoc-11\" >9. Reconcile Final Disposition<\/h3>\n<p>Compare all the devices on the original inventory list with a Certificate of Destruction. Check that nothing is in a storage room, back office, or vendor&#8217;s premises. All devices need to be accounted for.<\/p>\n<p>An open compliance issue is when a device on your inventory doesn&#8217;t have a matching certificate. Resolve it before closing out the disposal process.<\/p>\n<h2 id=\"rtoc-12\" >Checklist for HIPAA-Compliant Laptop Disposal<\/h2>\n<p><strong>Before Disposal<\/strong><\/p>\n<ul style=\"list-style: none; padding-left: 1em;\">\n<li>\u2610 Inventory all retired laptops<\/li>\n<li>\u2610 Record asset and device details<\/li>\n<li>\u2610 Identify devices containing ePHI<\/li>\n<li>\u2610 Check legal holds and obtain approvals<\/li>\n<li>\u2610 Select a qualified ITAD provider<\/li>\n<\/ul>\n<p><strong>Data Sanitization<\/strong><\/p>\n<ul style=\"list-style: none; padding-left: 1em;\">\n<li>\u2610 Select the appropriate sanitization method<\/li>\n<li>\u2610 Verify data sanitization or destruction<\/li>\n<li>\u2610 Collect destruction or sanitization records<\/li>\n<\/ul>\n<p><strong>Collection &amp; Transportation<\/strong><\/p>\n<ul style=\"list-style: none; padding-left: 1em;\">\n<li>\u2610 Secure and label all assets<\/li>\n<li>\u2610 Document pickup and transportation<\/li>\n<li>\u2610 Maintain chain of custody<\/li>\n<li>\u2610 Confirm delivery to ITAD provider<\/li>\n<\/ul>\n<p><strong>Vendor Verification<\/strong><\/p>\n<ul style=\"list-style: none; padding-left: 1em;\">\n<li>\u2610 Verify ITAD and data-security certifications<\/li>\n<li>\u2610 Review sanitization and security procedures<\/li>\n<li>\u2610 Confirm asset-level reporting<\/li>\n<\/ul>\n<p><strong>Final Disposition<\/strong><\/p>\n<ul style=\"list-style: none; padding-left: 1em;\">\n<li>\u2610 Match assets to disposition records<\/li>\n<li>\u2610 Resolve unmatched assets<\/li>\n<li>\u2610 Archive disposal records<\/li>\n<li>\u2610 Close out the disposal process<\/li>\n<\/ul>\n<p><strong>Final Check<\/strong><\/p>\n<ul style=\"list-style: none; padding-left: 1em;\">\n<li>\u2610 All laptops accounted for<\/li>\n<li>\u2610 Disposition fully documented<\/li>\n<li>\u2610 Chain of custody complete<\/li>\n<\/ul>\n<p><center><a class=\"cta btn ewaste-cta-btn\" href=\"https:\/\/hummingbirdinternational.net\/blog\/wp-content\/uploads\/2026\/09\/HIPAA-Compliant-Laptop-Disposal-Checklist.pdf\" target=\"_blank\" rel=\"noopener\" download=\"\">Download This<\/a><\/center><\/p>\n<h2 id=\"rtoc-13\" >Common HIPAA Compliance Failures in Laptop Disposal<\/h2>\n<p>These errors are commonplace. They&#8217;ve led to fines, investigations, and reputational harm.<\/p>\n<ul>\n<li><strong>Using non-certified vendors:<\/strong> The cheaper the vendor, the more likely you are to be fined if you use a non-certified vendor. HIPAA-certified vendors are more expensive because they abide by the rules. Only use certified partners.<\/li>\n<li><strong>Donating laptops with software wipes:<\/strong> &#8220;We deleted all the files&#8221; is not sufficient to meet HIPAA requirements. Deleted data can be recovered using forensic tools in minutes. It must be physically destroyed.<\/li>\n<li><strong>No chain of custody:<\/strong> If you can&#8217;t show who had it at each step and where it went, you can&#8217;t show that it was destroyed properly. Auditors will ask. You don&#8217;t need to rely on trust; you need documentation.<\/li>\n<li><strong>Destroying drives but keeping laptops:<\/strong> Shredding the hard drive, but retaining the laptop in storage, is still a liability. Dispose of the entire device. Residual data can exist on other components.<\/li>\n<li><strong>Missing Business Agreements:<\/strong> Verbal agreements are not binding. If the vendor fails, your hospital is liable for the entire loss without a signed document. No exceptions.<\/li>\n<li><strong>Treating disposal as a one-time event:<\/strong> Device disposal should be a regular and planned process, as part of your IT refresh cycle and compliance calendar. Not something you figure out each time a closet fills up.<\/li>\n<\/ul>\n<p>That&#8217;s why <a href=\"https:\/\/hummingbirdinternational.net\/blog\/compliance-regulations\/wiped-devices-fail-it-audit\/\" target=\"_blank\" rel=\"nofollow noopener\">data wiping alone is not sufficient<\/a> to meet compliance standards. Auditors will never approve if this is the only thing you did.<br \/>\n<img decoding=\"async\" loading=\"lazy\" class=\"wp-image-4395\" title=\"Common HIPAA Compliance Failures in Laptop Disposal\" src=\"https:\/\/hummingbirdinternational.net\/blog\/wp-content\/uploads\/2026\/09\/Image-3.png\" alt=\"Common HIPAA compliance failures in laptop disposal: non-certified vendors, no chain of custody, missing business agreements, software wipes, and more\" width=\"1200\" height=\"1200\"><\/p>\n<h3 id=\"rtoc-14\" >Vendor Verification Checklist: What to Confirm Before You Sign<\/h3>\n<p>Use this checklist to evaluate any vendor before signing a contract. Before you sign a contract, ask a vendor the following questions:<\/p>\n<p><strong>Certifications<\/strong><\/p>\n<ul style=\"list-style: none; padding-left: 1em;\">\n<li>\u2610 HIPAA compliance certification provided in writing<\/li>\n<li>\u2610 Data destruction certifications verified (R2v3, e-Stewards, or NAID AAA)<\/li>\n<\/ul>\n<p><strong>Process and Documentation<\/strong><\/p>\n<ul style=\"list-style: none; padding-left: 1em;\">\n<li>\u2610 Certificate of Destruction provided per device<\/li>\n<li>\u2610 Chain of custody process clearly explained<\/li>\n<li>\u2610 Confirmed how many days devices are held before destruction<\/li>\n<\/ul>\n<p><strong>Destruction Methods<\/strong><\/p>\n<ul style=\"list-style: none; padding-left: 1em;\">\n<li>\u2610 On-site or off-site destruction option confirmed<\/li>\n<li>\u2610 Destruction standards clearly stated (NIST 800-88, ASTM D4572)<\/li>\n<li>\u2610 Vague or ambiguous answers about data handling<\/li>\n<\/ul>\n<p><center><a class=\"cta btn ewaste-cta-btn\" href=\"https:\/\/hummingbirdinternational.net\/blog\/wp-content\/uploads\/2026\/09\/Vendor-Verification-Checklist.pdf\" target=\"_blank\" rel=\"noopener\" download=\"\">Download This<\/a><\/center><br \/>\nThe choice between <a href=\"https:\/\/hummingbirdinternational.net\/blog\/data-destruction-security\/onsite-vs-offsite-data-destruction\/\" target=\"_blank\" rel=\"nofollow noopener\">on-site and off-site data destruction<\/a> depends on your volume, risk tolerance, and operational setup. If done properly, both are compliant.<\/p>\n<p>Look for a vendor that can provide a professional laptop disposal service with a detailed destruction process and HIPAA certification.<\/p>\n<h2 id=\"rtoc-15\" >Conclusion<\/h2>\n<p>One of the least considered compliance issues in healthcare IT is laptop disposal. It doesn&#8217;t seem like an emergency until it is an emergency. Those old devices have patient data stored on them. A single breach (from one improperly disposed laptop) can result in fines, investigations and breach notification costs that far exceed any disposal program.<\/p>\n<p>Your organization has a clear and repeatable process with the nine-step checklist in this guide. Use qualified vendors, apply appropriate data sanitization or destruction methods, and document each step as part of your regular IT refresh cycle. This helps protect patient information and reduce compliance risks.<\/p>\n<h2 id=\"rtoc-16\" >Frequently Asked Questions (FAQs)<\/h2>\n<h3 id=\"rtoc-17\" >Does HIPAA require us to notify patients if a laptop is improperly disposed of?<\/h3>\n<p>Yes, if the improper disposal results in a breach of unsecured PHI, the HIPAA Breach Notification Rule may apply. Patients who are affected should be informed within 60 days of the discovery of the breach. Breaches involving 500 or more individuals in a state must also be reported to HHS and may require notification to prominent media outlets.<\/p>\n<h3 id=\"rtoc-18\" >Are employees personally liable if a laptop is improperly disposed of?<\/h3>\n<p>Under HIPAA&#8217;s criminal provisions, in some instances, individuals may be subject to penalties. Staff members who knowingly access or release PHI without permission could be fined and subject to other penalties. Written authorisations, clear procedures, and chain of custody records provide evidence of an appropriate disposal process.<\/p>\n<h3 id=\"rtoc-19\" >Can we donate old healthcare laptops after wiping?<\/h3>\n<p>Potentially. Healthcare organizations may reuse or donate equipment when an appropriate sanitization process has been completed and the organization can demonstrate that ePHI has been properly addressed. Physical destruction is not automatically required when the device is intended for reuse.<\/p>\n<h3 id=\"rtoc-20\" >What is the difference between degaussing and shredding?<\/h3>\n<p>Degaussing and shredding are not the same. In degaussing a powerful magnetic field is used to remove data from magnetic storage media by a process called degaussing.<\/p>\n<p>Shredding physically breaks up the drive into small pieces. Both are certified to be HIPAA-compliant. Unlike hard drives, SSDs are not degaussable, but must be physically destroyed.<\/p>\n<h3 id=\"rtoc-21\" >What happens to HIPAA compliance obligations if our hospital merges with or is acquired by another organization?<\/h3>\n<p>HIPAA responsibilities do not end when a company merges or acquires another company. The organizations should review the existing Business Associate Agreements and update as necessary. The devices acquired from the other organization should also be tracked and disposed of through the proper IT asset disposition process.<\/p>\n<p><script type=\"application\/ld+json\">{\"@context\":\"https:\/\/schema.org\",\"@type\":\"FAQPage\",\"mainEntity\":[{\"@type\":\"Question\",\"name\":\"Does HIPAA require us to notify patients if a laptop is improperly disposed of?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Yes, if the improper disposal results in a breach of unsecured PHI, the HIPAA Breach Notification Rule may apply. Patients who are affected should be informed within 60 days of the discovery of the breach. Breaches involving 500 or more individuals in a state must also be reported to HHS and may require notification to prominent media outlets.\"}},{\"@type\":\"Question\",\"name\":\"Are employees personally liable if a laptop is improperly disposed of?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Under HIPAA's criminal provisions, in some instances, individuals may be subject to penalties. Staff members who knowingly access or release PHI without permission could be fined and subject to other penalties. Written authorisations, clear procedures, and chain of custody records provide evidence of an appropriate disposal process.\"}},{\"@type\":\"Question\",\"name\":\"Can we donate old healthcare laptops after wiping?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Potentially. Healthcare organizations may reuse or donate equipment when an appropriate sanitization process has been completed and the organization can demonstrate that ePHI has been properly addressed. Physical destruction is not automatically required when the device is intended for reuse.\"}},{\"@type\":\"Question\",\"name\":\"What is the difference between degaussing and shredding?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Degaussing and shredding are not the same. In degaussing a powerful magnetic field is used to remove data from magnetic storage media by a process called degaussing. Shredding physically breaks up the drive into small pieces. Both are certified to be HIPAA-compliant. Unlike hard drives, SSDs are not degaussable, but must be physically destroyed.\"}},{\"@type\":\"Question\",\"name\":\"What happens to HIPAA compliance obligations if our hospital merges with or is acquired by another organization?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"HIPAA responsibilities do not end when a company merges or acquires another company. The organizations should review the existing Business Associate Agreements and update as necessary. The devices acquired from the other organization should also be tracked and disposed of through the proper IT asset disposition process.\"}}]}<\/script><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Hospitals and health care facilities retire hundreds of old laptops every year as part of hardware refresh cycles, technology upgrades, and office relocations. These retired devices are kept in storage rooms, transferred for reuse, sent to an IT asset disposition (ITAD) provider, or given to those who wish to take them. HIPAA requires healthcare organizations [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":4475,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false},"categories":[76],"tags":[],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/hummingbirdinternational.net\/blog\/wp-json\/wp\/v2\/posts\/4472"}],"collection":[{"href":"https:\/\/hummingbirdinternational.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/hummingbirdinternational.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/hummingbirdinternational.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/hummingbirdinternational.net\/blog\/wp-json\/wp\/v2\/comments?post=4472"}],"version-history":[{"count":42,"href":"https:\/\/hummingbirdinternational.net\/blog\/wp-json\/wp\/v2\/posts\/4472\/revisions"}],"predecessor-version":[{"id":4526,"href":"https:\/\/hummingbirdinternational.net\/blog\/wp-json\/wp\/v2\/posts\/4472\/revisions\/4526"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/hummingbirdinternational.net\/blog\/wp-json\/wp\/v2\/media\/4475"}],"wp:attachment":[{"href":"https:\/\/hummingbirdinternational.net\/blog\/wp-json\/wp\/v2\/media?parent=4472"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/hummingbirdinternational.net\/blog\/wp-json\/wp\/v2\/categories?post=4472"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/hummingbirdinternational.net\/blog\/wp-json\/wp\/v2\/tags?post=4472"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}