Medical Record Shredding & HIPAA-Compliant PHI Destruction
Hospitals, physician practices, dental offices, mental health providers, home health agencies, and every other HIPAA-covered entity in Massachusetts must destroy Protected Health Information in a way that renders it permanently unreadable. We are a certified HIPAA shredding provider with a 17-year track record, zero data breaches, and a notarized Certificate of Destruction on every medical shredding job.
Drop-off or pickup at your facility
- ✓HIPAA-certified physical destruction of all PHI
- ✓Paper records, charts, films, tapes & media
- ✓Hard drives & devices with ePHI — serial # CoD
- ✓Chain of custody from your facility to our plant
- ✓Notarized Certificate of Destruction every job
- ✓Business Associate Agreement available on request
HIPAA filing: $14.95 · All rates flat & confirmed in writing
What HIPAA actually requires for PHI disposal — and what does not satisfy it
The HIPAA Privacy Rule requires covered entities and their business associates to implement policies and procedures that address the final disposition of Protected Health Information. The standard is unambiguous: PHI must be rendered unreadable, indecipherable, and unable to be reconstructed. HHS guidance confirms that physical shredding satisfies this standard for paper records. For electronic PHI, the NIST SP 800-88 Destroy standard — physical shredding or disintegration of the storage media — is the accepted method that eliminates all residual data risk.
What does not satisfy the HIPAA disposal standard: placing records in recycling bins, passing files to uncertified collection services, deleting electronic files without certified media destruction, or using a shredding vendor who cannot produce a notarized Certificate of Destruction documenting the chain of custody and destruction event.
The HIPAA Security Rule (45 CFR §164.310(d)(2)(i)) separately requires covered entities to implement policies for the final disposal of electronic PHI and the hardware or media on which it is stored. A hard drive, laptop, tablet, or server that contained ePHI must be physically destroyed with a serial-number Certificate of Destruction — not donated, resold, or discarded without certified media destruction. See our IT asset and hard drive destruction service for how we handle ePHI devices specifically.
Massachusetts goes further: M.G.L. c. 111, §70
Massachusetts medical record retention law (M.G.L. c. 111, §70) requires providers to retain adult patient records for at least seven years from the date of last treatment. For minors, records must be retained until the patient reaches age 21, or for seven years from the date of last treatment — whichever is longer.
Massachusetts 201 CMR 17.00 additionally requires every organization maintaining personal information about Massachusetts residents — which includes all patient data — to ensure proper disposal. Physical shredding with a notarized Certificate of Destruction is the documented standard. Full retention periods are in our Massachusetts document retention schedule.
- Adult records: 7 years from last treatment date
- Minor records: until age 21 or 7 years — whichever is longer
- HIPAA administrative records: 6 years from creation or last effective date
- Billing & claims: 7 years (Medicare/Medicaid fraud SOL)
- Lab reports: 10 years under CLIA (cytology)
Every type of Protected Health Information we destroy
PHI exists in paper, film, electronic, and physical media formats. We handle all of them with the same certified process and the same notarized Certificate of Destruction.
Patient Charts & Clinical Records
Progress notes, encounter records, discharge summaries, referral letters, and all paper clinical documentation containing patient-identifiable information.
Billing & Insurance Records
Explanation of benefits (EOB), claims submissions, remittance advice, prior authorization records, and all billing documentation linking patients to financial data.
Mental Health & Substance Use Records
Psychotherapy notes, treatment plans, substance use treatment records (42 CFR Part 2), and all behavioral health documentation — which carry heightened federal protections beyond standard HIPAA.
Prescription & Pharmacy Records
Prescription histories, medication administration records, DEA-controlled substance logs, and pharmacy dispensing records linking patient identity to medications dispensed.
Lab Reports & Test Results
Blood work, pathology reports, microbiology results, cytology slides and reports, genetic testing results, and all diagnostic reports containing patient-identifiable information.
Radiology Films & Imaging
X-ray films, MRI and CT printouts, ultrasound images, nuclear medicine records, and all diagnostic imaging in any physical or printed format.
Hard Drives & ePHI Devices
Computers, laptops, servers, tablets, portable hard drives, backup tapes, and USB drives containing electronic PHI. Physical destruction with serial-number Certificate of Destruction. Software erasure is not sufficient for SSDs.
Administrative & HR Records
Staff credentialing files, employee health records, OSHA injury logs, and administrative documentation containing employee health information covered under HIPAA or state law.
Every type of healthcare organization we serve
Any organization that creates, receives, maintains, or transmits PHI is a covered entity or business associate under HIPAA. Every one of them has a documented disposal obligation — and every one we serve receives a notarized Certificate of Destruction and a Business Associate Agreement.
Hospitals & Health Systems
UMass Memorial Health, Lowell General, Lawrence General, and all affiliated inpatient, outpatient, and specialty campuses throughout Greater Boston and the Merrimack Valley. Large-volume annual purges accommodated with flat-rate pricing confirmed in writing.
Physician & Dental Practices
Solo and group practices, multi-specialty clinics, urgent care centers, and dental offices. Scheduled ongoing service with locked consoles and annual purges when retention periods are met. HIPAA filing fee of $14.95 applies.
Mental Health & Behavioral Health
Therapists, psychologists, psychiatrists, substance use treatment programs, and community mental health centers. Behavioral health records and 42 CFR Part 2 substance use treatment records carry heightened legal protections and require certified destruction with full chain of custody.
Home Health & Hospice
Home health agencies, visiting nurse associations, hospice programs, and personal care attendant organizations. Records generated in the field — clinical notes, medication administration records, care plans — all require the same certified destruction standard as facility-based records.
Laboratories & Imaging Centers
Independent clinical laboratories, radiology centers, pathology practices, and diagnostic imaging facilities. Lab reports and radiology films are PHI and subject to CLIA and HIPAA retention and destruction requirements.
Healthcare Business Associates
Medical billing companies, coding firms, healthcare IT vendors, transcription services, consultants, and any business associate that creates, receives, maintains, or transmits PHI on behalf of a covered entity. BAs have the same HIPAA disposal obligations as covered entities under the Omnibus Rule.
We are a HIPAA business associate — and we have the documentation to prove it
When a healthcare organization uses a shredding vendor to destroy PHI, that vendor becomes a HIPAA Business Associate under 45 CFR §164.502(e). The HIPAA Omnibus Rule requires covered entities to have a signed Business Associate Agreement (BAA) in place before any PHI is disclosed to a business associate — including a shredding vendor.
Many shredding providers cannot produce a signed BAA. We can. We operate as a HIPAA business associate with documented safeguards, trained personnel, and a process that satisfies both the Privacy Rule disposal standard and the Security Rule ePHI requirements. Our BAA is available on written request at no additional cost.
The covered entity’s obligation: Before disclosing PHI to any vendor — including your shredding company — you must have a signed BAA. Using a shredding vendor without a BAA is itself a HIPAA violation, regardless of whether the records are successfully destroyed.
What our BAA covers: Our Business Associate Agreement documents our obligation to use PHI only for destruction purposes, to implement appropriate safeguards, to report breaches, and to return or destroy PHI at the termination of the relationship. It satisfies the requirements of 45 CFR §164.504(e).
How to request it: Call (978) 636-0301 or submit a request online. We will have a signed BAA to you before service begins. This is standard for every medical shredding engagement we conduct.
The HIPAA filing fee — what it covers
Our medical shredding jobs include a HIPAA compliance filing fee of $14.95 in addition to the per-pound shredding rate. This fee covers the additional documentation, chain of custody recording, and notarized Certificate of Destruction specific to PHI destruction engagements — documentation that satisfies HIPAA audit requirements and supports your compliance program.
The $14.95 filing fee is flat regardless of volume — it does not scale with the number of boxes or pounds. For a practice destroying years of accumulated records, it represents a fraction of the total job cost and a complete HIPAA compliance record.
The Certificate of Destruction issued for every medical shredding job includes the date of destruction, your facility name and address, quantity and type of material destroyed, method of destruction, chain of custody declaration, and a notarized signature. File it with your HIPAA policies and your Business Associate Agreement.
From PHI to Certificate of Destruction in four steps
Schedule pickup or drop off
Book online or call (978) 636-0301. For medical facilities we come to you. Drop-off at our Tewksbury facility is also available with no appointment for smaller volumes. BAA signed before we touch any PHI.
Secured intake & chain of custody
All PHI is logged at intake and placed in locked containers. Pickup jobs travel in locked vehicles under a documented chain of custody. A signed intake receipt is provided before our driver departs your facility.
Industrial shredding — same day
All material is processed the same day it arrives at our certified Tewksbury facility. Industrial shredding renders paper and media unreadable, indecipherable, and unable to be reconstructed — satisfying the HIPAA disposal standard at 45 CFR §164.530(c).
Notarized CoD within 24–48 hrs
Your notarized Certificate of Destruction is emailed as a PDF. File it alongside your BAA and HIPAA policies. It is your documented proof that PHI was disposed of in compliance with 45 CFR §164.530(c).
Medical shredding rates — posted publicly, no surprises on the invoice
Every rate below is confirmed in writing before service begins. The price we quote is the price on your invoice. Always. Full rate schedule is posted on our rates page.
The notarized Certificate of Destruction — what every auditor asks for first
When the HHS Office for Civil Rights investigates a HIPAA complaint, when a malpractice attorney requests your records management documentation, or when your malpractice carrier reviews your policies at renewal — the Certificate of Destruction is the document they ask for. It is the evidence that PHI was disposed of in a manner consistent with 45 CFR §164.530(c) and your own written HIPAA policies.
A receipt from a drop-off service, a software-generated erasure log, or an unverified vendor confirmation does not carry the legal weight of a notarized Certificate from a certified HIPAA-compliant provider. Our CoD is notarized by a registered notary public and admissible as evidence of the facts it states.
Every Certificate of Destruction we issue documents:
I work for a Boston medical firm. We had a large storage room full of records — a mix of paper files, X-ray films, and old hard drives. We had gotten quotes from two national shredding companies and they were trying to charge us an arm and a leg. When I found Neighborhood Parcel, I was pleasantly surprised: flat rates, clear pricing, and they handled both the paper and the devices in one visit. The HIPAA certificate and the drive serial numbers were in my inbox the next morning. Exactly what we needed for our compliance file.
HIPAA shredding — frequently asked questions
The HIPAA Privacy Rule requires covered entities to implement policies for the final disposition of PHI that renders it unreadable, indecipherable, and unable to be reconstructed. HHS guidance confirms that shredding, burning, pulping, or pulverizing paper records satisfies this standard. Physical shredding by an industrial plant — with documented chain of custody and a notarized Certificate of Destruction — is the accepted standard because it provides both the physical destruction and the documented proof of compliance that auditors require. Placing medical records in recycling bins, standard dumpsters, or passing them to an uncertified collection service does not satisfy HIPAA.
Massachusetts M.G.L. c. 111, §70 requires medical providers to retain adult patient records for at least seven years from the date of last treatment. Minor patient records must be retained until the patient reaches age 21, or for seven years from the date of last treatment — whichever period is longer. HIPAA separately requires covered entities to retain their HIPAA policies, procedures, and documentation for six years from creation or last effective date. Billing records should be retained for seven years given the Medicare and Medicaid fraud statute of limitations. Lab reports are subject to CLIA requirements of up to 10 years for cytology records. Once these periods are met, records should be destroyed — continued indefinite storage of PHI that should have been destroyed years ago creates ongoing breach liability without any compliance benefit. Our full Massachusetts document retention schedule covers all record types.
Yes — and we have one ready. The HIPAA Omnibus Rule requires covered entities to have a signed Business Associate Agreement in place before disclosing PHI to any business associate, including a shredding vendor. Our BAA documents our obligations as a business associate, our safeguards for PHI in our custody, our breach notification obligations, and our commitment to destroy PHI and not use it for any purpose other than the contracted destruction service. We provide signed BAAs on written request at no additional cost. Contact us at (978) 636-0301 or through our booking form and we will have a signed BAA to you before any PHI changes hands.
The HIPAA Security Rule (45 CFR §164.310(d)(2)(i)) requires covered entities to implement policies for the final disposal of electronic PHI and the hardware on which it is stored. NIST Special Publication 800-88 identifies physical Destroy — shredding or disintegration of the media — as the highest and most certain level of sanitization for ePHI. Software erasure is unreliable on solid-state drives due to wear-leveling and overprovisioning; deleted ePHI may remain recoverable in unmapped sectors. Physical destruction of the storage media with a serial-number Certificate of Destruction is the accepted HIPAA-compliant standard for all ePHI-containing hardware. We provide this for HDDs, SSDs, NVMe drives, server drives, backup tapes, USB drives, tablets, and mobile devices. See our full IT asset disposal service page for details.
Yes. We provide on-site pickup at hospitals, physician practices, dental offices, behavioral health facilities, and all other healthcare settings throughout Greater Boston, the Merrimack Valley, Essex County, Worcester County, MetroWest, and southern New Hampshire. Our CORI-checked drivers transport all PHI in locked vehicles under documented chain of custody from your facility to our certified Tewksbury plant. A signed intake receipt is provided at your facility before our driver departs. We accommodate both scheduled recurring service (with locked consoles at your location) and one-time or annual purge pickups. Call (978) 636-0301 to discuss your facility’s specific volume and scheduling needs.
HHS Office for Civil Rights enforces HIPAA and can impose civil monetary penalties ranging from $100 per violation for unknowing violations to $50,000 per violation for willful neglect. The maximum penalty is $1.9 million per calendar year for identical violations. Criminal penalties under HIPAA can reach $250,000 and 10 years imprisonment for the most serious offenses involving intent to sell PHI. OCR has settled numerous cases involving improper PHI disposal — including cases where patient records were found in dumpsters or sold to recycling companies — for amounts ranging from $10,000 to millions of dollars. Beyond federal penalties, Massachusetts M.G.L. c. 93H requires breach notification to the Attorney General and affected patients, and private plaintiffs may have civil claims under state law. Our guide to what documents should be shredded explains the broader disposal obligations beyond medical records specifically.
Yes. We handle all categories of behavioral health records, including psychotherapy notes, psychiatric treatment records, and substance use treatment records subject to the heightened federal protections of 42 CFR Part 2. These records carry additional confidentiality requirements beyond standard HIPAA, but the disposal standard is the same: physical shredding that renders them unreadable, indecipherable, and unable to be reconstructed, with a notarized Certificate of Destruction. Our staff treat all PHI with the same confidentiality protocols regardless of the record type. Our Business Associate Agreement covers all categories of PHI including behavioral health records.
Ready to destroy PHI the right way? One call. Flat rate. Notarized Certificate of Destruction.
BAA available on request. HIPAA compliance filing included. Serving hospitals, practices, labs, and every type of healthcare organization throughout Greater Boston and New England since 2007.