Case studies
What went wrong when retired hardware was handled badly, what the law and the standards ask for, and what a defensible program looks like. Written for the people who have to sign the policy.
In the field: a CJIS destruction day for the City of Mansfield
Eighty-seven assets from a storage room to a signed certificate in one day, including the ones that turned out to be empty
What a routine municipal job looks like when it is done right: an inventory by asset tag, media logged by serial, hard drives degaussed and shredded, SSDs disintegrated, empty chassis recorded as inspected, the city's representative witnessing, and a certificate dated the same day.
The FBI's Media Destruction Program
Right machines, wrong everything before them: what the DOJ Inspector General found in 2024 and 2025
The FBI's central destruction facility ran a degausser, a shredder, and a disintegrator to NSA and NIST standards, and the contractor met its deliverables. The Inspector General still found Secret-marked drives in torn shrink wrap on a warehouse floor, extracted hard drives nobody counted, pallets waiting up to 21 months, and 395 people with access. Every mistake was upstream of the shredder.
The Morgan Stanley Data Breach
Due to improper sanitization of IT hardware
How a global bank's decommissioned data-center hardware ended up in strangers' hands after a vendor was paid to wipe it, and what it cost: a $35 million SEC penalty, a $60 million OCC fine, and a $60 million class-action settlement.
HealthReach Community Health Center Data Breach
A wake-up call on proper data disposal and HIPAA compliance
Improperly disposed hard drives exposed the records of more than 115,000 patients at a community health center. What HIPAA requires at the end of a record's life, and how to build a disposal program that would have prevented it.
HAMR Drives and Classified Environments
Plan the disposition before you deploy the drives
Heat-assisted magnetic recording drives cannot be degaussed, and the NSA's February 2026 reissue of Policy Manual 9-12 now says incineration is the only approved sanitization for them. What that means for a cleared facility, and how to identify a HAMR drive before it becomes a problem.
Ohio's Data Protection Act and Data Destruction
The digital safe harbor law, and how documented media sanitization helps you qualify
Ohio's Data Protection Act gives businesses an affirmative defense against breach lawsuits when they follow a recognized cybersecurity framework. Documented NIST 800-88 sanitization is part of qualifying. A plain-language comparison, not legal advice.
NIST 800-88 Media Sanitization and the Reasonableness Standard
Why regulators judge disposal against reasonableness, and how a documented sanitization plan proves your decisions were defensible
Courts and regulators ask whether an organization acted reasonably. NIST 800-88 is how you show it. A comparison of the technical framework and the legal standard, and why an ITAD vendor's business model belongs in your risk assessment.
