What You Need to Know about HIPAA

Posted on

Nov 27th, 2017

Category

Blog

Share on

Disposing of protected health information (PHI) isn’t as simple as tossing your hard drive in the trash and calling it a day. There are many safeguards you need to have in place to make sure your customer’s sensitive data doesn’t end up in the wrong hands. These range from training your staff on best practices to using proper disposal methods to make PHI unreadable.

The industry standard for managing IT recycling, data destruction, hard drive shredding, or computer recycling of PHI is known as the HIPAA Privacy and Security Rules. This article covers all the different safeguards and standards you’ll need to have in place to remain HIPAA compliant.

Here’s what you need to know about HIPAA

  • Organizational Standards:  Creating organizational standards is a critical first step when getting rid of public health information on your hard drive or IT infrastructure. Organizational standards are especially important if you regularly exchange public health information with other business associates or organizations.These standards should comply with all the latest rules and standards set by HIPAA and should explain each associate’s responsibilities and areas of accountability when handling public health information or managing IT recycling of PHI.
  • Policies and Procedures: Creating internal policies and rules in your organization is the best way to ensure you remain compliant with the latest HIPAA Privacy and Security Rules when shredding a hard drive or recycling a computer containing PHI.Your company must maintain written records of its security policies and procedures for at least six years after their date of creation and regularly update them based on any changes that may affect the security of PHI.
  • Administrative Safeguards: HIPAA also requires that you create administrative safeguards to prevent and detect security threats that may compromise PHI during data destruction. These safeguards should outline how your workers will handle sensitive client information and deal with any risks associated with handling PHI.Creating administrative safeguards usually starts with a comprehensive risk analysis of PHI, followed by an implementation phase. During the risk analysis stage, your goal should be to identify all vulnerabilities that may affect public health information stored on your electronic devices. You’ll then need to create and implement a detailed plan for managing data destruction, hardware and software storage, and PHI removal.
  • Physical Safeguards: Physical safeguards are policies and procedures designed to protect PHI systems, buildings and equipment from external hazards such as natural disasters and unauthorized intrusion. HIPAA requires that you implement physical safeguards within your company, and perform a complete risk analysis to evaluate all possible locations that PHI may be accessed.You may discover that PHI can be accessed in different areas of your office, or an employee’s house. In any case, you’ll need to develop a detailed facility security plan that outlines what entities have access to PHI and what steps they need to take to protect PHI in case of emergencies.

Get Rid of Public Health Information the Right Way

Getting rid of PHI doesn’t need to be complicated. If you would like to learn more about how to properly dispose of PHI, please contact us at any time. We would be happy to discuss ways to keep your data safe, both while you’re using public health information, and after you’re done with it.

  • Christopher Madeira

    Christopher Madeira

    Director of Marketing

    ITAD Communications & Strategy Expert

    Snapshot / Quick Stats

    • 15+ years of experience in marketing strategy, brand development, and communications
    • Specialized in IT asset disposition (ITAD) messaging for compliance-driven industries
    • Former leadership roles at The Chronicle of Higher Education, CQ Press, and other respected publishers
    • Key focus areas: Market Trends, Client Education, ITAD Compliance Messaging, Thought Leadership, SEO-Driven Strategy

    Areas of Specialization

    • Market Trends & Competitive Analysis – Tracks shifts in ITAD, resale, and sustainability markets to shape strategy and keep Securis ahead of industry developments.
    • ITAD Compliance & Security Messaging – Crafts clear narratives that translate regulatory and data security requirements into approachable guidance for IT leaders.
    • Client & Stakeholder Education – Builds educational resources and thought leadership content that empower clients to make informed ITAD decisions with confidence.

    Professional Narrative (Career Journey)

    Christopher Madeira is the Director of Marketing at Securis, where he shapes how the company communicates its mission of Secure, Accurate, and Sustainable IT Asset Disposition to regulated industries, government agencies, and enterprise clients. With more than 25 years of experience in marketing and communications, Christopher brings a unique perspective on how to bridge technical ITAD processes with clear, client-centered storytelling.

    Before joining Securis, Christopher served in senior marketing roles across publishing and education organizations, including The Chronicle of Higher Education, CQ Press, and Congressional Quarterly. These positions gave him deep expertise in shaping brand positioning, leading cross-functional teams, and delivering content that informs and engages decision-makers.

    At Securis, Christopher drives marketing strategies that not only build awareness but also educate IT leaders on data security, compliance, and sustainability best practices. His work ensures that Securis remains a trusted voice in the ITAD industry, aligning brand authority with the company’s core differentiators: Secure, Accurate, and Sustainable services.

    Quote

    “Clear communication makes complex ITAD issues approachable for IT leaders.”

    Thought Leadership & Recognition

    Christopher is the author of numerous Securis blog articles on compliance, sustainability, and ITAD strategy. He has also developed content campaigns that help IT decision-makers understand the evolving landscape of secure data destruction, ESG reporting, and value recovery.

    Personal 

    A strategist at heart, Christopher is passionate about helping organizations cut through the noise and understand the real risks — and opportunities — in ITAD. Outside of his professional work, he enjoys exploring D.C.’s history, traveling,  connecting with his community, and aviation photography. 

    Trust & Transparency

    Christopher ensures that every piece of Securis’ external communication is not only accurate but also aligned with the certifications and compliance standards that define the company’s reputation. His commitment to transparency reinforces Securis’ standing as a trusted partner for IT asset disposition.