Certified Data Erasure

Device Guide

HIPAA-Compliant SSD & NVMe Wipe

SSD and NVMe drives store PHI differently than HDDs — which is why format and overwrite are not enough. The right path is NIST 800-88 Purge: a hardware Sanitize. Here is why, and how.

✓ NIST 800-88 Purge ✓ ATA / NVMe Sanitize ✓ IEEE 2883 ✓ Cryptographic Erase

The Problem

Why SSDs are different: wear-leveling & over-provisioning

On an HDD, a logical address always maps to the same physical sector. On an SSD, the controller constantly spreads writes across different physical NAND cells to balance cell wear (wear-leveling) and keeps an over-provisioning area hidden from the OS. The result: when you "overwrite" a file, the old copy can remain in another physical cell. TRIM helps but is not a guarantee. So the software overwrite that works on an HDD does not fully destroy PHI on an SSD.

The Right Method

Hardware Sanitize (NIST 800-88 Purge)

The solution is to let the drive controller do the erase. Because the controller can reach all NAND — including hidden and reserved areas — the hardware command guarantees complete destruction:

  • ATA Secure Erase / Sanitize — block erase at controller level for SATA SSDs.
  • NVMe Sanitize — the fastest, most complete path for NVMe drives.
  • Cryptographic Erase (IEEE 2883) — destroys the drive encryption key; data becomes instantly inaccessible.

If a drive does not support the hardware command, PIWIPE falls back to verified overwrite (Clear) and notes it on the certificate. NIST 800-88 vs HIPAA →

Comparison

HDD vs SSD vs NVMe — the right method

Drive Overwrite enough? Recommended (NIST 800-88)
HDDYes (verified)Clear/Purge overwrite + HPA/DCO removal
SATA SSDNoPurge — ATA Secure Erase / Sanitize
NVMeNoPurge — NVMe Sanitize / Cryptographic Erase

Proof

Verify and certify

Just as important as erasing is proving it. After Sanitize, PIWIPE verifies the drive and produces a per-device tamper-proof PDF certificate: serial number, method applied (e.g., NVMe Sanitize), SS-036/NIST class (Purge), date, SHA-256 hash, PKCS#7 signature and QR verification. This is independent proof, in a HIPAA audit, that the SSD was genuinely destroyed.

Frequently Asked

HIPAA SSD Wipe

Can you wipe an SSD to HIPAA standards?
Yes. NIST 800-88 Purge (hardware ATA/NVMe Sanitize or Cryptographic Erase) meets HIPAA's requirement to render PHI unreadable. PIWIPE applies and certifies it.
Does overwriting an SSD remove all data?
Not reliably. Due to wear-leveling/over-provisioning, a software overwrite cannot reach reserved NAND cells; PHI can remain. A hardware Sanitize (Purge) is required.
Best way to erase an SSD with PHI?
SATA SSD: ATA Secure Erase/Sanitize; NVMe: NVMe Sanitize or Cryptographic Erase (IEEE 2883). Then verification + certificate. PIWIPE auto-selects.
Is NVMe secure erase HIPAA compliant?
Yes — aligned with NIST 800-88 Purge and IEEE 2883, it destroys all NAND including over-provisioning; documented with a certificate it meets a HIPAA audit. HIPAA media disposal requirements →

Sanitize your SSDs & NVMe, audit-ready.

PIWIPE applies hardware Sanitize and issues a per-device tamper-proof certificate.

HIPAA Compliant Disk Wipe Request a Demo

Or call us: +90 212 916 12 22