Industries · Healthcare
The device is retired. The record is not.
Health systems retire equipment that touched patient data — often equipment nobody classified as data-bearing. We produce the serialized evidence your privacy office and your auditors actually ask for.
What we hear
The problem is rarely the wipe. It is knowing what you had.
By the time a health system retires a fleet, the asset register and reality have usually drifted apart. Devices were moved between departments, replaced out of cycle, or absorbed through an acquisition that never fully reconciled. The retirement inventory is a best guess.
An untracked data-bearing device is not an inventory discrepancy — it is a potential reportable breach. Which is why the work that matters happens at intake: reconciling what physically arrives against what you believed you were sending, and surfacing the gap while it is still a logistics question rather than a disclosure question.
Where it goes wrong
Four failure modes we see repeatedly
PHI-bearing devices you did not classify as such
Imaging workstations, infusion pumps, nurse-station tablets, printers with retained spool data. The obvious endpoints get managed; the embedded media is what surfaces later.
Distributed sites with no local IT
Clinics, outpatient centres and satellite offices where equipment accumulates in a closet until someone decides to clear it — usually without a manifest.
Refresh cycles that outpace documentation
Devices are replaced faster than the asset register is updated, so the retirement inventory never matches the deployment inventory.
Evidence that arrives too late
Batch certificates and summary reports that cannot answer a question about one specific serial number during an audit or an investigation.
Client outcome
A Fortune 10 healthcare organization, 200,000 employees
Device management had begun consuming departmental staff time and exceeding the budget allocated to it. We took responsibility for the lifecycle: procurement with guaranteed buyback, asset tagging and MDM enrollment, kitting with rugged cases and hygienic keyboards, pooled connectivity, refresh of returned devices, and end-of-life disposition with verified sanitization across more than 5,000 assets.
Client identity withheld under confidentiality obligations.
FAQ
What healthcare privacy and security teams ask
Does using your service make us HIPAA compliant?
Are you a business associate?
How do you handle devices we did not know contained PHI?
What about devices under legal hold or litigation?
Can our privacy officer audit your facility?
We have equipment across dozens of sites. How does collection work?
Planning a clinical refresh or a site closure?
Tell us the scope and we will scope the disposition around it — including the sites where nobody is quite sure what is in the closet.