
Retire PHI-bearing hardware with the record to prove it.
For hospitals, integrated delivery networks, ambulatory clinics, and digital-health vendors retiring PHI-bearing hardware. Every storage-bearing device is sanitized to NIST SP 800-88 Rev. 1 and logged per drive — method, result, date, technician — feeding a serialized Certificate of Destruction your compliance office can file.
What healthcare teams need from ITAD.
Not marketing requirements — the ones your compliance office actually reviews when retired hardware leaves the building.
Sanitization verified per drive, not per pallet
Retired EHR endpoints, imaging workstations, and dictation systems often retain cached PHI long after the patient-record system is purged. An attestation that covers the pallet doesn’t cover the drive.
Documentation that survives a breach review
HIPAA’s disposal safeguard — 45 CFR §164.310(d)(2)(i) — expects documented media destruction. A generic “we recycled it” letter doesn’t answer a reviewer. A per-serial record does.
Custody across many pickup origins
Hospitals, satellite clinics, home-health offices, and BAA-covered third parties create dozens of pickup origins per refresh cycle. Every handoff needs a document, not a handshake.
A vendor your compliance file can defend
Vendor review asks who touches your media, under which certifications, audited by whom. The answers have to be third-party-verifiable — not self-declared.
What we run against each need.
Every line below is a verified, third-party-audited capability — no promises that aren’t written at a station on the Dallas floor.
NIST SP 800-88 Rev. 1, logged per drive
STN 04 · WIPE LOGOverwrite for HDDs, cryptographic erase for SSDs, physical destruction where required or where verification fails. Method, result, date, and technician recorded per drive. The wipe gate is a hard stop — no device advances without a completed, verified log. On-site shredding is available for media that can’t leave your premises.
Spec →Serialized Certificate of Destruction — included with every job
STN 05 · FINAL CERTOne line per serial: method, date, technician. The compliance crosswalk we hand auditors answers HIPAA with “PHI media destruction per 45 CFR §164.310(d)(2)(i)” — the disposal record your program files, retrievable when a reviewer asks. Our record on the process it documents: zero data incidents, ever.
Crosswalk →100% serialized chain of custody, five stages
BOL → FINAL CERTSealed, manifested transport on your schedule — custody transfers at your dock, on paper. Every pallet is reconciled against your manifest within 48 hours; discrepancies are flagged immediately, not discovered at settlement. No third-party warehousing.
Walk it →R2v3 — Responsible Recycling · #274644
SERI R2v3 StandardScope: IT Asset Disposition & Refurbishment, certified by Amtivo (ANAB-accredited) · SERI, independently audited annually, valid through March 2029 — verifiable on the SERI directory. Backed by ISO 9001, ISO 14001, and ISO 45001 management-system registrations.
Certs →What this does — and doesn’t — claim. No vendor can make a covered entity HIPAA-compliant, and we won’t claim to. VIG supports your compliance program: third-party-verified process controls, per-serial records, and the disposal documentation your safeguard requires. Your program stays yours; ours documents its disposal controls.
The paper trail, before you commit.
Five stages. One record per serial. Zero gaps. Each station below writes a named document — the same language our auditors see.
What lands in your file
Certificate records and controlled QC documents are viewable in the client portal. Nothing here is a download — originals are available for inspection on request.
Other industries we serve.

Ready to retire your fleet?
Send us your asset list and get a free valuation within one business day — no minimums, no commitment. Free pickup for 50+ unit lots in Texas. Serialized Certificate of Destruction included with every job.