🏥 Healthcare🔒 Patient Data Destruction

How Do Hospitals Dispose of IT Holding Patient Data?

Healthcare is the most breached sector in Australia, and almost every device a health provider retires held patient data. A clinical workstation, an imaging PC, a server, even the photocopier at the nurses' station can carry sensitive health information long after it is switched off. This guide explains how hospitals, clinics and aged-care providers destroy that data securely, and prove they did.

Certified to ISO 27001:2022 Certificate for Every Device

The Quick Answer

How do hospitals dispose of IT holding patient data?

Through a certified IT disposal process that destroys the data on every retired device to a recognised standard, tracks each asset under a documented chain of custody, and issues a certificate of destruction for each one. Patient information is among the most sensitive personal data there is, and it is protected under the Privacy Act 1988 and, where My Health Record data is involved, the My Health Records Act. A factory reset or a deleted file is not enough, because that data remains recoverable. So a health provider retires IT the same way it handles the data itself: securely, to a standard, and with a record to prove it. That is what healthcare IT disposal is built to deliver.

The reason this matters more in health than almost anywhere else is the combination of volume and sensitivity. Hospitals and clinics run large fleets of devices, refresh them constantly, and every one of them touches patient information at some point. When those devices are retired, the data does not leave with the clinician who used them; it stays on the storage until it is destroyed. This guide covers what health providers actually retire, why patient data carries extra obligations, the devices that are most often overlooked, and what compliant destruction looks like in practice.

What a Health Provider Actually Retires

Health IT is broader than office IT, and more of it holds patient data than people expect.

EquipmentWhy it holds patient data
Clinical workstations & laptopsAccess electronic medical records, results and correspondence; local caches and files remain until wiped
Servers, storage & EMR hardwareThe highest-risk items; hold the central store of patient records, destroyed and certified drive by drive
Imaging & diagnostic PCsRadiology, pathology and PACS workstations retain images and reports tied to named patients
Photocopiers & multifunction devicesTheir internal hard drives store an image of everything scanned, printed or faxed, including referrals and records
Tablets, phones & mobile cartsUsed at the bedside for records and medication; check for account locks before collection
Networking & access controlSwitches and access systems can retain configuration and staff or visitor data

Where patient data concentrates in a health fleet

Every device class holds recoverable patient information. The highest bars carry the most sensitive records and the greatest risk at disposal.

CriticalServers & EMR Very highImaging PCs HighClinical PCs HighPhotocopiers MediumTablets VariesNetworking

Illustrative: relative concentration of recoverable patient data by device class. Servers, imaging and clinical PCs, and photocopiers carry the highest risk.

The point of listing these is that a health provider's data risk is not confined to the obvious computers. The photocopier that leaves on a lease return, the imaging PC swapped out during an upgrade, the tablets retired from a ward, all of them can carry patient data, and all of them need the same certified treatment. A disposal that wipes the laptops but forgets the copier has not solved the problem. This is a data-bearing IT question, and the scope has to cover every device that ever touched a record. Note that this is about destroying the data on IT equipment, not recycling medical devices themselves; the focus is the information, wherever it is stored.

Why Patient Data Carries Extra Obligations

Health information is not ordinary personal data. Australian law treats it as more sensitive, and the duty to protect it runs all the way to disposal.

Under the Privacy Act 1988, health information is classified as sensitive information and attracts a higher level of protection than ordinary personal information. The Australian Privacy Principles require that personal information be destroyed or de-identified once it is no longer needed, and that reasonable steps be taken to protect it from unauthorised access, which at disposal means destroying it beyond recovery. Where My Health Record information is involved, the My Health Records Act adds its own obligations and penalties. For public health services there are also state records and health-records requirements layered on top. The common thread is that a health provider is accountable for patient data across its whole life, and disposal is the final and most overlooked stage of that life.

The practical consequence is that a certificate for every device does real work in a health setting. If a patient, an auditor, or a regulator ever asks how a person's records were handled when a device was retired, the answer needs to be a document, not a recollection. Certified destruction to a recognised standard such as NIST 800-88, carried out under a process certified to ISO 27001:2022, produces that evidence as a matter of routine. You can read how health information is protected on the OAIC website.

A note on retention

Health records must be kept for set periods under state and professional rules, often many years, and for children's records longer still. So the sequence matters: confirm the records are retained in your current systems for as long as the rules require, then destroy the old hardware with confidence. The disposal handles the device and its residual data; your records policy governs what information must be kept elsewhere. Certified destruction and records retention are partners, not opposites.

Where Health Disposals Most Often Go Wrong

Most failures are not dramatic. They are ordinary process gaps that only surface when a device, or its data, turns up where it should not.

1

Forgetting the non-obvious devices

The laptops get wiped, but the photocopier, the imaging PC or the old ward tablet is overlooked, and it leaves with patient data intact. The scope has to be every data-bearing device, not just the computers.

2

Relying on a reset or a delete

A factory reset feels like enough, but the data stays recoverable and there is no certificate to prove anything was done. For patient information, that is a gap, not a solution.

3

Informal disposal

A device gifted to a staff member, sold second-hand, or dropped at a general recycler leaves the provider unable to show where the data went. Without a chain of custody, it is simply unaccounted for.

4

Storing retired gear indefinitely

Equipment stacked in a store room or spare office while a decision is made is unlogged patient data sitting in a pile, at growing risk of being lost or forgotten during the next move.

5

No documentation to show for it

Even a well-intentioned disposal that leaves no certificate cannot be evidenced. If a patient, auditor or regulator asks, the answer needs to be a record, not a recollection.

Why Health Providers Are the Biggest Target

Healthcare consistently tops the national breach statistics, and patient data is exactly what attackers and opportunists want. Figures from named sources.

18%
Health was the highest-reporting sector for notifiable data breaches, the largest single share of any industry
Source: OAIC, Jan to Jun 2025
532
Notifiable data breaches reported to the OAIC in the first half of 2025, with breaches remaining at a high level
Source: OAIC, Jan to Jun 2025
$50M+
Maximum penalty for a serious or repeated privacy breach under the Privacy Act 1988
Source: OAIC

The Office of the Australian Information Commissioner reported that health was the highest-reporting sector for notifiable data breaches in the first half of 2025, at 18% of all breaches, more than any other industry. A retired device that leaves a health provider without its data destroyed is a direct contributor to that risk: it holds exactly the sensitive information the statistics are about, and it is easy to lose track of during an upgrade or a ward closure. Against a maximum privacy penalty of $50M or more, and the trust of the patients whose records are at stake, the cost of certified destruction is negligible. The current breach statistics are published on the OAIC website.

Compliant vs Risky Disposal, Side by Side

The difference is not the effort of collecting the equipment. It is whether patient data is provably destroyed, or quietly at large.

Compliant health disposal

  • Every data-bearing device in scope, copiers and imaging PCs included
  • Data destroyed to a recognised standard, wiped or physically destroyed
  • Documented chain of custody from collection to destruction
  • A certificate for every device, reconcilable to the asset register
  • Process certified to ISO 27001:2022

Risky informal disposal

  • Only the obvious computers wiped; copier and tablets forgotten
  • A factory reset that leaves data recoverable
  • Devices gifted, sold or dropped at a general recycler, untracked
  • No certificate, so nothing can be proven if questioned
  • Retired gear stored indefinitely, still holding records

Read the two columns together and the theme is evidence. A compliant disposal is not just one where the data happens to be destroyed; it is one where the provider can demonstrate, for any specific device, that it was destroyed to standard and accounted for from start to finish. In a sector where health information is treated as sensitive under the Privacy Act and breaches are reported more often than in any other industry, that ability to demonstrate is much of the point. It turns a patient-trust question and a regulatory question into a matter of retrieving records rather than reconstructing what probably happened to a device that left the building months ago.

What Compliant Disposal Looks Like in Health

Four things turn a health provider's disposal into one that protects patients and stands up to scrutiny.

1

Every data-bearing device in scope

Not just computers: imaging PCs, servers, tablets and the photocopiers and multifunction devices whose internal drives store scanned records. The scope covers anything that ever touched patient data.

2

Destruction to a recognised standard

Certified wiping to NIST 800-88 for reusable equipment, and physical shredding for drives that cannot be verifiably wiped, with solid-state media handled by a method matched to flash. See data destruction services.

3

Documented chain of custody

Every asset logged at collection and tracked to destruction, so there is never a window in which a device holding patient data is unaccounted for.

4

A certificate for every device

Item-level proof recording what was destroyed and how, reconcilable to your asset register, so you can show exactly how any specific device was handled.

Timing around clinical operations

Health services run around the clock, so collections are scheduled to fit clinical operations, ward closures, refurbishments or system upgrades, rather than disrupt care. Equipment can be securely held and collected in a coordinated sweep, so retired devices do not pile up in a corridor holding patient data while they wait. Talk to our team about scheduling around your environment.

It Is Not Just Hospitals: Clinics, Aged Care and Practices

The obligation scales down as well as up. A GP practice or an aged-care home holds the same sensitive data, with fewer resources to manage it.

Large hospitals have IT teams and formal processes; smaller providers often do not, yet they hold the same category of sensitive health information and carry the same obligations to destroy it securely at end of life. A general practice retiring a few workstations, an aged-care provider replacing tablets across a facility, a specialist clinic upgrading its imaging PC, all of them are handling patient data that must be destroyed to standard and documented. For these providers the risk is often higher precisely because disposal is informal: a device gets gifted to a staff member, sold second-hand, or left in a store room, still holding records. A certified collection removes that risk, brings the same standard a hospital would use to a smaller provider, and produces the certificate that proves it was done.

Because reusable equipment can be securely wiped and its value recovered, a refresh at a clinic or aged-care facility need not be a pure cost either. Working devices routed through buyback, once the data is destroyed and certified, can offset the cost of the new equipment, while everything else is recycled responsibly. The data is protected and the budget stretches further, which matters most for exactly the smaller providers who feel disposal as an overhead.

Hospital & Healthcare IT Disposal: FAQ

The questions health providers ask most about retiring IT that held patient data.

No. A factory reset or deleting files leaves the underlying data recoverable with freely available tools. To protect patient information, the storage must be securely wiped to a recognised standard such as NIST 800-88, or physically destroyed, with a certificate confirming it was done. That is the step that meets a health provider's obligations and provides evidence if it is ever questioned.

Usually yes. Most office photocopiers and multifunction devices contain an internal hard drive that stores an image of documents scanned, printed or faxed, which in a health setting includes referrals, results and records. When a copier is returned at lease end or retired, that drive should be wiped or destroyed and certified, exactly like any other data-bearing device. It is one of the most commonly overlooked risks in health disposal.

The Privacy Act 1988 classifies health information as sensitive information and requires it to be destroyed or de-identified once no longer needed, with reasonable steps taken to protect it. Where My Health Record data is involved, the My Health Records Act adds further obligations. Public health services also face state records and health-records requirements. Across all of them, secure, documented destruction at disposal is the expectation.

Health records must be retained for set periods, so archive the information you are required to keep to your current systems before the old hardware is destroyed. The disposal handles the device and its residual data; your records-retention policy governs what must be kept elsewhere. Confirm the archive is complete, then destroy the old equipment with confidence.

Yes. A GP practice, specialist clinic or aged-care home holds the same category of sensitive health information as a hospital and carries the same obligation to destroy it securely. The risk is often higher for smaller providers because disposal is informal. A certified collection brings the hospital standard to a smaller provider and produces the certificate that proves the data was destroyed.

Yes, once the data is destroyed and certified. Working equipment can be securely wiped to standard and refurbished, with its value recovered through buyback to offset the cost of a refresh, while the rest is recycled responsibly. The sequence is essential: the patient data is destroyed and documented first, then the clean hardware carries its value forward.

Retiring IT that held patient data? Contact our team or call 1300 048 226.

Protect Patient Data at End of Life

See how ITC destroys patient data on retired IT for hospitals, clinics and aged-care providers, to a recognised standard, with the chain of custody and per-device certificates that prove it was done.

Evidence for your auditor

Disposal that stands up to a compliance review

Regulators do not ask whether you recycled the hardware. They ask what happened to the data on it, who handled it, and where the record is. ITC holds ISO/IEC 27001:2022 for information security alongside ISO 14001:2015, ISO 9001:2015 and ISO 45001:2018, and issues serialised documentation on every job so the answer is already written down.

Talk to a compliance specialist View certifications

Book Your Free Collection

Request a callback