Fire, Shred, Pulp: How to Properly Destroy Sensitive Documents

The HHS says shredding, burning, pulping, and pulverizing are the only way these records should be destroyed.

HIPAA
Fire, Shred, Pulp: How to Properly Destroy Sensitive Documents

Dumping medical records in an alley dumpster is a sure way to end up on the HHS Wall of Shame

Did you hear about the Texas hospital fined for their PHI-filled microfiche found in a park dumpster? What about Eureka Internal Medicine’s janitorial service that mixed recycled papers containing PHI with the regular trash?

Or the four pathology groups in Massachusetts forced to pay $140,000 because their business associate abandoned thousands of medical records at the dump?

Making sure PHI is correctly disposed seems like a no brainer, but I wouldn’t be blogging about it if it weren’t a serious issue.

In 60 seconds, learn the compliant way to destroy documents.

Ok so what did we learn?

Paper or other physical copies of PHI should NEVER be thrown away in a dumpster, recycle bin, or office trashcan. The HHS says shredding, burning, pulping, and pulverizing are the only way these records should be destroyed.

What about labeled prescription bottles? Do you use a business associate to dispose of waste? The HHS says you should keep the bottles in opaque bags until a business associate picks them up to destroy them. If you don’t have a business associate, then individually ripping off the labels and shredding them works too.

For electronic media containing PHI (like an old hard drive or backup tape), the HHS recommends using software or hardware products to overwrite media with non-sensitive data, exposing the media to a strong magnet, or physically destroying the media (disintegration, pulverization, melting, incinerating, or shredding).

Hard drives make excellent target practice!

So how do you keep this HIPAA requirement top of mind in your office?

  • Replace office trashcans with crosscut shredders
  • Tape a sign to the trashcan that states, ‘NO PHI!’
  • Make it a policy that all paper documents be shredded, just in case

See also: How to stay off the HHS naughty list

Join thousands of security professionals.

Subscribe Now

Get the Guide to HIPAA Compliance

Download

Get a Quote for HIPAA Compliance

Request a Quote