Skip to main content
DTI

DATASAN FOR HOSPITALS

Hospital Data Security and Destruction Aligned with the PDP Law and NIST SP 800-88

Patient data remains your hospital's responsibility long after a hard drive is replaced or a server is retired. Datasan helps hospitals govern data security and destruction end to end: from retention policy to certified HDD/SSD media destruction aligned with NIST SP 800-88, complete with chain of custody and audit-ready certificates of destruction.

PDP Law No. 27/2022MoH Regulation No. 24/2022Gov. Regulation No. 71/2019NIST SP 800-88 Rev. 1

Discuss your deployment

Free initial consultation — we'll map your needs, integration, and compliance.

Are you inquiring for an organization or yourself?*

Reply within 1 business day · Your data is protected (UU PDP)

Hospital data security and destruction is now a legal obligation, not merely good practice. Indonesia's Law No. 27 of 2022 on Personal Data Protection (PDP Law) classifies health data as specific personal data, which means hospitals — as data controllers — must protect it throughout its entire lifecycle, including destroying it properly once retention periods end or the PDP Law's conditions for erasure and destruction are met.

In parallel, Ministry of Health Regulation No. 24 of 2022 on Medical Records mandates electronic medical records and governs their retention; once the retention period lapses, records may be destroyed in accordance with the regulation. The problem is that most data leaks occur at the points nobody watches: used hard drives from hospital information system servers, refreshed clinician laptops, backup media piling up in storage rooms, or devices handed to third-party vendors without any documentation.

Deleting files or reformatting media does not remove the data — it remains recoverable with widely available forensic software. NIST SP 800-88 Rev. 1 (Guidelines for Media Sanitization) is the globally recognized reference for media sanitization through its Clear, Purge, and Destroy approach. Datasan delivers destruction services and governance built on that standard, so your hospital can prove — not merely claim — that patient data has been properly destroyed.

The Hidden Risks in a Hospital's Retired Storage Media

Patient data remains readable after deletion or formatting

Delete and format commands only remove file pointers, not the content. Medical records, lab results, and radiology images on retired media can be recovered with common forensic tools.

Devices leave the hospital without a documented trail

Retired server drives, refreshed laptops, and backup media often change hands to vendors or asset auctions without serial-number logging or formal handover, leaving no one able to say where patient data went.

Destruction methods that don't match the media type

Degaussing works on magnetic media such as HDDs and tape, but does not erase SSDs or flash memory. Without method-to-media mapping, destruction can look complete while the data survives intact.

No defensible evidence when auditors come asking

When auditors, regulators, or legal teams request proof of destruction, an internal memo without method details, media serial numbers, and result verification is difficult to defend as PDP Law compliance evidence.

The Datasan Solution: Certified Data Destruction with End-to-End Governance

Media sanitization aligned with NIST SP 800-88 Rev. 1

Clear, Purge, or Destroy is selected based on media type, data sensitivity, and reuse plans — not a one-size-fits-all approach that ignores the differences between HDDs, SSDs, tape, and mobile devices.

Physical HDD/SSD destruction with verification

For media that will never be reused, physical destruction such as shredding or crushing is performed with per-unit logging and result verification, so no drive slips through the process.

Chain of custody from handover to destruction

Every media item is serial-logged, sealed, and documented at each transfer of possession. Your hospital holds a complete trail of who held which media, when, and for what purpose.

Certificates of destruction and audit-ready documentation

Every engagement produces a certificate of sanitization/destruction recording media identity, method, date, personnel, and verification results — evidence you can present to internal auditors, accreditation bodies, and regulators.

Data lifecycle governance through decommissioning

Datasan helps you build retention and destruction policies aligned with the PDP Law, MoH Regulation 24/2022, and Government Regulation 71/2019, including decommissioning procedures for hospital information system servers and medical devices that store patient data.

Datasan is trusted to handle decommissioning and storage media destruction for organizations in Indonesia's regulated sectors, including environments with stringent audit requirements.

How the Data Destruction Process Works

1

Assessment and media inventory

The team identifies every medium holding patient data — hospital information system servers, workstations, laptops, backup media, and storage inside medical devices — then maps media type, data classification, and retention status. The result is a clear register: what must still be retained, and what is ready for destruction.

2

Method selection and approval

For each media group, the sanitization method is set per NIST SP 800-88 — Clear for media reused internally, Purge (such as cryptographic erase or device sanitize where supported) for stricter needs, and Destroy for media leaving the hospital environment. The plan is approved with data owners and your compliance team before execution.

3

Execution under chain of custody

Media are sealed, logged by serial number, and destroyed either on-site at your hospital or at a destruction facility under documented escort. Every transfer of possession is recorded, and hospital representatives may witness the process directly.

4

Verification and evidence issuance

Destruction results are verified, then a certificate of destruction is issued together with a report listing media, methods, timestamps, and personnel involved. This documentation becomes your hospital's compliance archive for audits, accreditation, and legal defensibility.

Frequently Asked Questions

Are hospitals required to destroy patient data?

The PDP Law requires data controllers to destroy personal data under certain conditions, including when the retention period ends or the data is no longer needed for its processing purpose. For medical records, MoH Regulation No. 24 of 2022 governs the retention of electronic medical records and permits destruction once the retention period lapses, subject to its provisions. Properly documented destruction is therefore part of compliance, not an option.

Why isn't deleting files or reformatting a hard drive enough?

Standard deletion and formatting only remove file references from the operating system while the data stays on the media, recoverable with off-the-shelf recovery software. That is why NIST SP 800-88 defines the escalating Clear, Purge, and Destroy sanitization levels matched to data sensitivity and the media's next destination.

What's the difference between degaussing, shredding, and cryptographic erase — and which is right for SSDs?

Degaussing erases data using magnetic fields, so it is only effective on magnetic media such as HDDs and tape; SSDs are unaffected because they store data on flash chips. For SSDs, the right choices are Purge via the device's built-in sanitize mechanisms (including cryptographic erase where the prerequisites are met) or physical destruction such as shredding to an adequate fragment size. Datasan maps the appropriate method to each media type.

What evidence should we be able to show auditors or regulators?

Good practice includes per-batch or per-media certificates of destruction recording serial numbers, sanitization method, date, executing personnel, and verification results, plus chain-of-custody documents tracking every transfer of the media. This documentation set is what separates a claim of 'it was destroyed' from defensible compliance evidence.

Can destruction be performed on-site at the hospital?

Yes. For highly sensitive data such as medical records, on-site destruction means media are destroyed without ever leaving the hospital environment, witnessed directly by your representatives. When destruction is performed off-site, media are sealed and escorted under a documented chain of custody from handover to destruction.

What about hospital information system servers or medical devices being decommissioned?

Server and medical device decommissioning is among the highest-risk points because their storage media are easily overlooked. Datasan inventories every data-bearing component — including internal disks in medical devices and backup media — and performs sanitization or destruction before equipment is released, sold, or returned to vendors, with full documentation.

DATASAN FOR HOSPITALS

Make Patient Data Destruction Provable, Not Assumed

Talk to the Datasan team about your hospital's data security and destruction needs. We help you plan the media assessment, select sanitization methods per NIST SP 800-88, and produce audit-ready documentation for PDP Law and Ministry of Health compliance — without disrupting clinical operations.

Chat via WhatsApp