Skip to content

Industries · Healthcare

The device is retired. The record is not.

Health systems retire equipment that touched patient data — often equipment nobody classified as data-bearing. We produce the serialized evidence your privacy office and your auditors actually ask for.

What we hear

The problem is rarely the wipe. It is knowing what you had.

By the time a health system retires a fleet, the asset register and reality have usually drifted apart. Devices were moved between departments, replaced out of cycle, or absorbed through an acquisition that never fully reconciled. The retirement inventory is a best guess.

An untracked data-bearing device is not an inventory discrepancy — it is a potential reportable breach. Which is why the work that matters happens at intake: reconciling what physically arrives against what you believed you were sending, and surfacing the gap while it is still a logistics question rather than a disclosure question.

Where it goes wrong

Four failure modes we see repeatedly

PHI-bearing devices you did not classify as such

Imaging workstations, infusion pumps, nurse-station tablets, printers with retained spool data. The obvious endpoints get managed; the embedded media is what surfaces later.

Distributed sites with no local IT

Clinics, outpatient centres and satellite offices where equipment accumulates in a closet until someone decides to clear it — usually without a manifest.

Refresh cycles that outpace documentation

Devices are replaced faster than the asset register is updated, so the retirement inventory never matches the deployment inventory.

Evidence that arrives too late

Batch certificates and summary reports that cannot answer a question about one specific serial number during an audit or an investigation.

Client outcome

A Fortune 10 healthcare organization, 200,000 employees

Device management had begun consuming departmental staff time and exceeding the budget allocated to it. We took responsibility for the lifecycle: procurement with guaranteed buyback, asset tagging and MDM enrollment, kitting with rugged cases and hygienic keyboards, pooled connectivity, refresh of returned devices, and end-of-life disposition with verified sanitization across more than 5,000 assets.

24%
reduction in total cost of ownership
14 → 3
days to deploy, 99.8% first-attempt accuracy
100%
verified secure wiping of decommissioned devices
$380k+
value recaptured through remarketing

Client identity withheld under confidentiality obligations.

FAQ

What healthcare privacy and security teams ask

Does using your service make us HIPAA compliant?
No, and you should be sceptical of any vendor who claims otherwise. HIPAA obligations rest with the covered entity. What a disposition provider supplies is documented, serialized evidence of proper media disposal — the material your privacy officer and your auditors use to demonstrate that your own obligations were met. We do not certify your compliance. We produce the records that let you evidence it.
Are you a business associate?
That depends on the engagement and is a determination your counsel should make. Where devices containing PHI are transferred to us before sanitization, a Business Associate Agreement is the normal arrangement. Raise it during scoping and we will work to your legal team's requirements.
How do you handle devices we did not know contained PHI?
Every device is treated as potentially data-bearing until classified otherwise at intake. Media is identified and segregated during triage rather than assumed from the asset type, which is what catches the imaging workstation and the printer with a retained spool.
What about devices under legal hold or litigation?
They are segregated on arrival into restricted-access storage and cannot be wiped or transferred until we receive and log a written release from your authorized representative. Hold status is checked at intake, before any handling decision is made.
Can our privacy officer audit your facility?
Yes. Compliance officers and designated third-party auditors can schedule facility walkthroughs and records reviews on 48 hours' notice. The audit package includes lot-level processing reports, erasure certificate samples, security access logs and staffing and training records.
We have equipment across dozens of sites. How does collection work?
Collection and consolidation across distributed sites is a normal part of the engagement. We handle multi-carrier logistics with tracked shipments and reconcile every site's inbound against the manifest it declared, so a discrepancy at one clinic is visible rather than absorbed into a total.

Planning a clinical refresh or a site closure?

Tell us the scope and we will scope the disposition around it — including the sites where nobody is quite sure what is in the closet.