The short answer: copiers store PHI on internal hard drives
If you searched for how HIPAA relates to copier security, there is a good chance the question came from a training course or a compliance quiz, and the expected answer is short: modern copiers contain hard drives that store images of the documents they process, so a copier that handles patient records is storing electronic protected health information, and HIPAA requires that information to be protected just like ePHI on a server or laptop. That answer is correct, and if you only needed the quiz response, you have it. But the question deserves a longer treatment, because the copier sitting in your office hallway is one of the most commonly overlooked systems in healthcare compliance. It stores data almost nobody remembers it stores, it is frequently leased and returned to vendors with that data intact, it sits in physical locations chosen for convenience rather than security, and it prints, scans, and faxes PHI all day in front of patients and visitors. The Department of Health and Human Services has already collected more than a million dollars from one health plan over exactly this blind spot. This guide walks through how the HIPAA Security Rule and Privacy Rule apply to copiers, printers, fax machines, and multifunction devices, what the enforcement record shows, and the specific controls a practice or business associate should have in place, each tied to the regulation that requires it.
Start with the fact that makes copiers a HIPAA issue at all: since the early 2000s, nearly every digital copier and multifunction device has shipped with an internal hard drive or solid-state storage, and that storage retains latent images of the documents the machine touches. The Federal Trade Commission's business guidance on copier data security, published after a widely reported investigation into used copiers, makes the point plainly: the hard drive in a digital copier stores data about the documents it copies, prints, scans, faxes, or emails. On a busy front desk machine that means patient intake forms, insurance cards, explanation of benefits statements, lab results, referral letters, and photo IDs, accumulated over months or years. Under 45 CFR 160.103, electronic protected health information is individually identifiable health information transmitted by or maintained in electronic media, and the definition of electronic media explicitly includes hard drives and memory cards inside devices. A copier that has scanned patient records maintains ePHI in every meaningful sense. The Security Rule's general requirement at 45 CFR 164.306(a) obligates covered entities and business associates to protect the confidentiality, integrity, and availability of all ePHI they create, receive, maintain, or transmit, with no exception for data the organization forgot it was keeping. The machine also typically stores fax logs, scan-to-email address books, and print job queues, which are their own small inventories of patient names and destinations. None of this is exotic: it is ordinary office equipment doing what its manual says it does, in a regulatory environment that holds you responsible for knowing it.
The first regulatory hook is the one OCR cited in its landmark copier enforcement action: the risk analysis requirement at 45 CFR 164.308(a)(1)(ii)(A). That provision requires an accurate and thorough assessment of the risks to all ePHI the organization holds, and OCR has been explicit that all means all, including ePHI on devices that do not look like computers. A risk analysis that inventories servers, workstations, and phones but skips the fleet of multifunction devices is incomplete on its face, and an incomplete risk analysis is among the most commonly cited failures in OCR settlements. The companion risk management standard at 45 CFR 164.308(a)(1)(ii)(B) then requires security measures sufficient to reduce the identified risks to a reasonable and appropriate level, which is where copier-specific controls like drive encryption, image overwrite, and end-of-lease sanitization enter the program. The practical step is simple to describe: add every copier, printer, scanner, and fax machine that touches PHI to your asset inventory, note whether each has internal storage, record who services it and what happens to it at end of life, and score the risk like you would any other system. If you have never run that exercise, our free HIPAA risk assessment tool walks through the Security Rule standard by standard and produces a scored gap list you can act on, and copier storage is exactly the kind of finding it is designed to surface.
Device and media controls: the safeguard written for copier hardware
The Security Rule then addresses copier hardware directly through the device and media controls standard at 45 CFR 164.310(d)(1), which is arguably the single most copier-relevant requirement in HIPAA. The standard requires policies governing the receipt and removal of hardware and electronic media containing ePHI into, out of, and within a facility, and it carries four implementation specifications. Two are required without qualification. Disposal, at 45 CFR 164.310(d)(2)(i), requires policies for the final disposition of ePHI and the hardware or media on which it is stored: you may not simply discard, donate, or return a device with patient data still readable on its drive. Media re-use, at 45 CFR 164.310(d)(2)(ii), requires procedures for removing ePHI from media before the media is made available for re-use, which is precisely the scenario of a leased copier going back to the leasing company for refurbishment and placement with its next customer. The other two specifications are addressable, which under 45 CFR 164.306(d) means you must implement them if reasonable and appropriate or document why an alternative suffices, not that you may ignore them. Accountability, at 45 CFR 164.310(d)(2)(iii), calls for a record of the movements of hardware and media and the persons responsible, which is what lets you answer where every drive went. Data backup and storage, at 45 CFR 164.310(d)(2)(iv), covers creating retrievable copies before equipment moves. Read together, the standard assumes exactly what copiers do: hardware full of ePHI physically entering and leaving your facility.
If the regulatory text feels abstract, the enforcement record is not. In 2010, CBS Evening News ran an investigation in which reporters bought used office copiers from a New Jersey warehouse and examined their hard drives. One of the machines had been leased by Affinity Health Plan, a New York managed care organization, and its drive still contained medical records. Affinity reported the incident to OCR as a breach affecting up to 344,579 individuals, an estimate covering everyone whose information could have been on the returned machines. OCR's investigation found that Affinity had returned multiple leased copiers to its leasing vendors without erasing the hard drives, had failed to incorporate the ePHI stored on copier drives into its risk analysis, and had no policies for sanitizing the drives before the machines left its control. In August 2013 Affinity settled with OCR for $1,215,780 and signed a corrective action plan that required it to use its best efforts to retrieve the hard drives from copiers it had previously returned and to build device storage into its risk analysis going forward. The settlement remains the definitive answer to anyone who thinks copier security is a theoretical concern: a television news crew with a screwdriver was the discovery mechanism, the penalty exceeded a million dollars, and the underlying failure was not a sophisticated attack but a lease return processed the way thousands of offices process them every year.
Sanitizing drives and locking down networked copiers
Knowing the drive must be cleaned is one thing; cleaning it correctly is another, and the standard reference is NIST Special Publication 800-88, Guidelines for Media Sanitization, the document OCR itself points to for disposal questions. NIST describes three escalating sanitization methods. Clear uses standard read and write commands to overwrite data, which for copier drives typically means running the manufacturer's overwrite function so stored images are replaced with meaningless data. Purge applies stronger techniques such as cryptographic erase, where the drive's encryption key is destroyed so the encrypted data becomes unrecoverable. Destroy means physical destruction of the media by shredding, disintegration, or degaussing, appropriate when a drive will never be reused or when its condition makes verification impossible. Which method is appropriate depends on the sensitivity of the data and where the media is headed next, but for a copier full of patient records leaving your custody, the safe default is purge or destroy, with a certificate documenting what was done, by whom, and when. Manufacturers have met the market halfway: most business-class devices now offer hard drive encryption kits and automatic image overwrite features that erase each job after processing, and the FTC's guidance recommends asking for both at purchase. Turning those features on costs little, and the 164.310(d) documentation they generate is exactly the evidence an OCR investigator asks for when a device leaves your inventory.
Storage is only half the modern copier's risk surface, because a multifunction device on your network is a networked computer with its own operating system, web administration console, and default password, and the Security Rule's technical safeguards apply to it the way they apply to any system handling ePHI. Access control under 45 CFR 164.312(a)(1) means restricting who can use the device's stored functions and administrative settings: change the default admin credentials the day the machine arrives, disable the protocols and services you do not use, and keep firmware updated on the same schedule as other patched systems. Unique user identification, the required specification at 164.312(a)(2)(i), maps naturally to PIN codes or badge authentication at the panel, which also enables pull printing, where a job is held until the person who sent it authenticates at the machine and cannot sit unattended in an output tray. Audit controls under 45 CFR 164.312(b) are served by the device's job logs, which record who copied, scanned, or faxed what and when, and which should feed your activity review process under 164.308(a)(1)(ii)(D). Person or entity authentication at 164.312(d) covers verifying who is at the panel before stored scans or address books open. And transmission security at 45 CFR 164.312(e)(1) reaches scan-to-email, scan-to-folder, and cloud print paths: those jobs travel your network and often the internet, so they should move over encrypted channels to authenticated destinations, not to an open share or a personal email address someone typed into the address book three years ago.
Paper output, copier placement, and fax machines
HIPAA also cares about the paper side of the machine, which is where the Privacy Rule takes over from the Security Rule. The Privacy Rule's safeguards standard at 45 CFR 164.530(c) requires reasonable administrative, technical, and physical safeguards for PHI in every form, including the printed page, and OCR's guidance has always treated documents left in output trays, misfiled copies, and unattended fax machines as classic safeguard failures. Placement is the first control: a device that processes patient records belongs in a staff-controlled area, not beside the waiting room chairs, and the facility access controls standard at 45 CFR 164.310(a)(1) plus the workstation security logic of 164.310(b) and (c) support treating copier placement as a security decision rather than a furniture decision. Output discipline is the second: pull printing or prompt collection keeps lab results from sitting in a shared tray, clearing the platen glass after scanning keeps the last patient's ID card from greeting the next user, and the minimum necessary standard at 45 CFR 164.502(b) is a reminder that staff should copy and print only what the task requires. Disposal of paper is the third: patient documents go in locked shred bins or a cross-cut shredder, never the recycling bin, because HHS disposal guidance treats readable PHI in ordinary trash as a violation regardless of intent. None of these controls cost much, and all of them are visible to an investigator or a patient standing at your front desk within thirty seconds of walking in.
Fax deserves its own paragraph, both because the copier usually is the fax machine and because misdirected faxes are among the most frequent small incidents in healthcare. A fax containing PHI that goes to a wrong number is a disclosure, and whether it is a reportable breach depends on the four-factor risk assessment at 45 CFR 164.402: what was disclosed, to whom it went, whether the information was actually viewed, and how well the risk was mitigated. A single misdial to another covered provider who confirms destruction may well score as low probability of compromise; a schedule of behavioral health appointments faxed to a stranger's home office is a different conversation. The preventive controls are unglamorous and effective: maintain verified speed-dial entries rather than hand-keying numbers, use cover sheets with a confidentiality notice and a callback number, confirm receipt for sensitive transmissions, and review the machine's transmission logs when something looks off. If you use an electronic fax service, recognize that the service transmits and often stores your faxes, which makes the vendor a business associate that must sign a business associate agreement before PHI flows through it. And if a misdirected fax or a lost device does turn into a reportable event, the clock runs from discovery: our free HIPAA breach notification deadline calculator maps your role and discovery date to the specific federal deadlines under 45 CFR 164.404 through 164.410, which is a far better first step than guessing.
Lease returns, vendor BAAs, and your copier security checklist
The vendor relationships around a copier fleet get less attention than the hardware and deserve more. The business associate definition at 45 CFR 160.103 covers any entity that creates, receives, maintains, or transmits PHI on behalf of a covered entity, and it can reach copier vendors in several postures. A service technician who pulls and replaces a failed drive is handling media that contains ePHI. A managed print vendor that remotely administers your devices and collects stored job data is maintaining systems that hold ePHI. A leasing company taking back a machine with an unsanitized drive is receiving PHI whether anyone intended it or not. The clean way to run these relationships is to decide, contractually and in advance, who is responsible for the data on every drive: require a business associate agreement under 45 CFR 164.308(b)(1) and 164.502(e) where the vendor's role involves PHI access, write drive sanitization or drive surrender into the lease terms so the hard drive is removed and left with you or verifiably wiped before the machine ships, and collect a certificate of sanitization or destruction for your records. The accountability specification at 164.310(d)(2)(iii) is your friend here: a simple log of which devices left, when, who took them, and what happened to their drives converts a lease return from an unknowable risk into a documented process. Keep those records six years, the retention period 45 CFR 164.316(b)(2)(i) applies to Security Rule documentation, because the question about a copier returned in 2024 may not arrive until 2029.
Pull all of this together and copier security stops being a trick question and becomes a short checklist. Inventory every device that copies, prints, scans, or faxes PHI and record its storage. Fold those devices into your risk analysis under 164.308(a)(1)(ii)(A) and address the findings. Turn on drive encryption and image overwrite where the hardware supports it. Harden the network side: change default passwords, patch firmware, encrypt scan and print traffic, and require authentication at the panel. Position machines away from public areas, keep output trays clear, and shred paper waste. Verify fax numbers and use cover sheets. Put drive handling in writing with every leasing and service vendor, with BAAs where the vendor role requires them, and collect sanitization certificates at every end of lease. Sanitize to NIST SP 800-88 standards before any device leaves your control, and log the disposition. Then train the people who stand at the machine, because every control on this list fails if the workforce does not know it exists: security awareness training is required by 45 CFR 164.308(a)(5) and privacy training by 45 CFR 164.530(b), and the habits that prevent copier incidents, collecting output immediately, clearing the glass, confirming a fax number, questioning a drive leaving the building, are exactly what that training should build. If your team's training is stale or undocumented, USA HIPAA's online certification covers device and media handling as part of the full Privacy and Security Rule curriculum, takes about two hours per person, and produces the dated certificates that let you prove the requirement is met. The copier already remembers everything it has seen. The point of a copier security program is to make sure you remember it first.