Old computers do not forget. When a general practice replaces its reception workstation or an aged care facility decommissions its clinical server, the data on those drives does not disappear. It stays there, retrievable, until it is deliberately and verifiably destroyed. For Victorian healthcare providers, that is not just a technical problem. It is a legal obligation.

What patient data survives on retired hardware

Clinical systems accumulate patient records, Medicare details, pathology results, referral letters, and appointment histories. That data lives on local drives, on embedded storage inside multifunction printers, and sometimes on diagnostic equipment with built-in computers. When a device goes to a standard recycler, gets donated, or passes through a trade-in program, that data travels with it unless the device has been properly sanitised first.

Recovered data from second-hand devices is not hypothetical. Independent research has repeatedly found that a significant proportion of used drives available through consumer resale channels contain recoverable data, including personally identifiable information from business and medical contexts.

The legal obligations for healthcare in Victoria

Under the Privacy Act 1988 and Victoria Health Records Act 2001, health information is protected even after it is no longer needed for clinical care. That protection extends to how the hardware is disposed of. An organisation that sends old computers to landfill or to an unvetted recycler is not just creating an environmental problem. It may be in breach of its data security obligations.

The Victorian e-waste landfill ban, in effect since 2020, independently prohibits sending computers, monitors, and other electronic devices to landfill. Compliance with that ban and compliance with privacy law are separate requirements, but they both point to the same answer: use a verified ITAD provider.

The sanitisation standard healthcare organisations should apply

NIST Special Publication 800-88 Rev. 2 defines three levels of media sanitisation: Clear, Purge, and Destroy. For healthcare environments handling sensitive patient data, Clear (a basic software overwrite) is rarely sufficient for devices leaving the organisation.

  • Purge: cryptographic erase or verified multi-pass overwrite, suitable for drives that will be reused or resold.
  • Destroy: physical shredding or degaussing, required for end-of-life devices that will not be reused.

EWV disposal processes align with NIST 800-88 Rev. 2. Our operations also align with AS/NZS 5377 for e-waste handling and ISO 14001 for environmental management. Full ISO 27001 certification is on our roadmap.

Why chain of custody is non-negotiable

If a breach investigation or privacy audit arises, healthcare organisations need to demonstrate exactly which assets were disposed of, by whom, using which method, and on which date. An informal arrangement with a local IT shop does not constitute documentation.

What a compliant disposal process looks like:

  • A registered manifest of all assets, itemised by serial number
  • A certificate of destruction for each device
  • A clear chain of custody record from collection through to final processing
  • Confirmation that the Victorian e-waste landfill ban requirement has been met

EWV CircularTrack platform records every asset through the full disposal lifecycle and generates per-serial-number destruction certificates that compliance teams can file alongside their privacy documentation.

The EOFY pressure point

Healthcare organisations are not exempt from the EOFY hardware refresh cycle. With 30 June approaching, general practices, hospital networks, and aged care facilities upgrading equipment face the same time pressure as any business. The difference is the risk attached to cutting corners.

Under the Privacy Act, serious or repeated interferences with privacy can attract penalties of up to $50 million. The Office of the Australian Information Commissioner consistently lists health as one of the top sectors for notifiable data breaches in Australia.

Disposal is not a box to tick after procurement is complete. It is part of the compliance obligation.

Next step

If your organisation is refreshing IT assets before EOFY and you are not certain your current provider meets NIST 800-88 and AS/NZS 5377 requirements, request a process review from EWV before the hardware leaves your site.