Healthcare is the most breached sector in Australia, and almost every device a health provider retires held patient data. A clinical workstation, an imaging PC, a server, even the photocopier at the nurses' station can carry sensitive health information long after it is switched off. This guide explains how hospitals, clinics and aged-care providers destroy that data securely, and prove they did.
Through a certified IT disposal process that destroys the data on every retired device to a recognised standard, tracks each asset under a documented chain of custody, and issues a certificate of destruction for each one. Patient information is among the most sensitive personal data there is, and it is protected under the Privacy Act 1988 and, where My Health Record data is involved, the My Health Records Act. A factory reset or a deleted file is not enough, because that data remains recoverable. So a health provider retires IT the same way it handles the data itself: securely, to a standard, and with a record to prove it. That is what healthcare IT disposal is built to deliver.
The reason this matters more in health than almost anywhere else is the combination of volume and sensitivity. Hospitals and clinics run large fleets of devices, refresh them constantly, and every one of them touches patient information at some point. When those devices are retired, the data does not leave with the clinician who used them; it stays on the storage until it is destroyed. This guide covers what health providers actually retire, why patient data carries extra obligations, the devices that are most often overlooked, and what compliant destruction looks like in practice.
Health IT is broader than office IT, and more of it holds patient data than people expect.
| Equipment | Why it holds patient data |
|---|---|
| Clinical workstations & laptops | Access electronic medical records, results and correspondence; local caches and files remain until wiped |
| Servers, storage & EMR hardware | The highest-risk items; hold the central store of patient records, destroyed and certified drive by drive |
| Imaging & diagnostic PCs | Radiology, pathology and PACS workstations retain images and reports tied to named patients |
| Photocopiers & multifunction devices | Their internal hard drives store an image of everything scanned, printed or faxed, including referrals and records |
| Tablets, phones & mobile carts | Used at the bedside for records and medication; check for account locks before collection |
| Networking & access control | Switches and access systems can retain configuration and staff or visitor data |
Every device class holds recoverable patient information. The highest bars carry the most sensitive records and the greatest risk at disposal.
Illustrative: relative concentration of recoverable patient data by device class. Servers, imaging and clinical PCs, and photocopiers carry the highest risk.
The point of listing these is that a health provider's data risk is not confined to the obvious computers. The photocopier that leaves on a lease return, the imaging PC swapped out during an upgrade, the tablets retired from a ward, all of them can carry patient data, and all of them need the same certified treatment. A disposal that wipes the laptops but forgets the copier has not solved the problem. This is a data-bearing IT question, and the scope has to cover every device that ever touched a record. Note that this is about destroying the data on IT equipment, not recycling medical devices themselves; the focus is the information, wherever it is stored.
Health information is not ordinary personal data. Australian law treats it as more sensitive, and the duty to protect it runs all the way to disposal.
Under the Privacy Act 1988, health information is classified as sensitive information and attracts a higher level of protection than ordinary personal information. The Australian Privacy Principles require that personal information be destroyed or de-identified once it is no longer needed, and that reasonable steps be taken to protect it from unauthorised access, which at disposal means destroying it beyond recovery. Where My Health Record information is involved, the My Health Records Act adds its own obligations and penalties. For public health services there are also state records and health-records requirements layered on top. The common thread is that a health provider is accountable for patient data across its whole life, and disposal is the final and most overlooked stage of that life.
The practical consequence is that a certificate for every device does real work in a health setting. If a patient, an auditor, or a regulator ever asks how a person's records were handled when a device was retired, the answer needs to be a document, not a recollection. Certified destruction to a recognised standard such as NIST 800-88, carried out under a process certified to ISO 27001:2022, produces that evidence as a matter of routine. You can read how health information is protected on the OAIC website.
Health records must be kept for set periods under state and professional rules, often many years, and for children's records longer still. So the sequence matters: confirm the records are retained in your current systems for as long as the rules require, then destroy the old hardware with confidence. The disposal handles the device and its residual data; your records policy governs what information must be kept elsewhere. Certified destruction and records retention are partners, not opposites.
Most failures are not dramatic. They are ordinary process gaps that only surface when a device, or its data, turns up where it should not.
The laptops get wiped, but the photocopier, the imaging PC or the old ward tablet is overlooked, and it leaves with patient data intact. The scope has to be every data-bearing device, not just the computers.
A factory reset feels like enough, but the data stays recoverable and there is no certificate to prove anything was done. For patient information, that is a gap, not a solution.
A device gifted to a staff member, sold second-hand, or dropped at a general recycler leaves the provider unable to show where the data went. Without a chain of custody, it is simply unaccounted for.
Equipment stacked in a store room or spare office while a decision is made is unlogged patient data sitting in a pile, at growing risk of being lost or forgotten during the next move.
Even a well-intentioned disposal that leaves no certificate cannot be evidenced. If a patient, auditor or regulator asks, the answer needs to be a record, not a recollection.
Healthcare consistently tops the national breach statistics, and patient data is exactly what attackers and opportunists want. Figures from named sources.
The Office of the Australian Information Commissioner reported that health was the highest-reporting sector for notifiable data breaches in the first half of 2025, at 18% of all breaches, more than any other industry. A retired device that leaves a health provider without its data destroyed is a direct contributor to that risk: it holds exactly the sensitive information the statistics are about, and it is easy to lose track of during an upgrade or a ward closure. Against a maximum privacy penalty of $50M or more, and the trust of the patients whose records are at stake, the cost of certified destruction is negligible. The current breach statistics are published on the OAIC website.
The difference is not the effort of collecting the equipment. It is whether patient data is provably destroyed, or quietly at large.
Read the two columns together and the theme is evidence. A compliant disposal is not just one where the data happens to be destroyed; it is one where the provider can demonstrate, for any specific device, that it was destroyed to standard and accounted for from start to finish. In a sector where health information is treated as sensitive under the Privacy Act and breaches are reported more often than in any other industry, that ability to demonstrate is much of the point. It turns a patient-trust question and a regulatory question into a matter of retrieving records rather than reconstructing what probably happened to a device that left the building months ago.
Four things turn a health provider's disposal into one that protects patients and stands up to scrutiny.
Not just computers: imaging PCs, servers, tablets and the photocopiers and multifunction devices whose internal drives store scanned records. The scope covers anything that ever touched patient data.
Certified wiping to NIST 800-88 for reusable equipment, and physical shredding for drives that cannot be verifiably wiped, with solid-state media handled by a method matched to flash. See data destruction services.
Every asset logged at collection and tracked to destruction, so there is never a window in which a device holding patient data is unaccounted for.
Item-level proof recording what was destroyed and how, reconcilable to your asset register, so you can show exactly how any specific device was handled.
Health services run around the clock, so collections are scheduled to fit clinical operations, ward closures, refurbishments or system upgrades, rather than disrupt care. Equipment can be securely held and collected in a coordinated sweep, so retired devices do not pile up in a corridor holding patient data while they wait. Talk to our team about scheduling around your environment.
The obligation scales down as well as up. A GP practice or an aged-care home holds the same sensitive data, with fewer resources to manage it.
Large hospitals have IT teams and formal processes; smaller providers often do not, yet they hold the same category of sensitive health information and carry the same obligations to destroy it securely at end of life. A general practice retiring a few workstations, an aged-care provider replacing tablets across a facility, a specialist clinic upgrading its imaging PC, all of them are handling patient data that must be destroyed to standard and documented. For these providers the risk is often higher precisely because disposal is informal: a device gets gifted to a staff member, sold second-hand, or left in a store room, still holding records. A certified collection removes that risk, brings the same standard a hospital would use to a smaller provider, and produces the certificate that proves it was done.
Because reusable equipment can be securely wiped and its value recovered, a refresh at a clinic or aged-care facility need not be a pure cost either. Working devices routed through buyback, once the data is destroyed and certified, can offset the cost of the new equipment, while everything else is recycled responsibly. The data is protected and the budget stretches further, which matters most for exactly the smaller providers who feel disposal as an overhead.
The questions health providers ask most about retiring IT that held patient data.
No. A factory reset or deleting files leaves the underlying data recoverable with freely available tools. To protect patient information, the storage must be securely wiped to a recognised standard such as NIST 800-88, or physically destroyed, with a certificate confirming it was done. That is the step that meets a health provider's obligations and provides evidence if it is ever questioned.
Usually yes. Most office photocopiers and multifunction devices contain an internal hard drive that stores an image of documents scanned, printed or faxed, which in a health setting includes referrals, results and records. When a copier is returned at lease end or retired, that drive should be wiped or destroyed and certified, exactly like any other data-bearing device. It is one of the most commonly overlooked risks in health disposal.
The Privacy Act 1988 classifies health information as sensitive information and requires it to be destroyed or de-identified once no longer needed, with reasonable steps taken to protect it. Where My Health Record data is involved, the My Health Records Act adds further obligations. Public health services also face state records and health-records requirements. Across all of them, secure, documented destruction at disposal is the expectation.
Health records must be retained for set periods, so archive the information you are required to keep to your current systems before the old hardware is destroyed. The disposal handles the device and its residual data; your records-retention policy governs what must be kept elsewhere. Confirm the archive is complete, then destroy the old equipment with confidence.
Yes. A GP practice, specialist clinic or aged-care home holds the same category of sensitive health information as a hospital and carries the same obligation to destroy it securely. The risk is often higher for smaller providers because disposal is informal. A certified collection brings the hospital standard to a smaller provider and produces the certificate that proves the data was destroyed.
Yes, once the data is destroyed and certified. Working equipment can be securely wiped to standard and refurbished, with its value recovered through buyback to offset the cost of a refresh, while the rest is recycled responsibly. The sequence is essential: the patient data is destroyed and documented first, then the clean hardware carries its value forward.
See how ITC destroys patient data on retired IT for hospitals, clinics and aged-care providers, to a recognised standard, with the chain of custody and per-device certificates that prove it was done.
Evidence for your auditor
Regulators do not ask whether you recycled the hardware. They ask what happened to the data on it, who handled it, and where the record is. ITC holds ISO/IEC 27001:2022 for information security alongside ISO 14001:2015, ISO 9001:2015 and ISO 45001:2018, and issues serialised documentation on every job so the answer is already written down.