SANITIZE

CertifiedNIST SP 800-88 Rev. 2 · DoD 5220.22-M · IEEE 2883

Data Erasure for Healthcare

Secure patient data. Protect privacy.

Healthcare organisations hold some of the most sensitive information there is: patient records, PHI and ePHI, medical reports, billing details, insurance information and personal data. When a computer, server, hard drive, SSD or medical device is retired, deleting the files or formatting the disk does not reliably remove any of it.

Data sanitization is the step that does. It makes sure the information is securely erased and cannot simply be recovered by the next person to hold the device.

A retired device still carries confidential patient and business information. If that information is not properly erased before the device leaves your control, the privacy and security risk leaves with it.

What Goes Wrong

The Risks This Removes

PHI on Devices Nobody Tracks

Imaging consoles, laboratory analysers and portable diagnostic units store patient data locally and often sit outside the IT asset register entirely. A supplier swaps the unit, and the drive goes with them.

Factory Reset Treated as Erasure

A reset clears the interface, not the medium. Data written before the reset is frequently still sitting on the drive underneath and still recoverable from it.

No Document When It Is Needed

An investigation asks what happened to one specific device. Without a record kept per asset, the honest answer is that nobody knows.

Before The Device Leaves

Identify, Erase, Verify, Report, Then Decide

Do not rely on simple deletion. Run these five steps before a device is reused, transferred, sold, recycled or disposed of, and the risk stops at the door.

  1. 01

    Identify

    Find every device and every medium inside it, including the imaging consoles and analysers that never made it onto the asset register.

  2. 02

    Erase

    Wipe, erase or securely purge the medium using the method appropriate to that device and to how sensitive the data on it is.

  3. 03

    Verify

    Read the medium back afterwards and confirm the erasure actually succeeded. A device that will not verify is never certified.

  4. 04

    Report

    Produce a detailed erasure record per device, signed and kept, so the process can be audited long after the hardware has gone.

  5. 05

    Reuse, Recycle or Destroy

    Redeploy it, resell it, recycle it or dispose of it. Whichever it is, the evidence was created before the decision was acted on.

What Can Be Sanitized

DSP Pro securely erases data from HDDs, SSDs, laptops, desktops, servers, USB drives, external drives and the storage inside medical and IT equipment. Depending on the device and the security requirement, data can be wiped, erased or securely purged using the method appropriate to that medium — not one blanket method applied to everything.

Mixed healthcare hardware — ward workstation, imaging console drive, laptop and USB media on a bench

Simple, Secure Data Erasure

DSP Pro makes professional data erasure straightforward for healthcare organisations and the IT teams that support them. Erase and wipe securely, sanitize several devices at once, verify that the erasure actually succeeded, generate detailed reports, keep the records for audit and compliance, and run the whole thing as part of your existing IT asset disposal process.

Erasure console showing several healthcare devices being processed at once

Based on International Practice

DSP Pro supports sanitization processes built on internationally recognised standards and guidelines, so an organisation follows one consistent and reliable approach rather than a different one per device. The correct method depends on the type of storage, how sensitive the data is, and what happens to the device afterwards — and the software chooses on those grounds.

Standards list with the method selected for each medium highlighted

When Healthcare Data Should Be Erased

The MomentWhy It Is The Right Moment
Replaced or upgradedThe old device leaves the ward long before anyone checks what is still on it.
Retired or decommissionedA device out of service is out of mind, and a stored drive is still a live risk.
Returned after a leaseOnce it is back with the supplier you hold nothing but the record you made first.
Sold or donatedThe next owner has physical access to the medium, and recovery tools are free.
Recycled or disposed ofA recycler proves collection. Only erasure proves the data went with it.
Transferred to another departmentA new purpose is a new set of people, and old patient data should not travel with it.
Removed from medical or IT systemsComing off the network does not take the data off the disk.

What Secure Sanitization Gives a Healthcare Organisation

  • Patient and confidential information protected before hardware changes hands
  • Unauthorised data recovery prevented rather than assumed unlikely
  • The risk of a data breach reduced at the point it is easiest to control
  • Old and retired IT equipment secured instead of stored and forgotten
  • HIPAA and other security requirements supported with documented evidence
  • Devices safely reused, resold, recycled or disposed of
  • Clear records of the erasure process kept for as long as you need them
  • 25 methodsErasure Standards Built In

    NIST SP 800-88 Clear and Purge, IEEE 2883, DoD 5220.22-M, BSI, DPDP and twenty more. The software issues what the medium actually supports.

  • 100%Of Erased Drives Read Back

    A factory reset removes the index and leaves the blocks behind it. Verification reads the medium back afterwards, which is the difference between deleted and unrecoverable.

  • 0 expiryThe Certificate Does Not Lapse

    Keep the record for whatever retention period applies to you. It proves something that happened on a date, and it still verifies years later.

  • SHA-256Signature on Every Certificate

    The report is hashed and signed as it is written, so a certificate altered after the fact no longer verifies.

Questions

Frequently Asked Questions

Is deleting files or formatting a drive enough?

No. Both remove the index that points at the data and leave the data itself on the medium, where ordinary recovery software will find it. Sanitization overwrites or purges the medium and then reads it back to confirm the result.

Does certified erasure satisfy HIPAA?

HIPAA requires PHI to be rendered unusable, unreadable or indecipherable, and points to NIST SP 800-88 for the methods. Clear or Purge under that guidance, verified and documented per device, meets that requirement.

Can you erase clinical devices that will not boot normally?

Yes, provided the drive itself is readable. The software boots independently of whatever is installed on the machine, which is what makes it usable on imaging consoles and analysers running embedded or unsupported systems. If the drive has genuinely failed it is flagged for physical destruction instead.

What about devices leased from a supplier?

Erase before the device goes back and keep the certificate. Once the hardware is with the supplier, that record is the only thing you still hold, and it is the one that answers a later question.

Do you handle destruction as well?

Yes. Where a drive cannot be erased, or your policy requires destruction regardless, we shred on your site and issue a certificate of destruction per asset.

Tell us what you need

Protect Patient Data with DSP Pro

Securely wipe, permanently erase, verify the result and keep the proof — across the whole device lifecycle. Tell us what you retire and we will tell you what it takes.

Explore DSP Pro

Goes straight to our engineers. No newsletter, no call centre.