When we think about HIPAA requirements, many of us think electronic security measures. That’s a good thing – but don’t stop there!

Review the oldest charts and papers containing PHI that are being stored in the facility or offsite. Do NOT save any papers or charts that are unnecessary or past the requirement date for your State, Centers for Medicare and Medicaid, or any other regulatory organization that mandates the length of time patient data needs to be saved.

Check to see that there are NO OLD tapes, discs or Xrays that the organization would no longer have any use for. Additionally, do not store old computers that still have hard drives in them and would potentially have patient data.

Enlist your IT vendor and/or shredding company to properly dispose of all data containing PHI.

