45 CFR § 164.310(d)
Governs the receipt, removal, movement, and disposal of hardware and electronic media containing ePHI. Ensures proper sanitization of devices before reuse or disposal and tracks media throughout its lifecycle.
Sample Preview
Version 1.0·Effective [EFFECTIVE DATE]·Approved by [PRIVACY/SECURITY OFFICER NAME]
This policy governs the receipt, removal, movement, disposal, and reuse of hardware and electronic media that contain ePHI at [PRACTICE NAME]. Proper device and media controls prevent ePHI from being lost, stolen, or improperly disclosed when devices change hands, are moved, or reach end-of-life.
This policy applies to all hardware and electronic media that contain, have contained, or may contain ePHI. This includes hard drives, USB drives, CDs/DVDs, backup tapes, servers, workstations, laptops, tablets, smartphones, copiers with hard drives, fax machines with memory, medical devices with storage, and any other device or media capable of storing electronic data. It applies to all workforce members, IT vendors, and disposal contractors.
[PRACTICE NAME] shall implement policies and procedures that govern the receipt and removal of hardware and electronic media that contain ePHI into and out of a facility, and the movement of these items within the facility, as required by 45 CFR § 164.310(d). All ePHI shall be properly removed from devices and media before they are disposed of, reused, or transferred.
Electronic Media: Electronic storage material, including memory devices in computers (hard drives, SSDs) and any removable or transportable digital storage medium, such as USB flash drives, CDs, DVDs, magnetic tape, and memory cards.
Sanitization: The process of removing data from electronic media so that it cannot be retrieved or reconstructed. Methods include clearing (overwriting), purging (degaussing or cryptographic erasure), and destroying (shredding, incinerating, or disintegrating).
Disposal: The act of discarding electronic media or hardware that is no longer needed, with all ePHI properly sanitized beforehand.
Reuse: The act of repurposing electronic media or hardware for a different user or function, with all previous ePHI properly sanitized beforehand.
while we’re in beta
A professional, CFR-referenced policy template, ready to customize for your practice. Free during the beta.
Free while we’re in beta
Need more than one?
The Complete HIPAA Policy Library — every policy, checklist, and review template. Free while we’re in beta.
Free while we’re in beta
Templates require customization and legal review before adoption. Not legal advice. See full disclaimer.