How to Properly Dispose of PHI and ePHI Under HIPAA Regulations

Healthcare organizations and business associates handle massive amounts of Protected Health Information (PHI) daily. However, managing data securely doesn’t stop while it is in use—it extends through final destruction. Failing to securely dispose of patient records is one of the quickest ways to trigger an Office for Civil Rights (OCR) investigation, leading to severe data breaches and costly compliance fines.

Here is what your organization needs to know about meeting HIPAA disposal requirements for both physical and electronic records.

What Are the HIPAA Requirements for Disposing of PHI?

The Health Insurance Portability and Accountability Act (HIPAA) does not mandate one specific method for destroying records. Instead, it requires organizations to implement reasonable and appropriate safeguards to ensure patient data cannot be reconstructed or impermissibly disclosed.

The HIPAA Privacy Rule and Paper Records

Under 45 CFR 164.530(c), covered entities and business associates must apply administrative, technical, and physical safeguards to protect the privacy of PHI through its final disposition.

  • The Goal: Prevent data from being readable, reconstructed, or otherwise compromised during or after the disposal process.
  • Common Violation: Tossing intact paper charts, sign-in sheets, or billing records directly into a standard trash can or public dumpster.

The HIPAA Security Rule and ePHI

For digital data, 45 CFR 164.310(d)(2)(i) mandates strict policies and procedures regarding the final disposition of electronic PHI (ePHI) and the hardware or electronic media on which it is stored.

  • The Goal: Ensure that ePHI is permanently cleared or purged before electronic media is re-used, recycled, or thrown away.
  • Common Violation: Donating old office computers or discarding broken hard drives without completely degaussing or physically destroying the storage media.

Approved Methods for HIPAA-Compliant Data Destruction

Because federal law is flexible, your organization can choose the methods that best fit your workflow, provided they guarantee the data is unrecoverable.

Destroying Paper Records and X-Rays

For physical media, the objective is to ensure the PHI is rendered essentially unreadable and cannot be reconstructed. Approved disposal methods include shredding, burning, pulping, or incinerating the documents. Simply tearing up a patient chart by hand or throwing intact records into a recycling bin does not meet federal compliance standards.

Destroying Electronic Media (ePHI)

For digital data, organizations must ensure that ePHI cannot be retrieved from the hardware or electronic media on which it was stored. Compliant methods include clearing (overwriting the data with non-sensitive information), purging (degaussing or demagnetizing the media to flip the magnetic fields), or physical destruction of the hardware itself. Physical destruction of electronic media can be achieved through specialized disintegration, incineration, or hard drive shredding.

Managing Off-Site and Remote Employee Disposal

With the rise of remote work and telehealth, secure disposal extends far beyond the clinic walls. Under 45 CFR 164.530(b), your workforce must be actively trained on remote data destruction policies.

To maintain compliance with off-site employees, organizations generally utilize one of two strategies:

  1. The Return Policy: Requiring remote workforce members to securely hold and return all physical PHI to the main facility for professional shredding and disposal.
  2. The Direct Shred Policy: Permitting employees to shred paper records themselves only if the organization provides approved shredding equipment and maintains a strict verification and logging process.

Compliance Tip: If a workforce member fails to follow your established disposal protocols, HIPAA requires that your organization apply formal, documented sanctions to the employee.

Streamline Your HIPAA Compliance Program

Managing the final disposition of PHI requires clear, written policies and routine staff training. If you aren’t sure whether your current destruction protocols meet federal standards, we can help.

Colington Consulting provides customized compliance programs, comprehensive policy development, and expert risk management plans to keep your organization defensibly positioned against OCR audits.

Schedule Your Free 30-Minute HIPAA Risk Review Now

Frequently Asked Questions About PHI Disposal

Can you throw away paper charts in a dumpster if they are ripped up?

No. Simply ripping up paper charts by hand does not meet the HIPAA standard of making the text completely unreadable and impossible to reconstruct. Documents must be thoroughly shredded, pulped, or incinerated.

Does HIPAA require a certificate of destruction?

While the text of the HIPAA Rules does not explicitly mandate a “certificate of destruction,” utilizing a third-party shredding vendor that provides one is considered an industry best practice. It serves as vital documentation during an OCR audit to prove your organization followed proper physical safeguards.

  • Reviewed By: Jay Hodes, President – Colington Consulting, HIPAA Compliance Expert
  • Disclaimer: The information provided in this article is for educational and informational purposes only and does not constitute formal legal advice or an official regulatory determination. For specific guidance regarding your organization’s unique operational workflows, consult directly with a HIPAA compliance specialist or legal counsel.