Excess IT Hardware operates an EPA-registered processing facility (EPA ID FLR000269027) with a documented chain of custody, NIST 800-88 referenced data destruction methods, and a zero-landfill pathway through an R2 Certified downstream chain. Whether you are retiring 50 desktops or decommissioning a data center, every asset is tracked, sanitized or destroyed, and reported with a per-asset audit trail.
Most data breaches that begin with retired hardware never make headlines, but they do show up in compliance audits and HHS resolution agreements. The HHS Office for Civil Rights has issued multi-million-dollar settlements tied directly to leased equipment returned without sanitization and to retired drives that resurfaced on secondhand markets. HIPAA penalties reach $50,000 per violation with a $1.5 million annual cap per category. PCI DSS penalties run $5,000 to $100,000 per month. GDPR exposure for organizations handling EU resident data reaches 4% of global annual revenue.
The deeper risk is reputational. A single retired laptop containing patient records, payment data, or unreleased financial filings undoes years of brand trust. Computer disposal is not a procurement line item. It is a controls boundary.
Excess IT Hardware closes that boundary with documented procedures, an EPA-registered processing facility, and a sanitization workflow tied to recognized federal standards. Read the full ITAD compliance policy for the complete procedural reference.
A retired desktop or laptop is three things at once: a data risk, a material asset, and an environmental hazard. Effective computer disposal addresses all three in the same workflow.
Data carriers in scope: SSDs, NVMe drives, traditional spinning HDDs, embedded flash on motherboards, BIOS configuration data, optical media, and any remaining tape drives. Even after a quick format, forensic recovery tools can rebuild file structures from residual magnetic or charge-state remnants. Reformatting is not destruction.
Material assets: a typical mid-range business desktop contains roughly 2 grams of copper in cabling and components, recoverable aluminum in chassis, traces of gold and silver in connectors, and rare earth elements in magnets and capacitors. Recovery offsets program cost when handled properly.
Environmental hazards: lead in older CRT monitors, mercury in some flat-panel backlights, brominated flame retardants in plastics, lithium in batteries. Every state restricts landfill disposal of these materials. Florida’s Electronic Waste Recycling Act, California’s Electronic Waste Recycling Act, and federal RCRA universal waste rules all apply depending on quantity and origin.
Every project flows through a controlled workflow with documentation at each handoff. Pickup is scheduled through nationwide pickup logistics. Assets are sealed, manifested, and transported under controlled chain of custody. At intake, every device is scanned and entered into our asset tracking system with serial number, make, model, condition, and disposition path.
Data-bearing media is segregated and routed to the appropriate destruction method based on your stated policy. Reusable equipment moves to test and refurbishment for asset recovery. Non-working assets move to disassembly and material recovery. Materials route to an R2 Certified downstream chain consistent with our zero-landfill policy. The processing facility itself is registered with the U.S. Environmental Protection Agency under EPA ID FLR000269027 and operates in compliance with the Florida Electronic Waste Recycling Act.
We process the full range of computer equipment retired from business environments:
For the full inventory of accepted electronics across all product categories, see items we accept. When in doubt, send a list and we will confirm.
Different industries operate under different regulatory anchors. The destruction method, documentation, and chain of custody you need depend on which frameworks apply. The following mapping is how compliance officers translate their environment into a computer disposal workflow.
HIPAA (Health Insurance Portability and Accountability Act). Covered entities and business associates retiring devices that stored ePHI need NIST 800-88 referenced sanitization with documented verification. Excess IT Hardware operates with HIPAA-trained technicians and executes Business Associate Agreements where required. (Note: a company cannot be HIPAA Certified. HIPAA compliance is a matter of trained personnel, executed BAAs, and documented procedures.)
PCI DSS (Payment Card Industry Data Security Standard). Requirement 9.8 mandates rendering cardholder data unrecoverable when media is no longer needed. Software erasure with verification, hard drive shredding, or crushing all satisfy 9.8 when properly documented.
GLBA (Gramm-Leach-Bliley Act) Safeguards Rule. Financial institutions must protect non-public personal information through the asset lifecycle. Documented destruction of customer data on retired hardware is part of the Safeguards Rule program documentation.
SOX (Sarbanes-Oxley Act). Public companies must maintain controls over financial reporting systems. Retired servers, workstations, and storage that touched ERP, GL, or financial close systems need documented destruction tied to the IT general controls audit.
FACTA (Fair and Accurate Credit Transactions Act) Disposal Rule. Anyone holding consumer report information must take reasonable measures to dispose of it. Verification of destruction is the operative reasonable measure.
NIST SP 800-88 Rev. 1. Federal agencies and contractors handling controlled unclassified information default to NIST 800-88 sanitization categories: Clear, Purge, and Destroy. Excess IT Hardware destruction methods map to these categories on the certificate.
Florida Electronic Waste Recycling Act and federal RCRA Universal Waste rules. Govern the handling and downstream disposition of e-waste regardless of data sensitivity. Compliance with these is structural, not optional, for any disposal vendor.
Computer disposal without data destruction is not disposal. It is a breach in slow motion. Excess IT Hardware offers four destruction methods, each appropriate for a specific class of media and a specific level of regulatory exposure. Every method is documented on the Certificate of Recycling and Data Security.
Software-based data erasure uses NIST SP 800-88 referenced overwrite patterns and DoD 5220.22-M-style methods to permanently sanitize functional drives. Verification logs record drive serial number, sanitization start and stop time, method used, and final pass result. Appropriate for assets continuing to resale or redeployment.
On-site or off-site hard drive shredding physically destroys media into particles small enough that no commercial recovery technique can reconstruct sectors. Appropriate for high-sensitivity data, end-of-life drives, drives that fail erasure verification, and any policy that mandates physical destruction.
On-site hard drive crushing applies hydraulic force to deform platters and bend the spindle past any mechanical recovery threshold. Useful when shredding is not available on site, when policy requires destruction in your facility before transport, or when crushing is sufficient under the data classification level.
Magnetic media degaussing exposes drives and tapes to a high-strength magnetic field that erases recorded data permanently and renders the drive non-functional. Used for legacy magnetic media including LTO tape and certain spinning drives where electrical sanitization is impractical.
Excess IT Hardware coordinates nationwide pickup across the contiguous United States from the Florida processing facility, with vetted partner logistics for routes outside primary lanes. Single project, single point of accountability, no handoff to unknown subcontractors.
Logistics services include: scheduled pickup at headquarters, branches, or data centers; palletization and secure containerization on site; sealed transport with manifest at every transfer point; tractor-trailer or box-truck capacity matched to project size; and multi-site project coordination with consolidated reporting. For multi-state projects, a single master certificate ties every site to one auditable record set.
Equipment with remaining market value enters our asset recovery program. Hardware is tested, graded, sanitized to NIST 800-88, and remarketed through wholesale, retail, and parts channels. Net proceeds are returned to your organization on a revenue-share basis, often offsetting the full cost of the disposal program for organizations retiring late-cycle business hardware.
Larger-scale projects move into our ITAD engagement: full IT Asset Disposition with policy alignment, settlement reporting, and disposition routing across reuse, resale, parts harvest, and material recovery. Data center scale projects are handled through data center decommissioning with on-site rack pulls, secure cage handling, and palletized return logistics.
Where program goals include charitable distribution or community impact, equipment can be routed through our positive impact and donations program for sustainability reporting credit and ESG alignment.
Step 1: Tell us what you have.
Share location, estimated unit count, equipment types, and your data destruction policy. We confirm scope and produce a quote.
Step 2: Schedule pickup.
We coordinate logistics, timing, and any on-site requirements (loading dock, badge access, after-hours windows, palletization, secure cage handling for data center projects).
Step 3: Sealed transport with chain of custody.
Equipment is manifested, sealed in transport, and tracked from pickup point to processing facility. No unknown subcontractors, no unmanifested transfers.
Step 4: Intake, scan, and inventory.
Every device is scanned at intake. Serial number, make, model, and condition are entered into asset tracking. Data-bearing media is segregated.
Step 5: Data destruction per policy.
Drives are sanitized, shredded, crushed, or degaussed based on your stated policy. Each operation is logged. Verification confirms successful destruction or routes the drive to a higher-rigor method.
Step 6: Disposition routing.
Reusable equipment moves to test, grade, and remarketing. Non-working hardware moves to disassembly and material recovery. Materials route to an R2 Certified downstream chain consistent with our zero-landfill policy.
Step 7: Reporting and certificates.
You receive the Certificate of Recycling and Data Security, the per-asset destruction record, and access to the online reporting portal. Records are retained for the regulatory window applicable to your industry.
Use a vendor with documented chain of custody, NIST 800-88 referenced data destruction, an R2 Certified downstream chain for material recovery, and a per-project Certificate of Recycling and Data Security. Reformatting drives or sending equipment to general waste haulers does not meet any current regulatory standard.
No. Standard delete and format operations remove file system pointers but leave underlying data recoverable with widely available forensic tools. Permanent removal requires NIST 800-88 referenced overwrite (multi-pass software erasure with verification) or physical destruction by shredding, crushing, or degaussing.
NIST Special Publication 800-88 Revision 1 is the federal Guidelines for Media Sanitization. It defines three sanitization categories (Clear, Purge, Destroy) and the methods that satisfy each. HIPAA security officers, PCI DSS QSAs, SOX auditors, and government contracting officers all expect to see NIST 800-88 referenced in disposal documentation.
Excess IT Hardware operates a zero-landfill pathway by routing materials through an R2 Certified downstream chain. R2 certification applies to the downstream processing partners that handle final material recovery.
Yes. Every computer disposal project closes with a Certificate of Recycling and Data Security covering every processed asset, plus a per-asset destruction record with serial number, sanitization method, and date. Records are accessible through the online reporting portal.
Yes. Nationwide pickup is coordinated from our West Palm Beach processing facility with vetted logistics partners for routes outside primary lanes. Multi-site projects are coordinated under a single master engagement with consolidated reporting.
For organizations retiring late-cycle business hardware (typically two to four years from retail release), remarketing proceeds frequently offset the full cost of the disposal program and sometimes generate net positive returns. Older or specialized equipment is evaluated on a per-project basis.
Healthcare, financial services, legal, education, technology, and government contractors face the strongest regulatory anchors. In practice, any organization with employees, customer records, financial systems, or proprietary information benefits from formal computer disposal.
Computer disposal protects your data, supports compliance, and reduces environmental impact. Excess IT Hardware delivers all three with documentation that holds up to audit. From pickup through final disposition, every asset is tracked, destroyed per policy, and reported with a serial-level audit trail.
Ready to start: schedule a pickup online, call (561) 600-8656, or request a quote and a project specialist will respond within one business day.