Electronic media destruction under 42 CFR 2.16 must include sanitizing the media on which electronic Part 2 records are stored so patient-identifying information becomes nonretrievable. Deleting a file or account may leave copies in recycle bins, snapshots, backups, replicas, caches, devices, logs, exports, or vendor systems. The policy should cover retention, holds, method, verification, exceptions, and residual copies.
Editorial approval scope: The team checked current source fidelity, scope boundaries, dates, arithmetic, reader usefulness, practical workflow, and general-information limitations.
Current rule checkpoint
Live 42 CFR 2.16(a)(1)(ii)(B) requires formal policies and procedures for destroying electronic records, including sanitizing the media on which they are stored, so patient-identifying information is non-retrievable. NIST SP 800-88 Rev. 2 supplies current federal media-sanitization guidance, while the HHS fact sheet identifies February 16, 2026 as the Part 2 compliance date.
Inventory copies before destruction
The current electronic-destruction provision focuses on the nonretrievable outcome. Map production, staging, test, backup, archive, disaster recovery, laptops, phones, removable media, printers, scanners, messaging, email, cloud storage, vendors, and logs.
Method depends on media and control
Logical deletion, cryptographic erasure, secure overwrite, factory reset, physical destruction, account closure, tenant deletion, and key destruction have different preconditions and verification. Use qualified security guidance and vendor evidence for the actual technology.
Retention and recovery need coordination
Verify schedule, legal hold, complaint, audit, clinical continuity, backup cycle, restoration testing, immutable copies, patient rights, contract, return, deletion window, and exception approval. Record residual copies and their expiry.
Inventory every copy before authorizing destruction
Map primary systems, databases, files, virtual machines, cloud objects, replicas, snapshots, caches, queues, logs, indexes, archives, backups, laptops, phones, tablets, servers, network devices, removable media, imaging systems, printers, scanners, medical devices, vendor copies, exported files, and test data. Record owner, identifier, data, location, dependency, retention, hold, method, and disposition.
Confirm the authoritative copy and any legal, clinical, payer, research, contract, investigation, complaint, audit, or litigation-hold requirement. Destruction should not proceed merely because a user deleted a file or a device reached end of life.
Choose a sanitization method for the media and risk
Select and validate clear, purge, cryptographic erase, physical destruction, or another appropriate technique using current guidance, device capability, sensitivity, reuse, destination, and organizational policy. Account for solid-state storage, wear leveling, inaccessible areas, failed drives, virtual media, cloud abstraction, and encryption-key management.
Deleting a pointer, emptying a recycle bin, formatting a drive, removing an account, resetting an application, or ending a contract may leave recoverable copies. Confirm the method reaches the actual storage and associated replicas.
Control devices, cloud services, and vendors
Track media from removal through secure staging, transport, sanitization, reuse, return, recycling, or destruction. Use tamper controls, custody records, authorized personnel, verified facilities, subcontractor restrictions, incident notice, and evidence proportionate to risk.
For cloud and software services, define deletion scope, replication, backup aging, account closure, key destruction, logs, legal holds, export return, subcontractors, and provider attestation. Verify contractual promises against available technical and audit evidence.
Verify completion and preserve proof
Record asset or media identifier, data classification, owner, authorization, retention and hold check, method, tool and version, operator, date, result, verifier, destination, exception, vendor, and certificate. Use a second review or sampling for high-risk and bulk events.
When sanitization fails, a device is missing, a vendor cannot prove destruction, or a cloud copy persists, stop disposition, contain access, preserve evidence, notify privacy and security, assess exposure and breach duties, select another method, and verify remediation.
Separate reuse, return, and final disposal
Media reused inside the organization, reassigned to another role, returned to a lessor, repaired by a vendor, donated, resold, recycled, or physically destroyed presents different custody and verification needs. Name the intended destination before choosing the method. Prevent release until sanitization evidence and asset records agree.
For failed or inaccessible media, do not assume failure makes data unrecoverable. Use a method and controlled facility appropriate to the media and risk. Track replacement parts and removed storage during repair.
Reviewers can ask which physical or virtual media held the data, which replicas and backups exist, which method reached each copy, which tool or provider verified the result, where the asset went, and how exceptions were closed. A certificate with no matched asset is incomplete evidence.
Example
Fourteen deletion events are reviewed. Eleven have inventory, authority, hold check, method, primary and backup treatment, vendor confirmation, test, and closure; three stop at account deactivation. Readiness is 11 of 14 events.
Electronic-destruction checklist
- inventory systems, replicas, logs, caches, backups, devices, media, vendors, and exports;
- verify authoritative copy, retention, dependency, investigation, and every hold;
- select a method appropriate to media, risk, reuse, destination, and current guidance;
- control staging, custody, transport, cloud deletion, vendors, and subcontractors;
- record identifiers, method, tool, operator, result, verification, and certificate; and
- contain failed or unproven destruction and confirm corrective action.
Non-retrievable is an end-state requirement. Interface deletion or account closure alone does not prove that result.
Related terms
Sources
- Electronic Code of Federal Regulations, 42 CFR 2.16, Security for Records and Notification of Breaches
- U.S. Department of Health and Human Services, 42 CFR Part 2 Final Rule Fact Sheet
- National Institute of Standards and Technology, SP 800-88 Rev. 2, Guidelines for Media Sanitization
- Federal Register, Confidentiality of Substance Use Disorder Patient Records, 2024 Final Rule
Take the next step with clarity
Whether you are finding care, growing as a clinician, or building a stronger ABA practice, Finni brings the people, tools, and support together to help you move forward.
Start or grow your ABA practice with Finni