top of page
San Diego Medical Waste Services logo

What Documents Should Businesses and Healthcare Facilities Always Shred?

  • Writer: Sam Spaccamonti
    Sam Spaccamonti
  • 2 hours ago
  • 9 min read

TL;DR / Quick Answer: Businesses and healthcare facilities should securely shred documents containing sensitive personal, financial, employee, customer, or patient information once their required retention period has ended. Common documents include employee records, financial statements, tax documents, customer data, contracts, patient records, lab results, billing records, prescription information, and other documents containing Protected Health Information (PHI) or consumer information covered by regulations such as HIPAA and FACTA.


The Regulatory Framework Behind the Obligation to Shred


Businesses and healthcare facilities may have legal obligations to securely destroy sensitive information under federal regulations such as HIPAA, FACTA, and GLBA. The specific requirements depend on the type of information an organization handles and the industry it operates in.


1. Health Insurance Portability and Accountability Act (HIPAA) applies to covered entities, including hospitals, clinics, physicians, dentists, pharmacies, health plans, and healthcare clearinghouses, as well as their business associates. HIPAA's Privacy Rule requires that Protected Health Information be destroyed so that it is unreadable, indecipherable, and otherwise cannot be reconstructed.


For paper records, this means cross-cut or micro-cut shredding, incineration, pulverization, or pulping. A standard strip-cut shredder does not meet the standard. HIPAA requires covered entities to retain compliance-related documentation for at least six years, though actual medical records are governed by state law, which typically requires retention for five to ten years and longer for minor patients.


2. Fair and Accurate Credit Transactions Act (FACTA), the Disposal Rule applies to any business that uses consumer reports, including employers running background checks, landlords, retailers, financial institutions, and virtually every other type of business in America. FACTA requires consumer information to be burned, pulverized, or shredded so it cannot be read or reconstructed.


Unlike HIPAA, FACTA is not limited to healthcare. It reaches every business that holds consumer financial or personal data, which in practice means almost every business operating in the United States.


3. Gramm-Leach-Bliley Act (GLBA) applies to financial institutions broadly defined: banks, credit unions, insurers, mortgage lenders, investment advisors, tax preparers, payday lenders, financing auto dealers, and debt collectors. GLBA requires these institutions to implement safeguards to protect customer financial information, including secure disposal at the end of the information's useful life.


Together, these three frameworks establish that the obligation to shred is not discretionary. The question is never whether to shred sensitive documents. It is knowing exactly which documents qualify and ensuring they never reach a trash can or recycling bin without being destroyed first.



What Documents Should Businesses Always Shred?


What Documents Should Businesses Always Shred?

Businesses should shred any document containing sensitive personal, financial, customer, employee, or proprietary information once it reaches the end of its required retention period.


1. Employee Records and Human Resources Files


Employee and HR records contain sensitive personal and employment information. Businesses should securely destroy these records once the applicable retention period has ended.


Documents to shred include:


  • Employment applications

  • Resumes and job applications

  • Direct deposit forms

  • W-4 and I-9 forms after the applicable retention period

  • Performance reviews

  • Employee disciplinary records

  • Benefits enrollment forms

  • Termination paperwork

  • Copies of identification documents

  • Other personnel records containing sensitive employee information



2. Financial and Accounting Records


Financial and accounting documents can contain sensitive business, banking, payment, and tax information. These records should be securely destroyed after the applicable retention period.


Documents to shred include:


  • Bank statements

  • Credit card statements

  • Accounts payable and receivable records

  • Invoices

  • Tax documents after the applicable retention period

  • Financial reports

  • Payment records

  • Voided checks

  • Deposit records

  • Documents containing bank account or financial information



3. Business Contracts and Legal Documents


Business contracts and legal records may contain confidential information about clients, vendors, transactions, and business operations. These documents should be securely destroyed when they are no longer required to be retained.


Documents to shred include:


  • Expired contracts

  • Vendor agreements

  • Client agreements

  • Non-disclosure agreements (NDAs)

  • Legal correspondence

  • Settlement documents

  • Internal legal records

  • Confidential proposals

  • Documents containing sensitive business terms

  • Outdated copies of legal documents



4. Customer and Client Data


Customer and client records can contain personally identifiable information (PII), financial details, and other sensitive information that should not be left in regular trash.


Documents to shred include:


  • Customer applications

  • Account information

  • Customer contact information

  • Copies of identification documents

  • Credit applications

  • Customer correspondence

  • Account statements

  • Consumer reports

  • Forms containing Social Security numbers

  • Documents containing payment or financial information



5. Proprietary Business Information and Intellectual Property


Confidential business information and intellectual property can create significant risks if they are improperly discarded. Secure destruction helps prevent sensitive business information from being accessed by unauthorized individuals.


Documents to shred include:


  • Business plans

  • Product development documents

  • Research and development materials

  • Trade secret information

  • Internal strategy documents

  • Confidential pricing information

  • Marketing plans

  • Unreleased product information

  • Internal reports

  • Confidential client or vendor information



6. Payroll Records


Payroll records contain sensitive employee information, including compensation, banking, tax, and benefits information. Businesses should securely destroy these records once their applicable retention requirements have been met.


Documents to shred include:


  • Payroll reports

  • Pay stubs

  • Wage records

  • Time sheets

  • Direct deposit information

  • Payroll tax documents

  • Employee compensation records

  • Salary information

  • Benefits deduction records

  • Other payroll documents containing sensitive employee information



What Documents Should Healthcare Facilities Always Shred?


Healthcare facilities should securely destroy documents containing Protected Health Information (PHI) once the applicable retention period has ended. This includes medical records, lab results, billing documents, prescription information, patient intake forms, appointment schedules, and other records that identify a patient and relate to their healthcare.


1. Patient Medical Records and Clinical Documentation


Patient medical records contain Protected Health Information (PHI) and other sensitive healthcare information. Healthcare facilities should securely destroy these records when the applicable retention requirements have been met.


Documents to shred include:


  • Patient medical records

  • Physician notes

  • Nursing notes

  • Treatment records

  • Clinical documentation

  • Patient histories

  • Discharge summaries

  • Medical forms containing PHI

  • Copies of patient identification documents

  • Other patient records containing protected information



2. Lab Results and Diagnostic Reports


Laboratory and diagnostic documents can contain identifiable patient information and sensitive medical details. Securely destroy these records when they are no longer required to be retained.


Documents to shred include:


  • Laboratory test results

  • Blood test reports

  • Pathology reports

  • Diagnostic imaging reports

  • X-ray reports

  • MRI and CT scan reports

  • Other diagnostic documentation containing PHI

  • Copies of test results containing patient identifiers



3. Billing Records, Insurance Claims, and Explanation of Benefits Documents


Healthcare billing and insurance documents often contain both financial information and PHI. Secure destruction helps protect patients from unauthorized access to their medical and financial information.


Documents to shred include:


  • Patient billing records

  • Medical bills

  • Insurance claims

  • Explanation of Benefits (EOB) documents

  • Insurance forms

  • Payment records

  • Patient account statements

  • Billing correspondence

  • Documents containing insurance identification numbers

  • Other billing records containing PHI


4. Prescription Records and Medication Documentation


Prescription and medication records can contain identifiable patient information and details about a person's medical treatment. These documents should be securely destroyed when their applicable retention period has ended.


Documents to shred include:


  • Prescription records

  • Medication orders

  • Prescription labels containing patient information

  • Medication administration records

  • Pharmacy records containing PHI

  • Medication-related correspondence

  • Other prescription documentation containing patient identifiers



5. Patient Intake and Registration Forms


Patient intake and registration documents often contain names, addresses, contact information, insurance details, and other PHI. These documents should be securely destroyed after the required retention period.


Documents to shred include:


  • Patient registration forms

  • New patient intake forms

  • Patient demographic forms

  • Insurance information forms

  • Consent forms containing PHI

  • Copies of identification documents

  • Emergency contact information

  • Patient authorization forms

  • Other forms containing sensitive patient information



6. Appointment Schedules and Administrative Records


Appointment and administrative records can reveal patient identities, healthcare providers, appointment details, and other sensitive information. Healthcare facilities should securely destroy these records when they are no longer required.


Documents to shred include:


  • Appointment schedules

  • Patient appointment lists

  • Sign-in sheets containing patient information

  • Referral records

  • Patient correspondence

  • Administrative forms containing PHI

  • Call logs containing patient information

  • Other administrative documents containing identifiable patient information



7. Employee Records in Healthcare Settings


Healthcare employees' personnel records can contain sensitive personal, financial, and employment information. These records should be handled and securely destroyed according to applicable retention requirements.


Documents to shred include:


  • Employee applications

  • Resumes

  • Direct deposit forms

  • W-4 and I-9 forms after the applicable retention period

  • Performance reviews

  • Payroll records

  • Benefits enrollment forms

  • Disciplinary records

  • Termination paperwork

  • Copies of employee identification documents



Business vs. Healthcare Documents That Require Secure Destruction


Document Category

Business

Healthcare

Key Regulation/Concern

Employee records

FACTA / employment laws

Financial records

FACTA / GLBA where applicable

Customer information

Privacy requirements

Patient medical records

HIPAA

Lab results

HIPAA

Prescription records

HIPAA

Insurance claims

HIPAA

Proprietary business information

Confidentiality



Quick Reference: What Should You Shred?


1. Businesses:


  • Employee and HR records

  • Financial and accounting documents

  • Tax records after retention requirements

  • Customer information

  • Consumer reports

  • Contracts and legal documents

  • Payroll records

  • Proprietary business information


2. Healthcare facilities:


  • Patient medical records

  • Lab and diagnostic reports

  • Billing and insurance documents

  • Prescription records and labels

  • Patient intake forms

  • Appointment schedules

  • Documents containing PHI



How to Build a Compliant Document Shredding Program


  1. Identify documents that require secure destruction

  2. Create a document retention schedule

  3. Place secure collection consoles in key areas

  4. Schedule regular shredding pickups

  5. Maintain Certificates of Destruction

  6. Train employees on secure document disposal


Compliance Element

Why It Matters

Retention schedule

Prevents premature destruction

Locked collection bins

Prevents unauthorized access

Secure destruction

Makes information unreadable/reconstructable

Certificate of Destruction

Provides destruction documentation

Employee training

Reduces improper disposal

Chain of custody

Documents handling from collection to destruction



At San Diego Medical Waste (SD Medwaste), we help healthcare facilities close the physical security gap. We provide safe, compliant, and transparent shredding services along with medical waste, sharps, and pharmaceutical disposal services designed to protect your patients and your practice.  


Unlike national competitors that charge hidden fees and require rigid contracts, we offer straightforward, flat-rate pricing with a price-lock guarantee.  


Ready to secure your facility's physical waste and compliance? Contact SD Medwaste today for a free, no-obligation quote.



Frequently Asked Questions (FAQs)


Q1: Are businesses legally required to shred documents, or is it just a best practice?


For most businesses, shredding sensitive documents is a legal requirement, not a discretionary practice. FACTA's Disposal Rule requires any business that uses consumer reports to securely destroy that information and any documents derived from it by burning, pulverizing, or shredding.


Healthcare facilities are additionally required under HIPAA to destroy PHI so that it is unreadable and cannot be reconstructed. Financial institutions face equivalent obligations under the Gramm-Leach-Bliley Act. Penalties for non-compliance range from $100 to $50,000 per HIPAA violation, and FACTA violations can trigger federal enforcement actions and private class action lawsuits. State privacy laws add a further layer of obligation that varies by jurisdiction.


Q2: What counts as Protected Health Information (PHI) under HIPAA, and does it all need to be shredded?


PHI is defined as any individually identifiable information tied to a patient's health condition, care, or payment for care. HIPAA identifies 18 specific categories of identifiers that, when combined with health information, create PHI. These include names, dates, addresses, phone numbers, Social Security numbers, account numbers, and geographic data smaller than a state.


In practical terms, any document in a healthcare setting that identifies a patient in connection with health-related information must be treated as PHI and shredded when it reaches the end of its retention period. This includes not just medical records and lab results but also appointment schedules, billing statements, intake forms, prescription labels, and any sticky notes or informal documentation that links a patient's identity to health information.


Q3: How long should businesses and healthcare facilities retain documents before shredding them?


Retention periods vary by document type, industry, and jurisdiction, so every organization should maintain a formal document retention schedule reviewed by legal counsel. As general guidance: HIPAA requires compliance-related documentation to be retained for at least six years from creation or the last effective date, and many states require medical records to be kept for five to ten years, longer for minor patients. IRS records for tax purposes should generally be retained for at least seven years.


Employee payroll records should be kept for at least three years under the Fair Labor Standards Act. Financial records covered by SOX must be retained for seven years. The destruction obligation activates at the end of the applicable retention period. Shredding a document before its retention period has been met is as much a compliance failure as failing to shred it afterward.


Q4: What shredding method is required to meet HIPAA and FACTA compliance standards?


HIPAA requires that PHI be destroyed so that it is unreadable, indecipherable, and cannot be reconstructed. For paper documents, this means cross-cut or micro-cut shredding, incineration, pulverization, or pulping. Strip-cut shredding, which produces long ribbons of paper that can be reassembled, does not meet the HIPAA standard for PHI destruction. FACTA similarly requires that consumer information be destroyed so that it cannot be read or reconstructed.


The DIN 66399 security standard is the internationally recognized framework for shredding security levels, with P-4 cross-cut shredding recommended as the minimum for sensitive personal and financial information and P-5 and above required for highly sensitive or classified materials. When working with a certified shredding vendor, the Certificate of Destruction they provide is the documentation that demonstrates compliance with both HIPAA and FACTA requirements in the event of a regulatory audit.



Comments


bottom of page