Two issues here, one is retention of data, the other is secure deletion of data.
Straight off the bat I would say that if the data on the hard drive is important enough to warrant retention, then there should have been a backup in place already. I'm guessing maybe it's too late for should haves though?
As far as secure deletion goes, if EBME is responsible for maintenance (and therefore decommission) of the system then I suspect the data protection responsibility will also fall on them.
Manager has the ultimate responsibility although if the Tech was instructed and did not follow the instructions then I guess they are also culpable. Not that we have a blame culture in the NHS, of course.
As for actually having the work done, it might be something that can be done by the IT department, if there is one, or you may need to engage with a suitable contractor, or procure equipment to do the job in-house. If you don't already have an established process within your department, speak to the data protection officer to see if the organisation already has a facility for secure data deletion.
Unless you have a written agreement with your resale / disposal agency, it is not their responsibility to securely delete data. In any case, it is better to delete the data before it leaves the premises.