Hospitals, clinics, labs and insurers trust us with drives full of patient records. We sign Business Associate Agreements and follow the HIPAA Security Rule throughout the recovery.
How we protect PHI
- Business Associate Agreement signed before any device ships
- Administrative, physical and technical safeguards under the Security Rule
- Minimum-necessary access: only the assigned engineer touches the data
- Encrypted return media and certified destruction of working copies
- Breach-notification procedures aligned with the HITECH Act
Who we work with
Hospitals, physician groups, dental and imaging practices, labs, pharmacies, insurers and health-tech vendors.
Chain of custody
- Intake. Your device is photographed, serial-numbered and sealed in a tamper-evident bag. You get a case number and an intake record.
- Storage. Devices wait in a locked, access-logged vault, never on an open bench.
- Recovery. Only the assigned engineer can sign the device out. Every handoff is recorded with name, time and purpose.
- Verification. Recovered data is hashed so you can confirm nothing changed between our lab and your hands.
- Return. Data ships on a new encrypted drive by tracked, signature-required courier, or by secure download.
- Destruction. Once you confirm receipt, working copies are wiped to NIST 800-88 and you receive a certificate of destruction.
Certifications
SOC 2 Type IIIndependently audited controls
HIPAABusiness Associate Agreements
ISO Class 5 cleanroomParticle-controlled lab
Chain of custodyEvery device, every step