A hospital is decommissioning several old servers that once stored ePHI. The data has been backed up according to the contingency plan. According to the HIPAA Security Rule's Physical Safeguards, which of the following actions is a required and appropriate final step for the physical server media before it leaves the hospital's control?
-
A
Wiping the drives using a standard file deletion utility.
-
B
Removing the hospital's asset tags from the server chassis.
-
C
Degaussing or physically destroying the hard drives to render the ePHI unrecoverable.
-
D
Donating the servers to a local charity "as is" with a disclaimer.