What improper media destruction actually costs businesses in Yuma and Imperial Counties
In 2017, an IT consultant in Oklahoma bought some used hard drives at an online auction. When he powered them up, he found customer records belonging to Morgan Stanley Smith Barney. He emailed the bank to tell them.
That is how one of the largest financial institutions in the world learned that its retired equipment had been sold to strangers with the data still on it — a full year after the decommissioning project had been marked complete.
The Securities and Exchange Commission later found that Morgan Stanley had hired a moving and storage company with no experience in data destruction to decommission thousands of hard drives and servers containing the personal information of roughly 15 million customers, and then failed to monitor the work. The devices were sold to a third party and resold online with the data intact. The firm paid a $35 million SEC penalty. The Office of the Comptroller of the Currency had already fined it $60 million for related failures in decommissioning two data centers.
No hacker was involved. No firewall was breached. Someone simply threw away equipment that was still full of information.
Wiping is not destroying
There is a widespread and expensive assumption that a factory reset, a reformat, or a “secure erase” ends the story. For a meaningful category of media, it does not.
In September 2025, the National Institute of Standards and Technology published Revision 2 of SP 800-88, Guidelines for Media Sanitization, formally withdrawing the 2014 revision that most disposal policies still reference. The guidance is blunt about the limits of overwriting. For storage that uses overprovisioning and wear leveling — which describes essentially every modern solid-state drive, phone, tablet, and USB stick — overwriting achieves very little confidentiality protection, because the device cannot directly address all the areas where sensitive data may be retained. Spare cells and reserved blocks sit outside what any overwrite tool can reach.
Degaussing, the old standby for magnetic media, does nothing at all to flash memory. And on an SSD, no number of overwrite passes reliably reaches the standard NIST calls Purge.
This is not theoretical. A 2025 forensic study published through the Digital Forensics Research Conference examined 614 USB flash drives that had been purchased as new from low-cost suppliers. Researchers recovered non-trivial user data from 75 of them — more than 12 percent. The recovered files traced back to smart TVs, printers, voice recorders, and Android devices, evidence that memory chips had been harvested from discarded electronics and rebuilt into “new” drives without sanitization. If unused media can carry someone else’s data, a drive that spent four years in your accounting department certainly can.
There is a hierarchy here that matters. NIST distinguishes Clear (protects against simple recovery), Purge (defeats laboratory recovery), and Destroy (renders the media unusable). For media that is leaving your control — sold, recycled, returned on a lease, handed to a vendor — Destroy is the only outcome that does not depend on trusting a firmware command you cannot audit.
You probably will not find out
Here is the part that makes this risk so easy to underestimate.
If you look at federal breach reporting, improper disposal barely registers. In all of 2025, exactly one improper-disposal incident was reported by a HIPAA-regulated entity — though it affected more than 35,000 people. It would be easy to read that number and conclude the problem has been solved.
It hasn’t. What that number actually measures is detection, and disposal breaches are almost impossible to detect from the inside.
Consider how the known cases came to light. Cornell Prescription Pharmacy, a single-location compounding pharmacy in Denver, was investigated only because a local news outlet tipped off federal regulators about documents in an unlocked container. Kaiser Permanente’s statewide case in California began when district attorneys’ offices sent undercover inspectors to physically go through unsecured dumpsters at sixteen facilities. Morgan Stanley found out from a stranger’s email.
A ransomware attack announces itself. A phishing compromise leaves logs. A hard drive sold on an auction site with your client list on it generates no alert, no ticket, and no incident report. The organization continues to believe its disposal process works right up until the moment someone else tells them it doesn’t — if anyone ever does.
Low reported frequency is not low risk. It is low visibility.
What it costs
IBM’s 2026 Cost of a Data Breach Report puts the global average breach at a record $4.99 million and the U.S. average at $11.5 million. Healthcare topped the industry rankings for the thirteenth consecutive year at $6.64 million per incident.
Those figures describe large enterprises, and if you run a twelve-person clinic in El Centro or a family-owned logistics firm in San Luis, they may feel like someone else’s problem. So look instead at what disposal failures have cost organizations the size of yours.
|
Organization |
What happened |
Penalty |
|
Cornell Prescription Pharmacy |
1,610 patient records left unshredded in an unlocked container at a single-location pharmacy |
$125,000 — roughly $78 per record |
|
Parkview Health |
71 boxes of patient records left at the end of a driveway |
$800,000 |
|
Kaiser Permanente (California) |
Over 10,000 paper records covering 7,700 patients found in unsecured dumpsters, alongside hazardous waste |
$49 million |
|
Morgan Stanley |
Thousands of drives and servers decommissioned by an unqualified vendor and resold with data intact |
$95 million in regulatory penalties |
Cornell is the one to sit with. One location. One pharmacy. No cyberattack. Roughly $78 per record, plus a corrective action plan requiring new policies, procedures, and staff training. Multiply that against your own patient list, client file, or personnel archive.
The regional picture
Southwestern Arizona and the Imperial Valley are not low-risk simply because they are not Phoenix or San Diego.
|
Imperial County, CA |
Yuma County, AZ |
|
|
Population (2024) |
181,724 |
220,310 |
|
Employer firms |
2,060 |
2,632 |
|
Nonemployer establishments |
10,768 |
12,263 |
That is roughly 402,000 residents and nearly 28,000 businesses and sole proprietorships across the two counties — and the composition of that economy concentrates risk in three specific ways.
Healthcare is the region’s largest industry. In Imperial County, Health Care and Social Assistance employs more people than any other sector, ahead of retail and public administration, anchored by El Centro Regional Medical Center and Pioneers Memorial Healthcare District. The costliest breach sector in the country is also the valley’s biggest employer.
Defense is the region’s second economy. Yuma hosts both Marine Corps Air Station Yuma and U.S. Army Yuma Proving Ground. Every supplier, contractor, and subcontractor handling controlled unclassified information carries media sanitization obligations under DFARS 252.204-7012 and NIST SP 800-171. Note that the Department of War suspended CMMC Phase II in July 2026 pending a reform review — but the underlying cybersecurity requirements, Phase I self-assessments, and DFARS obligations all remain in force. The paperwork changed. The duty did not.
Cross-border trade and government generate enormous record volume. Customs operations, agricultural payroll for a seasonal workforce, and county administration produce exactly the categories of information that disposal statutes govern.
The Arizona gap, and California’s opposite problem
If you operate in Yuma County and you have read Arizona’s disposal law, you may have drawn a dangerously wrong conclusion.
A.R.S. § 44-7601 requires businesses to destroy or redact records containing a name combined with a Social Security number, card number, retirement account, bank account, or driver license number. Penalties run $500 for a first violation, $1,000 for a second, and $5,000 for a third. Modest enough to shrug at.
But read subsection F. The statute applies only to paper records and paper documents.
Arizona’s shredding law does not cover your hard drives. It does not cover backup tapes, phones, copier drives, or thumb drives. It also exempts HIPAA covered entities, financial institutions under Gramm-Leach-Bliley, and consumer reporting agencies entirely.
None of that means electronic media disposal is unregulated in Arizona. It means the obligations sit somewhere else — in HIPAA’s Security Rule, the FTC Safeguards and Disposal Rules, GLBA, and defense contracting requirements — and in A.R.S. § 18-552, where the Attorney General may impose civil penalties up to the lesser of $10,000 per affected individual or total economic loss, capped at $500,000 per breach. The cheap-looking penalty in the shredding statute is not the ceiling. It is a narrow floor under one type of media.
California runs the other direction. Civil Code § 1798.81 imposes a destruction obligation on any business holding customer records, with no revenue or volume threshold at all. And as of January 1, 2025, CCPA statutory damages were adjusted for inflation to not less than $107 and not more than $799 per consumer per incident, with administrative fines reaching $2,663 per violation and $7,988 per intentional violation.
Run that against a modest Imperial County practice holding 5,000 patient records. Statutory exposure alone — before notification costs, forensics, legal fees, or any federal penalty — ranges from $535,000 at the floor to nearly $4 million at the ceiling.
And enforcement here is genuinely local. The Kaiser case was built by six county district attorneys inspecting dumpsters. Arizona’s statute expressly authorizes the county attorney in the county where records were improperly discarded to bring an action. This is not a distant federal risk. It is a jurisdiction that ends at your loading dock.
What defensible destruction looks like
The common thread in every case above is not bad intent. It is an undocumented process and an unverified outcome.
NIST Rev. 2 draws a distinction worth borrowing. Verification asks whether you did what you planned — the tool ran, it reported success. Validation asks whether that was enough for the sensitivity of the data and the type of media involved. A process can pass the first and fail the second completely. Degaussing an SSD completes successfully as an operation and leaves every byte in place.
A destruction program that will survive an audit, a district attorney, or a plaintiff’s attorney has four properties:
- Physical destruction for media leaving your control, matched to the media type — not a firmware command you cannot independently confirm.
- Documented chain of custody from the moment material leaves your building. Morgan Stanley’s failure was fundamentally a vendor oversight failure.
- Serialized certificates of destruction recording date, device identifiers, method, and operator. The certificate is the artifact regulators actually ask to see.
- Coverage across every medium you actually hold — paper, hard drives, SSDs, tape, film, phones, and the storage inside copiers and multifunction printers. HIPAA protects health information in any form, and paper and film were still involved in 5.6 percent of reported healthcare breaches last year.
A word about “NIST certified”
You may see destruction vendors advertise “NIST certified” equipment. Be careful with that phrase, because there is no such thing.
NIST publishes guidelines. It does not operate a certification program, an accreditation body, or a registry for destruction equipment or destruction companies. SP 800-88 is a standard you conform to, not a credential you receive. The only U.S. government program that formally evaluates destruction equipment is the NSA/CSS Evaluated Products List — and that regime exists for classified national security information under NSA/CSS Policy Manual 9-12, not for commercial HIPAA, GLBA, or FACTA work.
What actually matters for a private-sector business is whether the destruction method is appropriate to the media type and the sensitivity of the data, and whether the outcome is documented well enough to defend.
The federal rules are explicit on this point. The FTC Disposal Rule permits a business to satisfy its obligations by contracting with a record destruction company after due diligence — and it lists several ways to conduct that diligence: reviewing an independent audit of the company’s operations, obtaining references, requiring certification by a recognized trade association, evaluating the company’s information security policies, or taking other appropriate measures to determine competency and integrity. The rule states plainly that these examples are illustrative only, and not an exclusive or exhaustive list.
In other words: an independent audit of a destruction provider’s process is a first-class form of due diligence in the eyes of the regulator. Ask any vendor how their work is verified and what documentation you receive. Those two answers matter far more than a certification logo.
How TRZ Environmental helps
TRZ Environmental provides secure destruction of paper documents, electronic media, film, and other record-bearing materials for businesses across Yuma and Imperial Counties.
We destroy to NIST SP 800-88 Rev. 2 specifications. Media is inventoried on receipt, tracked under documented chain of custody, and physically destroyed by a method matched to the media type — so that recovery is not a question of effort, equipment, or firmware you cannot audit.
We offer independent third-party verification. Rather than asking you to take our word for it, we can provide independent confirmation of our destruction process — the same form of due diligence the FTC Disposal Rule names first among its examples.
You receive a serialized certificate of destruction. Not a receipt. A record that identifies the assets by serial number, the method applied, the standard met, the date, location, and operator — the document an auditor, a contracting officer, a district attorney, or opposing counsel will actually ask to see.
We destroy the media rather than trusting it to forget. That distinction is the entire difference between a retired asset and a liability sitting in a stranger’s computer.
Contact jaime@trzenvironmental for a quick assessment


Leave a Reply