What Documents Should Businesses and Healthcare Facilities Always Shred?
- Sam Spaccamonti

- 2 hours ago
- 9 min read
TL;DR / Quick Answer: Businesses and healthcare facilities should securely shred documents containing sensitive personal, financial, employee, customer, or patient information once their required retention period has ended. Common documents include employee records, financial statements, tax documents, customer data, contracts, patient records, lab results, billing records, prescription information, and other documents containing Protected Health Information (PHI) or consumer information covered by regulations such as HIPAA and FACTA. |
The Regulatory Framework Behind the Obligation to Shred
Businesses and healthcare facilities may have legal obligations to securely destroy sensitive information under federal regulations such as HIPAA, FACTA, and GLBA. The specific requirements depend on the type of information an organization handles and the industry it operates in.
1. Health Insurance Portability and Accountability Act (HIPAA) applies to covered entities, including hospitals, clinics, physicians, dentists, pharmacies, health plans, and healthcare clearinghouses, as well as their business associates. HIPAA's Privacy Rule requires that Protected Health Information be destroyed so that it is unreadable, indecipherable, and otherwise cannot be reconstructed.
For paper records, this means cross-cut or micro-cut shredding, incineration, pulverization, or pulping. A standard strip-cut shredder does not meet the standard. HIPAA requires covered entities to retain compliance-related documentation for at least six years, though actual medical records are governed by state law, which typically requires retention for five to ten years and longer for minor patients.
2. Fair and Accurate Credit Transactions Act (FACTA), the Disposal Rule applies to any business that uses consumer reports, including employers running background checks, landlords, retailers, financial institutions, and virtually every other type of business in America. FACTA requires consumer information to be burned, pulverized, or shredded so it cannot be read or reconstructed.
Unlike HIPAA, FACTA is not limited to healthcare. It reaches every business that holds consumer financial or personal data, which in practice means almost every business operating in the United States.
3. Gramm-Leach-Bliley Act (GLBA) applies to financial institutions broadly defined: banks, credit unions, insurers, mortgage lenders, investment advisors, tax preparers, payday lenders, financing auto dealers, and debt collectors. GLBA requires these institutions to implement safeguards to protect customer financial information, including secure disposal at the end of the information's useful life.
Together, these three frameworks establish that the obligation to shred is not discretionary. The question is never whether to shred sensitive documents. It is knowing exactly which documents qualify and ensuring they never reach a trash can or recycling bin without being destroyed first.
What Documents Should Businesses Always Shred?

Businesses should shred any document containing sensitive personal, financial, customer, employee, or proprietary information once it reaches the end of its required retention period.
1. Employee Records and Human Resources Files
Employee and HR records contain sensitive personal and employment information. Businesses should securely destroy these records once the applicable retention period has ended.
Documents to shred include:
Employment applications
Resumes and job applications
Direct deposit forms
W-4 and I-9 forms after the applicable retention period
Performance reviews
Employee disciplinary records
Benefits enrollment forms
Termination paperwork
Copies of identification documents
Other personnel records containing sensitive employee information
2. Financial and Accounting Records
Financial and accounting documents can contain sensitive business, banking, payment, and tax information. These records should be securely destroyed after the applicable retention period.
Documents to shred include:
Bank statements
Credit card statements
Accounts payable and receivable records
Invoices
Tax documents after the applicable retention period
Financial reports
Payment records
Voided checks
Deposit records
Documents containing bank account or financial information
3. Business Contracts and Legal Documents
Business contracts and legal records may contain confidential information about clients, vendors, transactions, and business operations. These documents should be securely destroyed when they are no longer required to be retained.
Documents to shred include:
Expired contracts
Vendor agreements
Client agreements
Non-disclosure agreements (NDAs)
Legal correspondence
Settlement documents
Internal legal records
Confidential proposals
Documents containing sensitive business terms
Outdated copies of legal documents
4. Customer and Client Data
Customer and client records can contain personally identifiable information (PII), financial details, and other sensitive information that should not be left in regular trash.
Documents to shred include:
Customer applications
Account information
Customer contact information
Copies of identification documents
Credit applications
Customer correspondence
Account statements
Consumer reports
Forms containing Social Security numbers
Documents containing payment or financial information
5. Proprietary Business Information and Intellectual Property
Confidential business information and intellectual property can create significant risks if they are improperly discarded. Secure destruction helps prevent sensitive business information from being accessed by unauthorized individuals.
Documents to shred include:
Business plans
Product development documents
Research and development materials
Trade secret information
Internal strategy documents
Confidential pricing information
Marketing plans
Unreleased product information
Internal reports
Confidential client or vendor information
6. Payroll Records
Payroll records contain sensitive employee information, including compensation, banking, tax, and benefits information. Businesses should securely destroy these records once their applicable retention requirements have been met.
Documents to shred include:
Payroll reports
Pay stubs
Wage records
Time sheets
Direct deposit information
Payroll tax documents
Employee compensation records
Salary information
Benefits deduction records
Other payroll documents containing sensitive employee information
What Documents Should Healthcare Facilities Always Shred?
Healthcare facilities should securely destroy documents containing Protected Health Information (PHI) once the applicable retention period has ended. This includes medical records, lab results, billing documents, prescription information, patient intake forms, appointment schedules, and other records that identify a patient and relate to their healthcare.
1. Patient Medical Records and Clinical Documentation
Patient medical records contain Protected Health Information (PHI) and other sensitive healthcare information. Healthcare facilities should securely destroy these records when the applicable retention requirements have been met.
Documents to shred include:
Patient medical records
Physician notes
Nursing notes
Treatment records
Clinical documentation
Patient histories
Discharge summaries
Medical forms containing PHI
Copies of patient identification documents
Other patient records containing protected information
2. Lab Results and Diagnostic Reports
Laboratory and diagnostic documents can contain identifiable patient information and sensitive medical details. Securely destroy these records when they are no longer required to be retained.
Documents to shred include:
Laboratory test results
Blood test reports
Pathology reports
Diagnostic imaging reports
X-ray reports
MRI and CT scan reports
Other diagnostic documentation containing PHI
Copies of test results containing patient identifiers
3. Billing Records, Insurance Claims, and Explanation of Benefits Documents
Healthcare billing and insurance documents often contain both financial information and PHI. Secure destruction helps protect patients from unauthorized access to their medical and financial information.
Documents to shred include:
Patient billing records
Medical bills
Insurance claims
Explanation of Benefits (EOB) documents
Insurance forms
Payment records
Patient account statements
Billing correspondence
Documents containing insurance identification numbers
Other billing records containing PHI
4. Prescription Records and Medication Documentation
Prescription and medication records can contain identifiable patient information and details about a person's medical treatment. These documents should be securely destroyed when their applicable retention period has ended.
Documents to shred include:
Prescription records
Medication orders
Prescription labels containing patient information
Medication administration records
Pharmacy records containing PHI
Medication-related correspondence
Other prescription documentation containing patient identifiers
5. Patient Intake and Registration Forms
Patient intake and registration documents often contain names, addresses, contact information, insurance details, and other PHI. These documents should be securely destroyed after the required retention period.
Documents to shred include:
Patient registration forms
New patient intake forms
Patient demographic forms
Insurance information forms
Consent forms containing PHI
Copies of identification documents
Emergency contact information
Patient authorization forms
Other forms containing sensitive patient information
6. Appointment Schedules and Administrative Records
Appointment and administrative records can reveal patient identities, healthcare providers, appointment details, and other sensitive information. Healthcare facilities should securely destroy these records when they are no longer required.
Documents to shred include:
Appointment schedules
Patient appointment lists
Sign-in sheets containing patient information
Referral records
Patient correspondence
Administrative forms containing PHI
Call logs containing patient information
Other administrative documents containing identifiable patient information
7. Employee Records in Healthcare Settings
Healthcare employees' personnel records can contain sensitive personal, financial, and employment information. These records should be handled and securely destroyed according to applicable retention requirements.
Documents to shred include:
Employee applications
Resumes
Direct deposit forms
W-4 and I-9 forms after the applicable retention period
Performance reviews
Payroll records
Benefits enrollment forms
Disciplinary records
Termination paperwork
Copies of employee identification documents
Business vs. Healthcare Documents That Require Secure Destruction
Document Category | Business | Healthcare | Key Regulation/Concern |
Employee records | ✓ | ✓ | FACTA / employment laws |
Financial records | ✓ | ✓ | FACTA / GLBA where applicable |
Customer information | ✓ | ✓ | Privacy requirements |
Patient medical records | — | ✓ | HIPAA |
Lab results | — | ✓ | HIPAA |
Prescription records | — | ✓ | HIPAA |
Insurance claims | — | ✓ | HIPAA |
Proprietary business information | ✓ | ✓ | Confidentiality |
Quick Reference: What Should You Shred?
1. Businesses:
Employee and HR records
Financial and accounting documents
Tax records after retention requirements
Customer information
Consumer reports
Contracts and legal documents
Payroll records
Proprietary business information
2. Healthcare facilities:
Patient medical records
Lab and diagnostic reports
Billing and insurance documents
Prescription records and labels
Patient intake forms
Appointment schedules
Documents containing PHI
How to Build a Compliant Document Shredding Program
Identify documents that require secure destruction
Create a document retention schedule
Place secure collection consoles in key areas
Schedule regular shredding pickups
Maintain Certificates of Destruction
Train employees on secure document disposal
Compliance Element | Why It Matters |
Retention schedule | Prevents premature destruction |
Locked collection bins | Prevents unauthorized access |
Secure destruction | Makes information unreadable/reconstructable |
Certificate of Destruction | Provides destruction documentation |
Employee training | Reduces improper disposal |
Chain of custody | Documents handling from collection to destruction |
At San Diego Medical Waste (SD Medwaste), we help healthcare facilities close the physical security gap. We provide safe, compliant, and transparent shredding services along with medical waste, sharps, and pharmaceutical disposal services designed to protect your patients and your practice.
Unlike national competitors that charge hidden fees and require rigid contracts, we offer straightforward, flat-rate pricing with a price-lock guarantee.
Ready to secure your facility's physical waste and compliance? Contact SD Medwaste today for a free, no-obligation quote.
Frequently Asked Questions (FAQs)
Q1: Are businesses legally required to shred documents, or is it just a best practice?
For most businesses, shredding sensitive documents is a legal requirement, not a discretionary practice. FACTA's Disposal Rule requires any business that uses consumer reports to securely destroy that information and any documents derived from it by burning, pulverizing, or shredding.
Healthcare facilities are additionally required under HIPAA to destroy PHI so that it is unreadable and cannot be reconstructed. Financial institutions face equivalent obligations under the Gramm-Leach-Bliley Act. Penalties for non-compliance range from $100 to $50,000 per HIPAA violation, and FACTA violations can trigger federal enforcement actions and private class action lawsuits. State privacy laws add a further layer of obligation that varies by jurisdiction.
Q2: What counts as Protected Health Information (PHI) under HIPAA, and does it all need to be shredded?
PHI is defined as any individually identifiable information tied to a patient's health condition, care, or payment for care. HIPAA identifies 18 specific categories of identifiers that, when combined with health information, create PHI. These include names, dates, addresses, phone numbers, Social Security numbers, account numbers, and geographic data smaller than a state.
In practical terms, any document in a healthcare setting that identifies a patient in connection with health-related information must be treated as PHI and shredded when it reaches the end of its retention period. This includes not just medical records and lab results but also appointment schedules, billing statements, intake forms, prescription labels, and any sticky notes or informal documentation that links a patient's identity to health information.
Q3: How long should businesses and healthcare facilities retain documents before shredding them?
Retention periods vary by document type, industry, and jurisdiction, so every organization should maintain a formal document retention schedule reviewed by legal counsel. As general guidance: HIPAA requires compliance-related documentation to be retained for at least six years from creation or the last effective date, and many states require medical records to be kept for five to ten years, longer for minor patients. IRS records for tax purposes should generally be retained for at least seven years.
Employee payroll records should be kept for at least three years under the Fair Labor Standards Act. Financial records covered by SOX must be retained for seven years. The destruction obligation activates at the end of the applicable retention period. Shredding a document before its retention period has been met is as much a compliance failure as failing to shred it afterward.
Q4: What shredding method is required to meet HIPAA and FACTA compliance standards?
HIPAA requires that PHI be destroyed so that it is unreadable, indecipherable, and cannot be reconstructed. For paper documents, this means cross-cut or micro-cut shredding, incineration, pulverization, or pulping. Strip-cut shredding, which produces long ribbons of paper that can be reassembled, does not meet the HIPAA standard for PHI destruction. FACTA similarly requires that consumer information be destroyed so that it cannot be read or reconstructed.
The DIN 66399 security standard is the internationally recognized framework for shredding security levels, with P-4 cross-cut shredding recommended as the minimum for sensitive personal and financial information and P-5 and above required for highly sensitive or classified materials. When working with a certified shredding vendor, the Certificate of Destruction they provide is the documentation that demonstrates compliance with both HIPAA and FACTA requirements in the event of a regulatory audit.




Comments