Book online or chat with usAnswered 24/7Licensed, insured & bondedSchedule a Consultation
Request serviceUrgentConsultation

Managed IT

Data Destruction Services with NIST SP 800-88 Media Sanitization

Clear, purge or destroy matched to each drive, a certificate for every serial number, and a legal hold check before anything is wiped.

Veteran-LedSDVOSB
CertificateEvery Drive
Chain of CustodyEvery Device
AZ DPS PI LicenseNo. 1759795
Arizona-BasedCasa Grande

When you need data destruction services

Data destruction services make sure the data on a retired laptop, server, phone or copier cannot be recovered after the device leaves your hands. Honeybadger Solutions sanitizes media to NIST SP 800-88, issues a certificate for each drive, and ties the work to your asset records as part of our managed IT services. Because we also do digital forensics, we know how much data a careless wipe leaves behind.

A device usually leaves your control at a predictable moment, and that is when data walks out with it:

  • A laptop or desktop refresh, or an employee leaving the company.
  • Returning leased equipment, including copiers and printers with internal drives.
  • Selling, donating or recycling old servers and network storage.
  • Closing or moving an office.
  • Sending a failed drive back under warranty.

Clear, purge or destroy: which does your media need?

NIST published SP 800-88 Revision 2, Guidelines for Media Sanitization, in September 2025. It replaced Revision 1 from 2014, which NIST withdrew the same month. It defines three methods, and the right one depends on the sensitivity of the data, the type of media and whether you want to reuse the device.

Method What it protects against Can the device be reused? Typical use
Clear Simple recovery through the normal interface, such as undelete tools Yes Lower-sensitivity data on devices staying inside the organization
Purge Recovery even with state-of-the-art laboratory techniques Usually Devices being sold, donated, returned or redeployed; NIST prefers purge over clear when possible
Destroy Recovery with state-of-the-art laboratory techniques; the media cannot store data again No Failed or obsolete drives and the most sensitive data

Why do SSDs need different handling than hard drives?

Solid-state drives spread writes across spare memory cells, a design called wear leveling. NIST says that makes it infeasible to overwrite every area that once held data, and that old multi-pass overwrite methods on SSDs give very little protection. Degaussing, which uses a strong magnetic field, should not be used on SSDs at all. For flash media we use the drive’s built-in sanitize commands or cryptographic erase, chosen with the IEEE 2883 standard NIST points to, or we move to destruction.

Destruction is not as simple as it sounds either. NIST notes that drilling a hole or bending a drive may leave parts of it readable, and that as data density rises, shredding and pulverizing should be avoided for anything but the lowest-sensitivity data. We match the method to the media instead of using one tool for everything.

What rules apply when you dispose of devices?

The FTC Disposal Rule, 16 CFR Part 682, in effect since June 1, 2005, covers businesses holding consumer report information. It defines disposal to include the sale, donation or transfer of computer equipment that stores that data, and it requires reasonable measures, such as erasing or destroying electronic media so the information cannot practicably be read or reconstructed. For health care, HHS points to the HIPAA Security Rule’s disposal and media re-use requirements at 45 CFR 164.310(d)(2) and refers organizations to NIST SP 800-88.

Arizona’s records disposal statute, A.R.S. 44-7601, bars discarding records that pair a name with a Social Security, card, account or driver license number without redacting or destroying them, but by its own terms it applies only to paper records. Electronic media is covered by the federal rules above, your contracts, and Arizona’s breach notification law if a lost or resold drive exposes personal information.

Why check for a litigation hold before destruction?

Under Federal Rule of Civil Procedure 37(e), if electronically stored information that should have been preserved for litigation is lost because a party did not take reasonable steps, a court can order measures to cure the harm, and if it finds intent to deprive the other side, it can presume the lost data was unfavorable or even dismiss the case. A routine laptop wipe during a dispute can look like destruction of evidence. Before we sanitize anything, you confirm in writing that no legal hold, preservation letter or investigation covers the device. If one does, we can make a forensic image first and keep it under chain of custody.

What we deliver

Three services cover the end of a device’s life, from the inventory to the certificate to the replacement.

Media sanitization and certificate

Priced per drive, for drives that are accessible and healthy. We identify the media type, apply the right clear or purge technique, verify the result, and issue a certificate per drive with make, model, serial number, method, technique, tool and version, verification method, date and the person responsible, following the fields NIST SP 800-88 lists.

Physical destruction for failed drives

Drives that are dead, damaged or too sensitive to reuse go to physical destruction with chain of custody and a matching certificate. Destruction and transport are quoted separately from sanitization.

Asset lifecycle and procurement support

Hourly help with inventory reconciliation, refresh planning, warranty tracking and disposal coordination, so every serial number that left is matched to a certificate. NIST CSF 2.0 lists managing hardware and data throughout their life cycles as a core outcome (ID.AM-08).

Secure device rebuild

Priced per device with a capped block of technician time: a clean operating system install, current patches, security configuration and a handoff, so a wiped laptop can go back into service.

How data destruction services work

  1. Request online. Tell us how many devices, what types (laptops, desktops, servers, phones, copiers, loose drives) and whether any are failed.
  2. Hold check and approval. An authorized person confirms in writing that the devices are company-owned and not under a legal hold or investigation.
  3. Inventory and custody. We record each device and drive by serial number. Devices are shipped to us under chain of custody or handled onsite where needed.
  4. Choose the method. Hard drives, SSDs, phones and embedded storage each get a method suited to the media and the sensitivity of the data.
  5. Sanitize and verify. We run the sanitization, then check the result before we call the drive done.
  6. Certificate. You receive a certificate for each drive and a summary that matches your asset list.
  7. Next step. The device is rebuilt for reuse, returned to you, or sent for destruction or recycling.

Authority, consent and legal limits

We sanitize only devices the requester owns or is authorized to dispose of, and we keep the written approval with the certificates. For employee-owned phones and laptops, we remove company data only through the work profile or management tools covered by your device policy; we do not wipe another person’s personal device.

We refuse to destroy data that is under a legal hold, a preservation demand, a subpoena or an active investigation, and we refuse any request whose purpose is to keep information from a court, a regulator or an opposing party. When there is doubt, we ask you to get counsel’s sign-off first. This is general information, not legal advice.

How it is priced

Our data destruction services are priced in words here and in numbers on your written quote. Sanitization is priced per drive, with a job minimum, for accessible and healthy drives. Physical destruction and transport for failed or high-sensitivity drives are quoted separately. Asset lifecycle support is billed hourly with a short minimum. A secure rebuild is a fixed price per device with a stated block of technician time.

The main cost drivers are the number of drives, how many are SSDs or embedded storage that need special handling, how many have failed, and whether devices are shipped to us or handled onsite.

Included Quoted separately
Sanitization of accessible, healthy drives with verification Physical destruction and transport
A certificate for each drive and a summary report Forensic imaging before disposal
Written hold check and chain of custody records Shipping kits and onsite travel
Operating system, patches and security setup on a rebuild Data migration from the old device

Mistakes to avoid before you contact us

  • Trusting a factory reset. On many devices a reset clears pointers, not data. It may meet the clear method at best.
  • Drilling a hole and calling it destroyed. NIST warns that partial damage can leave readable areas.
  • Forgetting hidden storage. Copiers, printers, phones, firewalls, USB drives and backup media all hold data.
  • Returning leased gear as is. Check the lease terms, then sanitize before it goes back.
  • Skipping the certificate. Without a per-drive record you cannot prove what happened to a device if a regulator or client asks.
  • Wiping during a dispute. Confirm there is no legal hold first; a lost device record can cost far more than the device.

Who this is for

  • Medical and dental practices
  • Law and accounting firms
  • Lenders, landlords and employers using consumer reports
  • Schools and nonprofits
  • Businesses refreshing laptops or closing offices
  • IT managers retiring servers and storage

Why the online request is faster

Choose data destruction on the online request form and it goes straight to the lead who handles IT and forensics work. Your device list and hold confirmation arrive together, so we can quote and schedule without phone tag.

Frequently asked questions

Is a factory reset enough before we sell a laptop?

Often not. NIST SP 800-88 Rev. 2 treats many resets as the clear method at best, and for devices leaving your organization it prefers purge. We use the drive’s sanitize or cryptographic erase functions and verify the result.

What does the certificate of sanitization show?

Each certificate lists the make, model and serial number, the media type, the method and technique used, the tool and version, how the result was verified, and who did the work and when, following the fields NIST lists.

Can you sanitize SSDs and phones, not only hard drives?

Yes. SSDs and phones need different techniques than spinning hard drives because overwriting does not reach all of their memory. We choose the method by media type.

What happens to drives that have failed?

A drive that cannot be read cannot be sanitized by software. It goes to physical destruction with chain of custody and its own certificate, quoted separately.

Do data destruction services include shredding?

When destruction is the right method, yes, as a separately quoted step. NIST now cautions that shredding and pulverizing suit only lower-sensitivity data on dense modern media, so we pick the destruction technique to match the data.

What if a device might be needed for a lawsuit?

Then it should not be wiped. We require written confirmation that no legal hold covers each device. If one does, we can make a forensic image first and keep it under chain of custody.

Related guides

We sanitize only devices the requester owns or may dispose of, after written confirmation that no legal hold or investigation covers them.

Sources: NIST SP 800-88 Rev. 2, FTC Disposal Rule, 16 CFR 682, HHS HIPAA disposal FAQ, A.R.S. 44-7601, FRCP 37(e).

Retire devices without leaving data behind

Request this service online with your device list, and our IT lead will quote and schedule it. Picking the service on the form routes it straight to the right specialist, so there is no phone tag. If a device with sensitive data is lost or stolen, use our urgent intake form.