Standards Explainer
NIST 800-88 vs HIPAA — What Standard Does HIPAA Require?
Short answer: HIPAA does not name a standard — it requires an outcome. HHS guidance points to NIST SP 800-88. Below, what that means for you in practice.
The Core Question
Does HIPAA name a specific standard? No.
The media-disposal provision of the HIPAA Security Rule (45 CFR §164.310(d)(2)(i)) is technology-neutral and outcome-based: electronic media holding Protected Health Information (PHI) must be disposed of so that PHI cannot be read or reconstructed. The rule imposes no specific algorithm — it asks you to reliably achieve, and document, that outcome.
The Accepted Method
Why everyone points to NIST SP 800-88
HHS guidance for the HIPAA Security Rule and its breach-notification interpretations explicitly reference NIST SP 800-88 for media sanitization. Because the standard has become the de-facto reference in practice, implementing NIST 800-88 is the most defensible way to say "we destroyed PHI using an accepted method." Meet NIST 800-88 and you meet HIPAA's outcome requirement.
Two Levels
NIST 800-88: Clear vs Purge, by device type
PIWIPE detects the device type and auto-recommends the correct NIST 800-88 level. All 18+ standards →
Mapping
HIPAA requirement → NIST 800-88 + PIWIPE
- ✓Render PHI unreadable — NIST 800-88 Clear/Purge; PIWIPE applies per device.
- ✓Cover hidden areas — HPA/DCO and over-provisioning are cleared.
- ✓Documentation — Per-device tamper-proof PDF certificate (hash + signature).
- ✓6-year retention — Indefinite cloud archive, audit-ready.
Frequently Asked
NIST 800-88 & HIPAA
Apply NIST 800-88, audit-ready.
PIWIPE applies the right level per device and issues a tamper-proof certificate.
Or call us: +90 212 916 12 22