Service-disabled veteran-owned. Mobile on-site destruction anywhere in the lower 48.330-704-1641    contact@mansfieldtech.us

Hard drive shredding and ITAD for hospitals, clinics, and practices

Protected health information lives on far more than servers: imaging workstations, PACS storage, clinic PCs, dictation devices, and the copier in the records office. We destroy all of it at your dock, under a Business Associate Agreement, with a certificate your HIPAA officer can file.

What the rules require

  • HIPAA Security Rule
    Device and media controls require covered entities and business associates to address the final disposition of ePHI and the hardware it lives on, and to make it unrecoverable before disposal or reuse.
  • HHS breach notification
    A retired drive that surfaces with PHI on it is a reportable breach with a sixty-day notification clock. Witnessed destruction with a serial-level certificate is the evidence that the clock never started.
  • NIST SP 800-88 Rev. 2
    The sanitization standard HHS points to. Destroy is the method that removes the question of whether a wipe reached every sector of an imaging array.

How we handle it

We sign a BAA before the first device is touched. The truck parks at your loading dock, your compliance or IT staff witness every drive go in, and PHI never leaves the building intact.

Imaging systems, ultrasound carts, and lab analyzers hold storage nobody remembers is there. We open them, find it, destroy it, and log the chassis as inspected. Copiers and multifunction printers with hard drives get the same treatment.

We schedule around clinical hours, stage a large refresh over consecutive days so no department loses a workstation before its replacement arrives, and the certificate lists every serial number against your asset tags.

“If they can fit you into their schedule, take it! They quickly destroyed thousands of our old hard drives for us and provided documentation, so we could adhere to our local laws. We’ll be using again soon!”

Documents your vendor-management process will ask for

  • A Business Associate Agreement, signed before any work. Ours is short; download it from the due diligence kit, or send us yours.
  • A certificate of insurance naming your organization, with cyber and privacy liability included, available before the job.
  • A sample Certificate of Destruction and media log, so your privacy officer can see the record before the first drive is destroyed.

Where we do it

Cleveland, Columbus, Cincinnati, Akron, Toledo, Pittsburgh, Detroit, Ann Arbor, and everywhere else we go.

Read next

Questions from healthcare

  • Do you sign a Business Associate Agreement?

    Yes, before any work begins. Ours is short and we will sign yours if you prefer.

  • Can you destroy media from imaging and lab equipment?

    Yes. Modalities, PACS storage, ultrasound carts, and analyzers hold drives and flash that we remove and destroy on-site, with the equipment recorded as inspected on the certificate.

  • How fast can you respond to a breach-risk situation?

    In our next-day metros, usually the next business day. If a device has gone missing and you need the rest of the fleet secured quickly, tell us and we will route the truck.

  • Is the certificate enough for an OCR audit?

    It is written to NIST 800-88 Rev. 2's documentation requirement, lists every serial number, names the method and machine, and carries a three-year audit right. Keep it with your risk analysis and your BAA.

  • Are you NAID AAA certified?

    No. NAID AAA was built around paper shredding and the security of off-site destruction facilities, which is not how we work: we destroy electronic media on your site, in front of you, on NSA-listed equipment, with a serial-level certificate. If your vendor policy lists NAID AAA as a requirement, ask your privacy officer whether witnessed on-site destruction to NIST 800-88 with a BAA satisfies its intent; it usually does, and we will answer any questionnaire that follows.

Tell us what you have.

Request a custom quote