HIPAA-compliant shredding.

Medical records and patient data shredded to HIPAA standards, witnessed and documented so your disposal stands up to an audit.

Overview

What the rule requires when you dispose of data.

HIPAA does not let you simply throw out protected health information. Records must be rendered essentially unreadable, indecipherable, and impossible to reconstruct. Improper disposal is one of the most common and most penalized HIPAA violations.

Shreddee shreds paper records and destroys the drives that hold patient data, and issues a certificate of destruction for every job.

What we destroy

  • Paper medical records & charts
  • Imaging & printouts
  • Hard drives & servers with ePHI
  • Backup media
  • Prescription & label data
  • Billing & insurance paperwork
The disposal rule

What it comes down to.

01

Render it unreadable

PHI must be destroyed so it cannot be read or reconstructed, shredding paper, and destroying electronic media.

02

Stay accountable

Covered entities remain responsible for PHI through disposal, with agreements in place for any vendor who handles it.

03

Document it

You should be able to show what was destroyed, how, and when. A certificate of destruction provides that evidence.

FAQ

HIPAA destruction questions.

PHI must be rendered unreadable and impossible to reconstruct. Shredding paper and destroying electronic media meet that standard; simply discarding records does not.

Not reliably. Physical destruction of the drive is the surest way to render electronic PHI unrecoverable and prove it.

Both. We can shred at your location so nothing leaves your premises intact, or collect it securely and shred it at our facility, whichever you prefer. Either way you get a certificate of destruction.

Need HIPAA-compliant destruction?

Tell us what you need destroyed and we will take care of it, securely, and with a certificate every time.

  • Fully documented
  • Audit-ready documentation
  • Full chain of custody
  • Certificate of destruction every time