164.310(d)(2)(i) Disposal (Required)
164.310(d)(2)(i) in HIPAA Security Rule (the HIPAA Security Rule as it currently stands). All HIPAA Security Rule controls held. Open HIPAA Security Rule on the standards site.
The control as we hold it
Disposal (Required). Implement policies to address the final disposition of ePHI and the hardware or media on which it is stored. NIST recommends sanitization per SP 800-88 with certificates of destruction.
Reviewed and closest counterparts in the other frameworks
Reviewed rows come from a released pair; a closest match is the nearest held text and is not a reviewed row.
SOC 2
- SOC2-C1.2 C1.2 Disposing of confidential information (closest match)
- SOC2-CC6.5 CC6.5 Protecting data on assets until disposal (closest match)
- SOC2-P4.3 P4.3 Securely disposing of personal information (closest match)
NIST SP 800-53 Rev 5
- NIST800-MP-6 MP-6 Media Sanitization (closest match)
- NIST800-SI-18 SI-18 Personally Identifiable Information Quality Operations (closest match)
What an auditor commonly asks for
General guidance for this control area (domain: Physical), in our words, not a statement of the standard and not binding on an assessor.
- the facility access and visitor records
- the workstation-use and device-control records
- the media-disposal and re-use records