Skip to content

HIPAA Compliance Policy

Last Updated: April 2026 Target Audience: Management, IT Manager, Operations Manager, All Employees Handling Healthcare Customer Materials Effective Date: April 7, 2026

This policy establishes Scott Recycling's obligations under the Health Insurance Portability and Accountability Act of 1996 (HIPAA), as amended by the HITECH Act and the HIPAA Omnibus Final Rule. Scott Recycling acts as a Business Associate when providing recycling and data destruction services to healthcare organizations (Covered Entities).


Why This Matters

Healthcare customers — hospitals, clinics, medical groups, and their affiliates — are legally required to protect patient data called Protected Health Information (PHI). When Scott Recycling picks up, transports, stores, or destroys materials from these customers, we may encounter PHI on paper records, hard drives, labels, equipment, or other media. This makes us a Business Associate under HIPAA, and we are directly liable under federal law for how we handle that information.

HIPAA Violations Are Serious

Penalties for HIPAA violations range from $100 to $50,000 per violation, up to $1.5 million per year for each violation category. Criminal penalties can include fines up to $250,000 and imprisonment up to 10 years. Individual employees can be held personally liable.


Key Definitions

Term Definition
Protected Health Information (PHI) Any individually identifiable health information — patient names, addresses, dates of birth, Social Security numbers, medical record numbers, diagnoses, treatment information, insurance information, or any data that could identify a patient
Electronic PHI (ePHI) PHI stored or transmitted in electronic form — hard drives, USB drives, backup tapes, servers, phones, tablets, CDs/DVDs
Covered Entity A healthcare provider, health plan, or healthcare clearinghouse that is subject to HIPAA (our healthcare customers)
Business Associate A company that performs services for a Covered Entity and may access PHI in the process (Scott Recycling)
Business Associate Agreement (BAA) A legal contract between a Covered Entity and Business Associate that establishes HIPAA obligations
Breach An impermissible use or disclosure of PHI that compromises the security or privacy of the information
Minimum Necessary Standard The requirement to limit PHI access, use, and disclosure to the minimum amount needed to accomplish the task

Scope

This policy applies to:

  • All employees who pick up, transport, receive, sort, process, or destroy materials from healthcare customers
  • All managers and supervisors who oversee work involving healthcare customer materials
  • IT staff who manage systems containing records related to healthcare customers
  • Any subcontractors or temporary workers who may encounter healthcare customer materials

The Three HIPAA Rules

1. The Privacy Rule

The Privacy Rule governs how PHI can be used and disclosed.

Scott Recycling's obligations:

  • Use PHI only as needed to perform our contracted services (pickup, transport, destruction)
  • Apply the Minimum Necessary Standard — do not read, copy, or share PHI beyond what is required for the job
  • Never sell PHI or use it for marketing, research, or any purpose outside our service agreement
  • Support individual rights — if a healthcare customer forwards a patient's request to access, amend, or get an accounting of their PHI, we must assist (see Individual Rights section below)

2. The Security Rule

The Security Rule requires administrative, physical, and technical safeguards to protect ePHI.

Administrative Safeguards:

Safeguard Scott Recycling Implementation
Security Officer designation IT Manager serves as the HIPAA Security Officer
Workforce training All employees complete HIPAA training at hire and annually
Access controls Only authorized personnel handle healthcare customer materials
Incident procedures Breach response plan documented and tested (see Breach Response Plan)
Risk assessment Annual security risk assessment conducted and documented
Sanctions policy HIPAA violations result in disciplinary action up to and including termination

Physical Safeguards:

Safeguard Scott Recycling Implementation
Facility access controls Secure staging area with restricted access for data-bearing devices
Workstation security Processing workstations in controlled areas, not visible to visitors
Device controls All data-bearing devices tracked by serial number from receipt to destruction
Disposal procedures NIST 800-88 compliant data destruction (see Data Destruction Procedures)

Technical Safeguards:

Safeguard Scott Recycling Implementation
Access controls Role-based access in Odoo — only authorized users can view healthcare customer records
Audit controls System logs track who accesses healthcare customer records and when
Integrity controls Serial number tracking ensures no devices are lost between receipt and destruction
Transmission security Certificates of Destruction sent via secure methods; customer records stored in access-controlled systems

3. The Breach Notification Rule

If a breach of unsecured PHI occurs, Scott Recycling must:

  1. Notify the Covered Entity within 5 business days of discovering the breach
  2. Provide details including what happened, what PHI was involved, who was affected, and what we are doing about it
  3. Cooperate with the Covered Entity's investigation and notification to affected individuals and HHS

See the full HIPAA Breach Response Plan for step-by-step procedures.


Identifying Healthcare Customers and PHI

How to Know If a Customer Is a Covered Entity

Healthcare customers include but are not limited to:

  • Hospitals and hospital systems
  • Medical groups and physician practices
  • Dental offices
  • Clinics (urgent care, specialty, outpatient)
  • Nursing homes and long-term care facilities
  • Health insurance companies
  • Pharmacies
  • Mental health and substance abuse facilities
  • Medical laboratories

When In Doubt, Ask

If you are unsure whether a customer is a healthcare organization, ask your supervisor. It is better to treat materials as PHI-containing and be wrong than to treat PHI casually and cause a breach.

Where PHI Can Appear

PHI is not limited to hard drives. Watch for it on:

  • Paper records — patient charts, billing records, insurance forms, prescription labels, appointment schedules
  • Labels on equipment — patient name labels on hospital PCs, printers, monitors
  • Hard drives and storage media — electronic medical records, patient databases
  • Phones and tablets — patient communication apps, photos, voicemails
  • Copiers and printers — internal storage that may contain scanned/printed patient records
  • Shipping labels and manifests — may contain patient or facility information
  • Sticky notes, printouts, and loose papers found inside equipment

PHI Handling Procedures

At Pickup (Drivers)

  1. Keep healthcare customer materials separate from other customers' materials on the truck when feasible
  2. Do not read paper records or documents found in or with the equipment
  3. Secure the load — ensure materials cannot fall out, be accessed by unauthorized persons, or be exposed during transport
  4. Report any loose PHI (papers with patient names, medical information) to your supervisor immediately
  5. Never photograph patient records or PHI-containing labels

At Receiving (Warehouse)

  1. Identify the customer — check if the incoming shipment is from a healthcare customer
  2. Segregate healthcare materials — route data-bearing devices from healthcare customers to the secure staging area immediately
  3. Handle paper records carefully — any paper PHI found in or with equipment must be collected and routed to secure destruction (cross-cut shredding or incineration)
  4. Do not leave PHI unattended — healthcare customer materials should not sit on open warehouse floor

During Processing

  1. Follow chain of custody — every data-bearing device from a healthcare customer must be tracked per the Data Destruction Procedures
  2. Destroy data to NIST 800-88 standards — software wipe (Purge level minimum) or physical destruction
  3. Destroy paper PHI — cross-cut shred any paper records; do not place in general recycling or trash
  4. Issue Certificates of Destruction — healthcare customers require these as proof of HIPAA-compliant destruction

In the Office / Systems

  1. Restrict access to healthcare customer records in Odoo to authorized personnel only
  2. Do not email PHI — do not send patient names, medical record numbers, or other PHI via email unless encrypted
  3. Store BAAs securely — Business Associate Agreements must be retained for the duration of the relationship plus 6 years
  4. Log access — document who accesses healthcare customer records and for what purpose

Risk Assessment

Scott Recycling conducts an annual HIPAA Security Risk Assessment to identify vulnerabilities in how we handle PHI/ePHI.

Risk Assessment Process

  1. Inventory PHI touchpoints — identify everywhere PHI enters, moves through, and exits our operations
  2. Identify threats — what could go wrong (theft, loss, improper disposal, unauthorized access, system breach)
  3. Assess current controls — what safeguards are already in place
  4. Determine risk levels — likelihood x impact for each threat
  5. Document findings — maintain a written risk assessment report
  6. Create a remediation plan — address identified gaps with specific actions, owners, and deadlines
  7. Review and update — reassess annually or whenever significant changes occur (new services, new systems, incidents)

Risk Assessment Schedule

Activity Frequency Owner
Full risk assessment Annually (Q1) IT Manager / HIPAA Security Officer
Risk remediation review Quarterly IT Manager
Post-incident risk review After any breach or security incident IT Manager + Management
New customer/service risk review Before onboarding a new healthcare customer Management + IT Manager

The risk assessment report and remediation plan are maintained by the IT Manager and available for review by management and auditors.


Subcontractors and Downstream Vendors

If Scott Recycling uses any subcontractor, vendor, or agent that may create, receive, maintain, or transmit PHI on our behalf, we must:

  1. Execute a written agreement (BAA or equivalent) with the subcontractor imposing the same HIPAA restrictions and safeguards
  2. Verify the subcontractor's compliance — confirm they have appropriate data security practices
  3. Monitor the relationship — periodically verify the subcontractor continues to meet requirements
  4. Accept liability — Scott Recycling remains fully responsible for the acts and omissions of our subcontractors

Downstream Vendors

This includes any vendor who transports, stores, processes, or destroys materials that may contain PHI from our healthcare customers. If a downstream recycler or scrap processor receives materials from a healthcare customer's shipment, they need appropriate agreements in place.


Individual Rights

Under HIPAA, patients have rights regarding their PHI. If a healthcare customer (Covered Entity) contacts Scott Recycling to assist with fulfilling a patient's rights request, we must cooperate:

Right Our Obligation
Right of Access If we maintain any PHI for a healthcare customer, provide access to it within 30 days of request
Right to Amendment If requested, amend PHI in our records (e.g., correct a serial number linked to a patient)
Right to Accounting of Disclosures Provide a log of any disclosures of PHI we have made (other than for treatment, payment, or operations) going back 6 years

In practice, Scott Recycling's primary function is to destroy PHI, not maintain it. These requests will be rare, but we must have a process to respond. Route any such request to the IT Manager immediately.


Record Retention (HIPAA-Specific)

Record Retention Period Notes
Business Associate Agreements Duration of relationship + 6 years Federal HIPAA minimum
HIPAA policies and procedures 6 years from date created or last effective Federal HIPAA minimum
Risk assessment reports 6 years Federal HIPAA minimum
Training records (HIPAA) 6 years from date of training Federal HIPAA minimum
Breach investigation records 6 years Federal HIPAA minimum
Destruction records for healthcare customers 7 years Per our data destruction policy (exceeds HIPAA minimum)
Certificates of Destruction 7 years Per our data destruction policy

Sanctions Policy

Violations of this HIPAA policy will result in disciplinary action based on the severity of the violation:

Violation Level Examples Consequence
Unintentional / Minor Forgetting to segregate healthcare materials, not following proper handling on first occurrence Verbal warning + retraining
Negligent Leaving PHI unattended, failing to report a potential breach, repeated minor violations Written warning + mandatory retraining
Serious Reading or sharing PHI unnecessarily, failing to destroy PHI, ignoring breach reporting Suspension + formal investigation
Willful / Malicious Stealing PHI, selling data, intentional unauthorized disclosure Termination + referral to law enforcement

Roles and Responsibilities

Role HIPAA Responsibilities
Management Overall HIPAA compliance oversight, BAA execution, resource allocation, sanctions enforcement
IT Manager (HIPAA Security Officer) Risk assessments, policy maintenance, technical safeguards, breach investigation, training coordination, HHS audit support
Operations Manager Physical safeguards, PHI handling procedures enforcement, subcontractor oversight
Team Leaders Ensure team members follow PHI handling procedures, report incidents immediately
Drivers Secure transport of healthcare customer materials, report loose PHI
Warehouse / Processing Staff Segregate healthcare materials, follow chain of custody, destroy PHI properly
Office / CSR Staff Restrict access to healthcare customer records, do not email PHI, route rights requests to IT Manager

Active Business Associate Agreements

Covered Entity BAA Effective Date Signed By Services Covered
Java Medical Group, LLC April 7, 2026 Tim Snider (IT Director, Java Medical) Electronics recycling, data destruction

This table must be updated whenever a new BAA is signed or an existing BAA is terminated.



Questions? Contact the IT Manager (HIPAA Security Officer) or your supervisor.