Audit Evidence
Certificate of Destruction for PHI
In a HIPAA audit, saying "we wiped it" is not enough — you must prove it. Here is what a valid PHI certificate of destruction must contain, and why it must be tamper-proof.
Mandatory Fields
What a PHI certificate of destruction must contain
- 1Device identity — Make, model, serial number / IMEI.
- 2Method applied + class — e.g., NVMe Sanitize; NIST 800-88 / SS-036 Clear or Purge.
- 3Date and time — Start/end timestamp.
- 4Operator / organization — Who performed it, on behalf of which organization.
- 5Verification result — Confirmation that the wipe was verified.
- 6Integrity hash (SHA-256) — Proves the document was not altered.
- 7Independent verification (QR / link) — So an auditor can confirm it without a login.
Why It Fails
A "we ran format" statement is not evidence
Writing "wiped" in a spreadsheet, or a verbal statement, is not verifiable for an auditor and does not protect you during an incident. An auditor looks for three things: which device, by what method, when — and a guarantee it cannot be altered afterward. A per-device, tamper-proof certificate delivers all three. HIPAA media disposal requirements →
Tamper-Proof
Two layers: SHA-256 hash + PKCS#7 signature
SHA-256 Verification Hash
The certificate data is reduced to a single fingerprint and stored on the server. If a date, device or result is changed, the hash no longer matches — caught instantly in online verification.
PKCS#7 Digital Signature
The entire PDF is signed with a private key and the signature is embedded in the file. Change a single byte and Adobe Reader shows "signature invalid" — no internet needed.
In a Breach
Lost/stolen device: "low probability of compromise"
The HIPAA Breach Notification Rule (45 CFR §164.404) requires notifying affected individuals and HHS. But if a device was destroyed before disposal and you hold a valid certificate, the incident can fall outside breach scope by demonstrating a "low probability of compromise." The certificate is the documentary basis for that assessment; QR verification gives an HHS auditor independent confirmation.
Frequently Asked
Certificate of Destruction
An audit-ready certificate for every wipe.
PIWIPE issues a per-device tamper-proof PDF certificate — SHA-256, PKCS#7 signature and QR verification.
Or call us: +90 212 916 12 22