Compliance

The laws that say you can't just throw it away

If your business touches medical, financial, credit, employee or customer information, at least one of these federal laws tells you how it must be destroyed. Most say the same thing in different words: make it unreadable, do it reliably, and be able to prove it.

1999 · Financial

Gramm-Leach-Bliley Act (GLBA)

Banks, credit unions, lenders, insurers, accountants, tax preparers and car dealers must safeguard customer financial information from collection through disposal.

Read about GLBA
1996 · Healthcare

HIPAA

Medical, dental and mental-health practices, pharmacies and their vendors must dispose of patient information so it can't be read or reconstructed.

Read about HIPAA
2009 · Healthcare vendors

HITECH Act

Extends HIPAA to the companies healthcare providers hire — including shredding vendors — and adds breach notification rules and higher penalties.

Read about HITECH
2003 · Anyone using credit reports

FACTA & the Disposal Rule

Any business that pulls a credit report — landlords, employers, dealers, lenders — must take reasonable measures to destroy that information when it's no longer needed.

Read about FACTA
2002 · Public companies & auditors

Sarbanes-Oxley (SOX)

Requires retention of financial records for set periods and makes destroying documents to obstruct an investigation a federal crime. A written retention-and-destruction policy is the practical answer.

Read about SOX
1996 · Trade secrets

Economic Espionage Act (EEA)

Makes trade-secret theft a federal crime — but only protects information you took reasonable steps to keep secret. How you dispose of drafts, formulas and customer lists is part of that.

Read about the EEA

What every one of these laws has in common

None of them require a specific machine or a specific vendor. They require that sensitive information be rendered unreadable, that the process be reliable, and that you can document it. On-site shredding with a certificate of destruction satisfies all three — which is why regulators point to it in their own guidance.

See what enforcement looks like

Your compliance checklist

  • A written policy for how long you keep each type of record
  • Locked collection bins so paper isn't readable while waiting
  • Destruction that makes documents unreadable and unrecoverable
  • A certificate of destruction kept with your records (six years for HIPAA)
  • A Business Associate Agreement if you're a healthcare provider
Call (567) 202-2660 Get a Quote