The HIPAA privacy and security rules require certain steps be taken during the destruction or removal of PHI (protected health information). These portions of the act mandate "reasonable safeguards to limit incidental, and avoid prohibited, uses and disclosures of PHI." What this means is that if HIPAA data is left in a trash can or an old hard drive that is replaced and discarded, HIPAA is violated.