Sector

Healthcare

Patient data is special category data. Treat the hardware accordingly.

Health and care records are special category data under Article 9 of the UK GDPR. The bar for handling them sits higher than for ordinary personal data, and it does not drop the moment a machine is switched off for the last time.

A retired desktop from a consulting room still holds patient data until the drive has been sanitised and that sanitisation has been evidenced. Until then it is a breach waiting for someone to plug it back in.

What the DSPT asks you to show

The Data Security and Protection Toolkit expects you to evidence that end-of-life equipment was disposed of securely. An invoice from a recycler does not show that.

We give you the paperwork instead:

File it against your DSPT submission, or put it in front of your Caldicott Guardian, your DPO or the ICO. We hold no NHS approval and we are not on any framework: the assertion is yours to make, and our documentation supports the evidence behind it rather than satisfying the Toolkit.

Need-to-know access under the Caldicott principles counts for nothing if a drive leaves the building readable.

How the data is destroyed

Drives are sanitised to NIST SP 800-88 Rev. 1, and to HMG Infosec Standard 5 Enhanced on request; the method is set out under certified data destruction. These are the standards we work to, not certifications we hold.

We never open, index or inventory what is on a drive.

Equipment that has been in service a decade

Hardware stays in service as long as it works. The tower under the reception desk may have held demographics, scanned correspondence, referral letters and clinical system caches since before most of the current staff arrived.

Age makes erasure harder, not easier. Failed drives, machines that will not boot, laptops nobody has the BIOS password for. Bring them out with the rest. A spinning disk takes hours to work through where a modern SSD takes minutes, so tell us what is in the pile.

Clinical systems and licensed software

Tell us before collection if a workstation still carries a clinical system client, practice management software or imaging applications. Some of it needs deauthorising, or sits on a support contract you will want to close cleanly. Erasure takes the software with everything else, so anything you need has to come off first.

When it is nobody's job

If the practice has no IT function, disposal lands on the practice manager, between the rota and the CQC paperwork. We log it, take it away, sanitise it and document it, the same as any other IT asset recovery collection.

A care home is the same problem with less to work with: a few office PCs, an old server running the care planning system, a drawer of eMAR tablets nobody returned to the supplier.

Collection

We cover Oxfordshire, Buckinghamshire, Berkshire, Northamptonshire and Warwickshire, work around surgery hours, and can collect from a store room or corridor without going near a clinical area.

Collection is free where the resale value in the load covers the trip, and that value is credited back to you; otherwise we quote the cost first.

Send a rough list of what you have to oliver@kiverefresh.com, or get a quote, and we will tell you what happens to each item.

Common questions

Does this satisfy our DSPT evidence?

It gives you the evidence the Toolkit expects to see. Your signed manifest shows what left the premises and when. The Certificate of Data Erasure for each drive shows the method used and the standard applied, referenced to the drive serial and the machine it came out of.

We are not NHS-approved and we are not on any framework. The assertion is yours to make; our documentation supports it rather than satisfying the Toolkit on our authority.

Is your process different because this is special category data?

The method is the same one we apply to everything, because it already assumes the drive holds something serious: it is set out under certified data destruction. What changes is the paperwork. Every drive is certified individually, so you can point at one machine and say what happened to it: the level of record an Article 9 breach investigation would ask for.

Can you collect from a live surgery?

Yes. Equipment can be staged in a store room, corridor or car park and collected from there, so nothing happens in a clinical area or in front of patients. Give us a time that suits the practice.

What if the machine still holds clinical software?

Tell us before we collect. Clinical system clients, practice management software and imaging applications sometimes need deauthorising or releasing from a licence first. Erasure removes everything on the drive, so anything you still need has to be migrated off. We never open, index or read the files on a drive, so we cannot tell you what is installed on a machine, and that check has to happen on your side, before collection. What you get from us is the hardware record: make, model and serial on the collection manifest, and the drive's own make, model, capacity and serial on its erasure certificate afterwards.

What happens to drives that have failed?

Any drive that cannot be sanitised is physically destroyed: dead drives, drives that fail read-back verification, machines that will not boot far enough to be wiped. You get a record of destruction referenced to the serial number, as you would an erasure certificate. Send a rough list when you get a quote and we will say what is likely to fall into that group.


Services for this sector

Talk to someone who's done it before

No call centre, no ticket queue. You'll be talking to the person who does the collection.