on site destruction is not required in the HIPAA rules, but the generator(hospital) cannot delegate responsibility for the loss of control of patient data. SO even if a full R2 certified facility takes the material and signs away their life, if the data is lost and resurfaces, the Generator(hospital) is still responsible, though the Hospital has legal recourse...
But any lawyer worth a SH12 will tell the hospital to have the data destroyed before it gets into other hands. No one trusts degaussing anymore since there are so many (real crime dramas) showing that stuff getting put back together. So an on site shredder is what you are going to have to compete with if you want into this line of work, and most Lawyers if asked will want the entire hard drive destroyed board and all, and no one from the hospital IT department will waste their time arguing about getting to sell the hardrive boards.
Beware and tell your customers to beware of the people claiming to be R2 compliant. this is a common scam to avoid getting certified and still being treated like you are.
V/r HT1
Bookmarks