The Part 2 source-media sanitization deadline is one year for electronic media that held patient records or identifying information before transfer to the approved retained-record archive. The period runs from program discontinuation or acquisition. The scope includes email and other electronic communications. The deadline needs a locked trigger date, complete media inventory, owner, method, verification, and exception handling.
Editorial approval scope: The team checked current source fidelity, scope boundaries, dates, arithmetic, reader usefulness, practical workflow, and general-information limitations.
Current rule checkpoint
Live 42 CFR 2.19(b)(2)(ii) requires all electronic media on which retained patient records or patient-identifying information resided before the prescribed archive transfer to be sanitized within one year of program discontinuation or acquisition. The text expressly includes email and other electronic communications and requires consistency with section 2.16. NIST SP 800-88 Rev. 2 is technical guidance rather than Part 2 authority.
Start the clock from the legal event
Under 42 CFR 2.19(b)(2)(ii), the deadline runs within one year of discontinuation or acquisition. Counsel should document the operative event and date, entity scope, affected systems, any staged shutdown, and how mergers or successor operations affect the analysis.
Inventory every prior residence
Include production systems, databases, file shares, email, messaging, interfaces, cloud tenants, laptops, phones, removable media, printers, scanners, local exports, backups, logs, disaster-recovery copies, vendors, and test environments that held the information before transfer.
Use a controlled sanitization program
NIST SP 800-88 Rev. 2 describes program-level media sanitization based on information sensitivity and technology. Apply qualified technical judgment, vendor evidence, chain of custody, validation, failed-media handling, residual-copy tracking, and completion records.
Establish the legal event and deadline
Document the entity, program, discontinuation, takeover, or acquisition event, operative date, qualified legal conclusion, affected systems, and one-year due date. Address staged closures, continuing affiliates, delayed migrations, and multiple legal entities explicitly rather than choosing a convenient project date.
Set milestones for discovery, owner assignment, dependency analysis, method approval, vendor scheduling, execution, verification, exception resolution, and final certification. Escalate missed milestones well before the outer deadline.
Inventory every location that held the information before transfer
Include clinical and billing systems, databases, file shares, document stores, portals, messages, email, archives, journals, interfaces, cloud tenants, virtual machines, logs, caches, queues, search indexes, laptops, phones, tablets, servers, network devices, printers, scanners, removable media, backups, disaster recovery, vendor systems, subcontractors, local exports, and test environments.
For each, record asset or service, owner, location, data, time range, copies, dependency, retention or hold, access, vendor, method, scheduled date, result, and verifier. Distinguish the prescribed retained archive media from the prior source media that must be sanitized within the year.
Resolve dependencies without preserving unnecessary copies
Confirm that the retained archive is complete, readable, encrypted, reconciled, and accessible to the responsible person before sanitizing source media. Identify software, schema, lookup table, reader, key, export, audit, and patient-access dependencies. Move only what is necessary for the lawful archive.
Legal holds, regulatory duties, or another supported retention requirement may affect a source. Document scope and authority and use a controlled exception plan rather than silently skipping the asset. Reevaluate as soon as the hold or dependency ends.
Execute sanitization by technology and service
Choose methods under section 2.16 procedures using qualified technical judgment and current guidance. Address live media, snapshots, replicas, backups, deleted objects, encryption keys, failed devices, wear-leveling media, virtual storage, cloud retention, vendor copies, and immutable systems. Decommission applications, accounts, and integrations without losing evidence of completion.
For email and communications, inventory mailboxes, shared boxes, archives, journals, legal holds, exports, mobile sync, collaboration tools, attachments, and backups. Avoid deleting unrelated records outside the approved scope.
Verify, reconcile, and close
Preserve authorization, asset identifier, chain of custody, method, tool or provider, date, operator, result, exception, retry, vendor attestation, independent verification, and certificate. Reconcile every asset and service to the inventory and investigate unknown, missing, failed, or unproven items.
Use an executive and privacy closeout that confirms archive readability, one-year trigger, scope, exceptions, residual copies, vendor completion, and corrective action. Continue tracking supported exceptions to their own end date.
Example
Twenty source-media groups enter the one-year plan. Sixteen have owner, location, data scope, method, dependency, due date, validation, and closure evidence; four legacy email archives remain unassigned. Readiness is 16 of 20 groups.
One-year sanitization checklist
- document the legal event, operative date, one-year deadline, milestones, and owners;
- inventory every prior system, communication, device, media, backup, vendor, and export;
- verify the prescribed retained archive before sanitizing its sources;
- resolve holds and dependencies with documented, time-limited exceptions;
- apply technology-specific methods under section 2.16 and current guidance; and
- reconcile results, failures, vendors, residual copies, certificates, and closeout.
The one-year deadline applies to prior electronic media, including email and communications. A completed archive transfer does not prove that those source copies were sanitized.
Related terms
Sources
Take the next step with clarity
Whether you are finding care, growing as a clinician, or building a stronger ABA practice, Finni brings the people, tools, and support together to help you move forward.
Start or grow your ABA practice with Finni