HIPAA Compliance Policy¶
Last Updated: April 2026 Target Audience: Management, IT Manager, Operations Manager, All Employees Handling Healthcare Customer Materials Effective Date: April 7, 2026
This policy establishes Scott Recycling's obligations under the Health Insurance Portability and Accountability Act of 1996 (HIPAA), as amended by the HITECH Act and the HIPAA Omnibus Final Rule. Scott Recycling acts as a Business Associate when providing recycling and data destruction services to healthcare organizations (Covered Entities).
Why This Matters¶
Healthcare customers — hospitals, clinics, medical groups, and their affiliates — are legally required to protect patient data called Protected Health Information (PHI). When Scott Recycling picks up, transports, stores, or destroys materials from these customers, we may encounter PHI on paper records, hard drives, labels, equipment, or other media. This makes us a Business Associate under HIPAA, and we are directly liable under federal law for how we handle that information.
HIPAA Violations Are Serious
Penalties for HIPAA violations range from $100 to $50,000 per violation, up to $1.5 million per year for each violation category. Criminal penalties can include fines up to $250,000 and imprisonment up to 10 years. Individual employees can be held personally liable.
Key Definitions¶
| Term | Definition |
|---|---|
| Protected Health Information (PHI) | Any individually identifiable health information — patient names, addresses, dates of birth, Social Security numbers, medical record numbers, diagnoses, treatment information, insurance information, or any data that could identify a patient |
| Electronic PHI (ePHI) | PHI stored or transmitted in electronic form — hard drives, USB drives, backup tapes, servers, phones, tablets, CDs/DVDs |
| Covered Entity | A healthcare provider, health plan, or healthcare clearinghouse that is subject to HIPAA (our healthcare customers) |
| Business Associate | A company that performs services for a Covered Entity and may access PHI in the process (Scott Recycling) |
| Business Associate Agreement (BAA) | A legal contract between a Covered Entity and Business Associate that establishes HIPAA obligations |
| Breach | An impermissible use or disclosure of PHI that compromises the security or privacy of the information |
| Minimum Necessary Standard | The requirement to limit PHI access, use, and disclosure to the minimum amount needed to accomplish the task |
Scope¶
This policy applies to:
- All employees who pick up, transport, receive, sort, process, or destroy materials from healthcare customers
- All managers and supervisors who oversee work involving healthcare customer materials
- IT staff who manage systems containing records related to healthcare customers
- Any subcontractors or temporary workers who may encounter healthcare customer materials
The Three HIPAA Rules¶
1. The Privacy Rule¶
The Privacy Rule governs how PHI can be used and disclosed.
Scott Recycling's obligations:
- Use PHI only as needed to perform our contracted services (pickup, transport, destruction)
- Apply the Minimum Necessary Standard — do not read, copy, or share PHI beyond what is required for the job
- Never sell PHI or use it for marketing, research, or any purpose outside our service agreement
- Support individual rights — if a healthcare customer forwards a patient's request to access, amend, or get an accounting of their PHI, we must assist (see Individual Rights section below)
2. The Security Rule¶
The Security Rule requires administrative, physical, and technical safeguards to protect ePHI.
Administrative Safeguards:
| Safeguard | Scott Recycling Implementation |
|---|---|
| Security Officer designation | IT Manager serves as the HIPAA Security Officer |
| Workforce training | All employees complete HIPAA training at hire and annually |
| Access controls | Only authorized personnel handle healthcare customer materials |
| Incident procedures | Breach response plan documented and tested (see Breach Response Plan) |
| Risk assessment | Annual security risk assessment conducted and documented |
| Sanctions policy | HIPAA violations result in disciplinary action up to and including termination |
Physical Safeguards:
| Safeguard | Scott Recycling Implementation |
|---|---|
| Facility access controls | Secure staging area with restricted access for data-bearing devices |
| Workstation security | Processing workstations in controlled areas, not visible to visitors |
| Device controls | All data-bearing devices tracked by serial number from receipt to destruction |
| Disposal procedures | NIST 800-88 compliant data destruction (see Data Destruction Procedures) |
Technical Safeguards:
| Safeguard | Scott Recycling Implementation |
|---|---|
| Access controls | Role-based access in Odoo — only authorized users can view healthcare customer records |
| Audit controls | System logs track who accesses healthcare customer records and when |
| Integrity controls | Serial number tracking ensures no devices are lost between receipt and destruction |
| Transmission security | Certificates of Destruction sent via secure methods; customer records stored in access-controlled systems |
3. The Breach Notification Rule¶
If a breach of unsecured PHI occurs, Scott Recycling must:
- Notify the Covered Entity within 5 business days of discovering the breach
- Provide details including what happened, what PHI was involved, who was affected, and what we are doing about it
- Cooperate with the Covered Entity's investigation and notification to affected individuals and HHS
See the full HIPAA Breach Response Plan for step-by-step procedures.
Identifying Healthcare Customers and PHI¶
How to Know If a Customer Is a Covered Entity¶
Healthcare customers include but are not limited to:
- Hospitals and hospital systems
- Medical groups and physician practices
- Dental offices
- Clinics (urgent care, specialty, outpatient)
- Nursing homes and long-term care facilities
- Health insurance companies
- Pharmacies
- Mental health and substance abuse facilities
- Medical laboratories
When In Doubt, Ask
If you are unsure whether a customer is a healthcare organization, ask your supervisor. It is better to treat materials as PHI-containing and be wrong than to treat PHI casually and cause a breach.
Where PHI Can Appear¶
PHI is not limited to hard drives. Watch for it on:
- Paper records — patient charts, billing records, insurance forms, prescription labels, appointment schedules
- Labels on equipment — patient name labels on hospital PCs, printers, monitors
- Hard drives and storage media — electronic medical records, patient databases
- Phones and tablets — patient communication apps, photos, voicemails
- Copiers and printers — internal storage that may contain scanned/printed patient records
- Shipping labels and manifests — may contain patient or facility information
- Sticky notes, printouts, and loose papers found inside equipment
PHI Handling Procedures¶
At Pickup (Drivers)¶
- Keep healthcare customer materials separate from other customers' materials on the truck when feasible
- Do not read paper records or documents found in or with the equipment
- Secure the load — ensure materials cannot fall out, be accessed by unauthorized persons, or be exposed during transport
- Report any loose PHI (papers with patient names, medical information) to your supervisor immediately
- Never photograph patient records or PHI-containing labels
At Receiving (Warehouse)¶
- Identify the customer — check if the incoming shipment is from a healthcare customer
- Segregate healthcare materials — route data-bearing devices from healthcare customers to the secure staging area immediately
- Handle paper records carefully — any paper PHI found in or with equipment must be collected and routed to secure destruction (cross-cut shredding or incineration)
- Do not leave PHI unattended — healthcare customer materials should not sit on open warehouse floor
During Processing¶
- Follow chain of custody — every data-bearing device from a healthcare customer must be tracked per the Data Destruction Procedures
- Destroy data to NIST 800-88 standards — software wipe (Purge level minimum) or physical destruction
- Destroy paper PHI — cross-cut shred any paper records; do not place in general recycling or trash
- Issue Certificates of Destruction — healthcare customers require these as proof of HIPAA-compliant destruction
In the Office / Systems¶
- Restrict access to healthcare customer records in Odoo to authorized personnel only
- Do not email PHI — do not send patient names, medical record numbers, or other PHI via email unless encrypted
- Store BAAs securely — Business Associate Agreements must be retained for the duration of the relationship plus 6 years
- Log access — document who accesses healthcare customer records and for what purpose
Risk Assessment¶
Scott Recycling conducts an annual HIPAA Security Risk Assessment to identify vulnerabilities in how we handle PHI/ePHI.
Risk Assessment Process¶
- Inventory PHI touchpoints — identify everywhere PHI enters, moves through, and exits our operations
- Identify threats — what could go wrong (theft, loss, improper disposal, unauthorized access, system breach)
- Assess current controls — what safeguards are already in place
- Determine risk levels — likelihood x impact for each threat
- Document findings — maintain a written risk assessment report
- Create a remediation plan — address identified gaps with specific actions, owners, and deadlines
- Review and update — reassess annually or whenever significant changes occur (new services, new systems, incidents)
Risk Assessment Schedule¶
| Activity | Frequency | Owner |
|---|---|---|
| Full risk assessment | Annually (Q1) | IT Manager / HIPAA Security Officer |
| Risk remediation review | Quarterly | IT Manager |
| Post-incident risk review | After any breach or security incident | IT Manager + Management |
| New customer/service risk review | Before onboarding a new healthcare customer | Management + IT Manager |
The risk assessment report and remediation plan are maintained by the IT Manager and available for review by management and auditors.
Subcontractors and Downstream Vendors¶
If Scott Recycling uses any subcontractor, vendor, or agent that may create, receive, maintain, or transmit PHI on our behalf, we must:
- Execute a written agreement (BAA or equivalent) with the subcontractor imposing the same HIPAA restrictions and safeguards
- Verify the subcontractor's compliance — confirm they have appropriate data security practices
- Monitor the relationship — periodically verify the subcontractor continues to meet requirements
- Accept liability — Scott Recycling remains fully responsible for the acts and omissions of our subcontractors
Downstream Vendors
This includes any vendor who transports, stores, processes, or destroys materials that may contain PHI from our healthcare customers. If a downstream recycler or scrap processor receives materials from a healthcare customer's shipment, they need appropriate agreements in place.
Individual Rights¶
Under HIPAA, patients have rights regarding their PHI. If a healthcare customer (Covered Entity) contacts Scott Recycling to assist with fulfilling a patient's rights request, we must cooperate:
| Right | Our Obligation |
|---|---|
| Right of Access | If we maintain any PHI for a healthcare customer, provide access to it within 30 days of request |
| Right to Amendment | If requested, amend PHI in our records (e.g., correct a serial number linked to a patient) |
| Right to Accounting of Disclosures | Provide a log of any disclosures of PHI we have made (other than for treatment, payment, or operations) going back 6 years |
In practice, Scott Recycling's primary function is to destroy PHI, not maintain it. These requests will be rare, but we must have a process to respond. Route any such request to the IT Manager immediately.
Record Retention (HIPAA-Specific)¶
| Record | Retention Period | Notes |
|---|---|---|
| Business Associate Agreements | Duration of relationship + 6 years | Federal HIPAA minimum |
| HIPAA policies and procedures | 6 years from date created or last effective | Federal HIPAA minimum |
| Risk assessment reports | 6 years | Federal HIPAA minimum |
| Training records (HIPAA) | 6 years from date of training | Federal HIPAA minimum |
| Breach investigation records | 6 years | Federal HIPAA minimum |
| Destruction records for healthcare customers | 7 years | Per our data destruction policy (exceeds HIPAA minimum) |
| Certificates of Destruction | 7 years | Per our data destruction policy |
Sanctions Policy¶
Violations of this HIPAA policy will result in disciplinary action based on the severity of the violation:
| Violation Level | Examples | Consequence |
|---|---|---|
| Unintentional / Minor | Forgetting to segregate healthcare materials, not following proper handling on first occurrence | Verbal warning + retraining |
| Negligent | Leaving PHI unattended, failing to report a potential breach, repeated minor violations | Written warning + mandatory retraining |
| Serious | Reading or sharing PHI unnecessarily, failing to destroy PHI, ignoring breach reporting | Suspension + formal investigation |
| Willful / Malicious | Stealing PHI, selling data, intentional unauthorized disclosure | Termination + referral to law enforcement |
Roles and Responsibilities¶
| Role | HIPAA Responsibilities |
|---|---|
| Management | Overall HIPAA compliance oversight, BAA execution, resource allocation, sanctions enforcement |
| IT Manager (HIPAA Security Officer) | Risk assessments, policy maintenance, technical safeguards, breach investigation, training coordination, HHS audit support |
| Operations Manager | Physical safeguards, PHI handling procedures enforcement, subcontractor oversight |
| Team Leaders | Ensure team members follow PHI handling procedures, report incidents immediately |
| Drivers | Secure transport of healthcare customer materials, report loose PHI |
| Warehouse / Processing Staff | Segregate healthcare materials, follow chain of custody, destroy PHI properly |
| Office / CSR Staff | Restrict access to healthcare customer records, do not email PHI, route rights requests to IT Manager |
Active Business Associate Agreements¶
| Covered Entity | BAA Effective Date | Signed By | Services Covered |
|---|---|---|---|
| Java Medical Group, LLC | April 7, 2026 | Tim Snider (IT Director, Java Medical) | Electronics recycling, data destruction |
This table must be updated whenever a new BAA is signed or an existing BAA is terminated.
Related Documents¶
- HIPAA Breach Response Plan — Step-by-step breach notification procedures
- Data Destruction Procedures — NIST 800-88 compliant destruction methods, chain of custody, certificates
- Workplace Safety — Physical safeguards, facility security
- HIPAA Training — Employee training course
- Employee Handbook — General company policies
Questions? Contact the IT Manager (HIPAA Security Officer) or your supervisor.