Here’s What You Need to Know
HIPAA requires covered entities to dispose of protected health information so it is “unreadable, indecipherable, and otherwise unable to be reconstructed” — but it doesn’t mandate a specific method or shred size. Shredding through a NAID AAA Certified provider is widely considered the most reliable way to meet that standard, with documentation to prove it. Richards & Richards has served Middle Tennessee since 1987 and provides both one-time purge shredding and regularly scheduled service for healthcare organizations and any business that handles PHI.
What HIPAA Requires (General Information, Not Legal Advice)
HIPAA’s Privacy Rule requires organizations that handle protected health information to apply “appropriate administrative, technical, and physical safeguards” to protect it — including how it’s disposed of. A few specifics worth knowing:
- What counts as PHI: names, birthdates, addresses, phone/fax numbers, email addresses, medical record numbers, biometric identifiers, photos, Social Security numbers, health plan beneficiary numbers, account numbers, license numbers, vehicle identifiers, device identifiers, web URLs, IP addresses, and an individual’s health information generally.
- There’s no specific required shred size or method — the standard is simply that the information must be unreadable and impossible to reconstruct before disposal.
- HIPAA itself doesn’t set a document retention period. State and federal privacy laws determine how long records must be kept; HIPAA governs how they’re protected the whole time you have them (“cradle to grave”), including at the moment of destruction.
Every organization’s specific compliance obligations should be confirmed with your own counsel or compliance officer — this page is general information, not legal advice.
Why Shredding Is the Practical Answer
Not all shredders render documents truly unreadable and unreconstructable — this is where a professional, NAID AAA Certified provider matters. The weak points in a document’s chain of custody are usually: the period after records are pulled for a purge (sitting in a pile, box, or unlocked bin), the handling during transport, and what happens after shredding if the material isn’t properly secured or recycled. A single employee skipping a step is enough to create a breach — which is the core argument for locked collection containers and a professional chain of custody rather than an office shredder and good intentions.
What Richards & Richards Provides
- NAID AAA Certified destruction — audited by independent security professionals
- Locked, secure collection containers so staff can dispose of PHI without a manual process
- A documented chain of custody from pickup through destruction
- A Certificate of Destruction for every job, as proof of compliant disposal
- Both one-time purge service (for backlog records) and regularly scheduled pickups (for ongoing PHI disposal)
- 100% of shredded material recycled after destruction
Common Myths, Corrected
Myth: “HIPAA requires a specific shred size.”
Fact: It doesn’t. HIPAA requires PHI to be unreadable and unable to be reconstructed — it doesn’t specify a particle size or even require shredding specifically, though shredding is the most practical way to meet the standard.
Myth: “Any accidental exposure of PHI is automatically a HIPAA violation with penalties.”
Fact: Not every improper use of PHI is treated as a reportable breach. Each situation is evaluated on whether the information was actually viewed (or could have been viewed) by someone unauthorized. Complaints go to the Department of Health and Human Services, and most are resolved through corrective action rather than fines — penalties are generally reserved for intentional, knowing violations.
Myth: “HIPAA tells us exactly how long we have to keep records before shredding.”
Fact: HIPAA itself doesn’t set retention periods — state and federal record-retention laws do. Confirm your specific retention requirement before scheduling a purge.
Frequently Asked Questions
Is your shredding service HIPAA-compliant?
Yes. Our NAID AAA Certified process, locked collection containers, documented chain of custody, and Certificate of Destruction are designed to meet HIPAA’s requirement that PHI be rendered unreadable and unreconstructable before disposal.
Does HIPAA require a specific shred size?
No. HIPAA requires PHI to be unreadable and impossible to reconstruct — it does not specify a particle size or method.
How long do we have to keep medical records before shredding them?
HIPAA doesn’t set a retention period; state and federal record-retention laws do. Confirm your specific requirement, then we can help you dispose of records once that period has passed.
What happens to our documents after they’re shredded?
100% of shredded material is recycled, and you receive a Certificate of Destruction as proof of compliant disposal.
Ready to Get Started?
Handling protected health information? Get a NAID AAA Certified shredding partner in place before your next purge or ongoing pickup.
Request a Quote — or talk to a local team member about setting up scheduled service.


