Sector expertise

NHS & Healthcare IT Disposal: Patient Data Destroyed with Evidence

Retired clinical and administrative devices carry some of the most sensitive data held anywhere in the UK. We destroy patient data with per-serial evidence, on hospital sites where required, and hand your information governance team a pack built for DSPT submissions, Caldicott sign-off and inspection day.

ISO 27001NIST 800-88WEEE CompliantCyber Essentials
Nanosoft engineer degaussing magnetic media as part of certified data destruction
Inside our UK facility
Nanosoft engineer degaussing magnetic media as part of certified data destruction
The short answer

Who provides IT asset disposal for NHS and healthcare organisations?

Nanosoft sanitises and destroys patient-data devices for NHS trusts, GP practices, clinics and care providers across the UK, to NIST 800-88, with witnessed destruction available on hospital sites. Every serial number is certificated individually, and the audit pack is built to slot into DSPT submissions and information governance reviews.

Compliance

What the rules require, and how we evidence it

The regimes below are the ones your auditors and regulators actually cite. For each, here is what it requires of your organisation and the evidence we put in your hands.

NHS Data Security and Protection Toolkit (DSPT) 2025-26

DSPT 2025-26 is version 8, aligned to the NCSC Cyber Assessment Framework (CAF): objectives A to D plus the NHS-specific Objective E, with a publication deadline of 30 June 2026. Secure disposal of data-bearing assets sits inside the evidence base your organisation must publish against.

How we evidence it

Per-serial destruction certificates, chain-of-custody records and a reconciled asset inventory that slot directly into your DSPT submission as disposal evidence, mapped to the assets your IG team declares.

The eight Caldicott Principles

Confidential patient information must be protected across its whole lifecycle, disposal included. The eighth principle, added in December 2020, requires organisations to inform patients about how their confidential information is used, which presumes the organisation can account for it to the end.

How we evidence it

An unbroken, documented chain from ward or office to verified destruction, so your Caldicott Guardian can sign off that confidentiality was preserved through disposal and account for every device that held patient information.

CQC inspection evidence

The CQC regulates health and social care providers, not their disposal contractors: an ITAD cannot be CQC-registered. What inspected providers must be able to show is that patient records and data-bearing devices were disposed of securely.

How we evidence it

Audit-ready disposal evidence your team can present at CQC inspections: serialised inventories, destruction certificates and custody records, organised so they can be produced on the day without preparation.

UK GDPR special-category data

Health data is special-category data under UK GDPR, carrying heightened security obligations and a duty to demonstrate that personal data on retired devices has been irreversibly destroyed, not merely deleted.

How we evidence it

NIST 800-88 sanitisation or physical destruction for every device, evidenced serial by serial, so your records show exactly what was destroyed, when, how and by whom.

What you receive

Deliverables on every nhs & healthcare engagement

  • Per-serial certificates of data destruction for every drive and device
  • Witnessed destruction on hospital sites, with certificates issued before we leave
  • Crews briefed on clinical-equipment handling and embedded storage in medical devices
  • A consolidated audit pack delivered to your IG team within 10 working days
  • Chain of custody with numbered tamper-evident seals from your site to our processing floor
Hard drive destruction being witnessed at close quarters with a Nanosoft engineer
Hard drive destruction being witnessed at close quarters with a Nanosoft engineer
The stakes

What goes wrong without evidence

Unaccounted drives from retired clinical devices

Imaging workstations, diagnostic equipment and clinical terminals often hold storage that a standard IT inventory misses. A single unaccounted drive containing patient data is a reportable incident waiting to be found, years after the device left the building.

Subcontracted couriers breaking custody

Many disposal firms hand collections to courier networks the moment they leave your site. Every handoff is a gap in the custody record, and it is your organisation, not the courier, that answers to the ICO and your patients if media goes missing in transit.

Batch certificates failing IG audits

A certificate saying "40 drives destroyed" cannot prove that any specific drive was among them. Information governance audits increasingly ask for per-serial evidence, and batch-level paperwork discovered at audit time cannot be repaired retrospectively.

Verified erasure stations sanitising drives at the Nanosoft facility
Verified erasure stations sanitising drives at the Nanosoft facility
Chain of custody scanning of serial numbers at the Nanosoft intake bench
Chain of custody scanning of serial numbers at the Nanosoft intake bench
Drives physically destroyed in the industrial shredder at the Nanosoft facility
Drives physically destroyed in the industrial shredder at the Nanosoft facility
Common questions

Frequently asked by nhs & healthcare clients

Supplier DSPT positions change as each toolkit year is republished, so we do not make static claims on a web page. Ask for our current DSPT position when you enquire and we will set it out plainly, alongside our ISO 27001 certification and the per-serial destruction evidence we provide for your own submission.

NIST 800-88, the sanitisation standard referenced across UK public-sector guidance. Depending on media type and your risk appetite we apply Clear, Purge or Destroy: verified erasure for reusable devices, physical destruction for failed drives and media your IG team flags as destroy-only. The method used is recorded on each certificate.

Yes. Our mobile shredding unit destroys drives at your premises to NIST 800-88 Destroy, witnessed by your staff, with certificates issued on the spot. Media never leaves the site intact. For trusts that prefer off-site processing, witness video of the destruction is available as an alternative.

One audit pack within 10 working days: a serialised asset inventory reconciled against the collection manifest, per-device certificates of data destruction, chain-of-custody records with seal numbers, and WEEE and waste transfer documentation. It is structured for DSPT submissions, Caldicott sign-off and inspection evidence.

Yes. Ultrasound units, patient monitors, imaging workstations and similar equipment frequently contain internal storage that standard IT disposal misses. Our crews are briefed to identify and extract embedded media, and each extracted drive is serialised and certificated individually, linked back to the parent device in your inventory.

Trust-scale collections run from around 10 devices with no upper limit, coordinated across sites by a single project manager. For GP practices and small clinics with less than that, we consolidate with nearby collections or supply tamper-evident packaging for tracked courier of loose drives to our secure Essex facility.

DSPT 2025-26 must be published by 30 June 2026, and disposal evidence is easiest to gather while devices are still in the building. Clearing legacy equipment now, with per-serial certificates, closes off the asset-disposal questions in your submission rather than leaving them open against a deadline.

Ready to dispose of NHS & Healthcare IT equipment with the evidence built in?

Same-day quote, no obligation. Tell us what you have and where it is, and we confirm a collection slot and a fixed price the same day.

ISO 27001NIST 800-88WEEE CompliantCyber Essentials