Viewing a single comment thread. View all comments

Red__M_M t1_j6nhnh4 wrote

I work in healthcare and laptops are almost always intentionally destroyed not repurposed. A laptop can contain absurd amounts of personally identifiable data and if it is lost then the fine for violating the Health Insurance Portability and Accountability Act (HIPAA) can quickly exceed $1M. It starts at $100 PER RECORD! Now imagine a nurse that sees 10 patients per day for 5 years. Or how about a person doing claims review on 100 claims per day? Then there is me who processes millions of records all the time.

Since a loss of information could be so costly, it is much easier to just destroy laptops than to try to format them. One of my former employers would take old hard drives and run a government format on them. Next they would erase them (again) with a strong magnet. Then they would shred the devices in house. Then they would give the shreds to a secure documents destruction company who I think would melt things down. Admittedly that was a bit over the top, but my point is that hardware destruction is the norm in healthcare.

9

pm_me_your_buttbulge t1_j6pfz5b wrote

SSD's don't delete like an HDD. Recovery, without modifying the settings of the SSD, is non-trivial. One dd if=/dev/urandom of=/dev/sd0 and you are not recovering that data. I've yet to find a recovery company capable of getting any useful data even when given the location of a text file and all they had to do was tell me what was in the file and nothing else.

It's become a phobia for quite some time now because of the laws.

It turns out the theory that some with an electron microscope could extra several layers of data was very wrong but people took it as gospel. Turns out it's an order of magnitude more difficult.

Most recovery is done from a 'they deleted the file and turned the machine off' type situation. Meaning no actual wiping occurred more than pointers to the file.

Specifically, for SSD's, it depends on the trim setting on your drive.

But even for HDD's, one solid dd wipe to full and there is not going to be any data recovery.

Now if you're talking hard drive made before the late 90's then some things can get weird and a few other factors may come into play but most of those hard drives are long dead now but even then it's still extremely difficult to recover data that's been zero'ed.

> but my point is that hardware destruction is the norm in healthcare.

It's also the norm in the federal government for similar reasons.

4

frosty_pickle t1_j6p42sn wrote

Having benefited from some data recovery companies in the past, sometimes data that’s erased is still there. That being said a there are some thorough formatting procedures which do a damn good job of cleaning everything out. But if your it department is overwhelmed with other things and information security is vital then a shredder does a pretty good job.

1