There is a version of every business’s records situation that is clean, documented, and defensible. There is another version that involves filing cabinets from 2009, boxes in a storage room that nobody has opened in three years, and a general understanding that “the old stuff” is somewhere but nobody is quite sure where.

Most businesses are living in the second version. Not because they are irresponsible, but because records management is genuinely unglamorous work, and the consequences of neglecting it are invisible until they aren’t. The problem with invisible consequences is that they tend to become very visible at the worst possible moment — during an audit, a legal dispute, a regulatory examination, or a data breach investigation.

Here are eight signs that your business’s records situation has passed the threshold from “needs attention” to “needs to happen this month.”

The problem with keeping records too long isn’t just the space they take up. It’s the liability they create — for information you no longer need and can no longer protect.

1

You have records you’re keeping “just in case” without knowing the retention requirement

“Just in case” is not a retention policy. Every category of business record has a defined retention period under federal or Massachusetts law — tax records (7 years), employment records (3–7 years depending on type), HIPAA records (6 years), corporate records (permanently). When a business keeps records past their required retention period, those records remain fully discoverable in litigation — meaning you can be compelled to produce them even though they serve no legitimate business purpose. Keeping records you no longer need exposes you to risks you no longer have any reason to accept.

2

Nobody knows what’s in the storage room

If your business has a closet, a room, or an off-site storage unit full of boxes and nobody on your current staff can give you a reasonably accurate accounting of what’s in them, you have a records management problem. Those boxes represent liability you can’t quantify — confidential client information you may not be protecting, records you may be required to produce, documents you may have been required to destroy years ago. “We’re not sure what’s in there” is not a defensible answer to a regulatory inquiry.

3

Your business recently changed ownership, merged, or lost key staff

Transitions are when records problems surface and compound. A business acquisition inherits the seller’s records obligations, including any compliance failures in their document retention practices. A staff turnover can mean that the person who “knew where everything was” is no longer there, and the institutional knowledge of what’s been kept, why, and for how long walks out the door with them. Post-transition is the right time to audit what you have, identify what needs to stay, and destroy what doesn’t.

4

You’re paying for offsite storage you never access

Offsite document storage is one of the most persistent invisible costs in small business operations. A storage facility charges $50 to $200 per month for boxes that haven’t been opened in five years, many of which contain records whose retention periods expired long ago. Run the math: $100/month for three years on records that should have been destroyed at year seven of a seven-year retention is $3,600 spent protecting liability you should have eliminated. An annual purge that clears expired records pays for itself within months.

5

Client or patient information is stored in forms you can’t fully account for

For HIPAA-covered businesses — medical and dental practices, health insurance companies, billing services — the inability to account for where PHI is stored and who has access to it is itself a compliance failure. If patient charts are in boxes that haven’t been audited, if old billing records are in a former employee’s filing area that nobody has reviewed, or if paper records exist for patients seen before your current EHR system went live and nobody has inventoried them, you have a HIPAA exposure. The fix is straightforward: audit, document, retain what you need, and destroy the rest with a BAA-covered vendor.

6

Your staff shreds documents on an ad-hoc basis — or not at all

If your business’s shredding practice is “whoever remembers to do it, when they have time, in the office shredder,” you do not have a records destruction policy. You have a reasonable approximation of one that will fail to satisfy any regulatory standard requiring documented, systematic disposal. Massachusetts 201 CMR 17 requires that businesses “take reasonable steps to verify that its service providers with access to personal information have the means to destroy such records.” An office strip shredder operated inconsistently by whoever happens to walk past it does not meet this bar.

7

You’ve never issued or received a Certificate of Destruction

A Certificate of Destruction is the documented evidence that specific records were destroyed on a specific date by a specific method. For businesses subject to HIPAA, GLBA, FTC Safeguards, or MA 201 CMR 17, the ability to demonstrate that records were properly destroyed — not just that you intended to destroy them — is the difference between a manageable audit and a significant one. If your business has no Certificates of Destruction on file, you have no documented defense. Our notarized Certificate covers every job, every time.

8

You’re about to move, renovate, or downsize your office

An upcoming office change is one of the best forcing functions for a records purge. Moving forces you to account for what you have. Downsizing creates a genuine space constraint that makes the decision easy. And the physical act of consolidating and moving creates the natural moment to evaluate what should come along and what should be destroyed. A purge before a move costs less than moving boxes you then have to store somewhere, and creates an orderly start at the new location.

The fix is simpler than you think

A business records purge sounds like a large project. It doesn’t have to be. The most efficient approach is a single scheduled pickup: we come to your office or storage facility, you’ve identified what needs to go, we collect it in locked containers, transport it to our Tewksbury facility, and return a notarized Certificate of Destruction covering every document destroyed. One appointment, any volume, documented.

Before you call us — a 20-minute pre-purge checklist

Identify records past their retention periods using our Massachusetts retention guide
If you handle PHI: confirm we sign a BAA before any records transfer (we do, at no charge)
Box or bag the records for destruction — no sorting required, we shred everything including folders, binders, and paper clips
Note whether you need hard drives or electronic media destroyed — we handle those with serial-number CoDs
Call (978) 636-0301 — we quote in 2 minutes and can often schedule within the week

For ongoing records management, our scheduled recurring service with locked consoles means you never let the backlog build up again. A notarized Certificate of Destruction at every pickup. Published rates, no contract required for most arrangements.

What it actually costs to do nothing

A HIPAA breach involving unsecured PHI carries civil penalties of $100 to $50,000 per violation, per year the violation continued. A Massachusetts data security violation under 201 CMR 17 carries civil penalties of up to $5,000 per violation. A discovery order in civil litigation requiring you to produce records you can’t locate, because they’re in boxes that nobody has touched in years, costs attorney time that makes a shredding bill look like pocket change.

Our annual purge service is 99 cents per pound, flat transport rate confirmed before scheduling, notarized Certificate of Destruction on every job. Call (978) 636-0301 today.