Skip to content
The lit frontage of the WesternTechSystems facility at night

Resources · Compliance

Disposal requirements, by the regulation you are actually being asked about

Buyers arrive at this subject holding a regulation, not an industry. These pages take each one, quote what it says from the primary source, and separate your legal obligation from the evidence a disposal provider can give you.

The thing worth knowing first

No US regulator certifies a disposal vendor

It is worth establishing this before anything else, because it reframes every vendor claim you will read on this subject — ours included. There is no federal certification, approval or accreditation of IT asset disposition or data destruction providers. Not under HIPAA, not under GLBA, not under FERPA, and not under the FACTA Disposal Rule. PCI DSS is not federal law at all.

The consistent architecture is the opposite: the regulated organization holds a non-delegable duty and must exercise its own diligence over the vendors it uses. HHS says so explicitly. The FTC writes the duty into the rule. EPA encourages third-party certification and issues none.

Where federal regulation comes closest to touching vendor credentials at all is the FACTA Disposal Rule, which lists requiring that the disposal company be certified by a recognized trade association or similar third party as one example of reasonable diligence — alongside reviewing an independent audit, taking references, and evaluating the provider's own security policies. One method among several, discharging your duty. It confers nothing on the vendor.

Which is why these pages are built the way they are. A certification we hold is evidence you can weigh. It is not a status that transfers, and any provider telling you otherwise has told you something useful about the rest of their claims.

The shared technical basis

Where NIST 800-88 fits into all five

Four of these five regulations name no sanitization method at all, and the fifth is prescriptive only for paper. What fills that gap in practice is NIST SP 800-88, which HHS references directly in its breach guidance and which has become the common vocabulary — Clear, Purge and Destroy — that auditors across all five frameworks now expect to see used correctly.

One currency note, because it is the sort of detail a technical reviewer will catch: NIST published Revision 2 as final in September 2025, superseding Revision 1, which is now withdrawn. HHS guidance still links the Revision 1 document, so you will encounter both citations in the wild. The practical position is to work to the current revision and to cite NIST SP 800-88 without a revision number when describing what HHS points to.

FAQ

Questions about compliance and certification

Is any IT asset disposition vendor certified by a US federal regulator?
No. We checked this against the agencies themselves rather than against industry commentary. HHS states that it does not certify any persons or products as HIPAA compliant and that private certifications do not absolve a covered entity of its obligations. EPA encourages electronics recyclers to seek third-party certification but issues none itself. NIST publishes guidance and accredits no sanitization vendors. The FTC requires your diligence rather than a credential. PCI DSS is not federal law at all. Every phrase of the form “HIPAA-compliant ITAD” or “PCI-certified disposal” describes something no agency issues.
Then what is R2v3 worth?
Quite a lot, provided it is described accurately. It is a private third-party certification against a published standard, audited by an accredited certifying body — not a legal status, and not a substitute for your own diligence. The FACTA Disposal Rule is explicit on this point in a way that is useful to both of us: it lists requiring that a disposal company be certified by a recognized trade association or similar third party as one acceptable method among several for discharging your due diligence. One method. Among several. And the duty stays yours.
Why does every page here have a section on what the rule does not say?
Because that section is the reason to trust the rest of the page. Compliance content in this industry is overwhelmingly written to make a regulation sound like it mandates whatever the vendor sells. Once you have read a page that tells you FERPA has no sanitization requirement at all, you have a reasonable basis for believing what the same page says about §99.10(e).
Do you have a page for our regulation?
Not necessarily. These five cover the requests we see most often. If your examiner, auditor or counsel is working from something else — a state student-privacy statute, a sectoral rule, an insurer's requirement — send us what has been asked for and we will tell you which of it we can evidence, including when the answer is none of it.

Send us your auditor's request.

Tell us what has been asked for and we will tell you which of it we can evidence — and which of it is yours to produce.