Shredding manifests and wiping old phones: HIPAA disposal rules for NEMT records
Overview
HIPAA names no single disposal method, but it requires reasonable safeguards through disposal (45 CFR 164.530(c)) and written procedures to remove rider data from devices before reuse or disposal (164.310(d)(2)). For paper, HHS names shredding, burning, pulping, or pulverizing; for electronic media, clearing, purging, or destroying. Records may not go into public dumpsters or recycling bins unless they are already unreadable.
On this page
What HIPAA requires when records are thrown away
HIPAA leaves the method to you but holds you to the result: rider information has to stay protected all the way to its destruction. Two rules carry that duty. Under the Privacy Rule, health information in every form, from a printed manifest to a phone call, must be guarded by suitable administrative, technical, and physical safeguards (45 CFR 164.530(c)), and HHS reads that duty as running through disposal. The Security Rule adds two required procedures for electronic data: policies for the final disposition of rider data and the hardware it sits on, and steps to remove that data from any device or media before it is reused (45 CFR 164.310(d)(2)(i) and (ii)). A third item, keeping a record of where hardware and media move and who is responsible for them, is addressable.
Broker contracts are one way these rules reach a NEMT company. MTM’s standard agreement requires providers to sign its business associate agreement, and WellTrans’s Indiana agreement attaches a subcontractor business associate agreement as Exhibit C. The HIPAA guide for NEMT providers explains how that works.
HHS’s disposal guidance adds three points that shape every policy below:
- No dumping. Patient information may not be abandoned or tossed into any dumpster or bin that the public or other unauthorized people can get into.
- Fit the method to the risk. Weigh the form, type, and amount of information. HHS singles out names, Social Security numbers, driver’s license numbers, card numbers, diagnoses, and treatment details as warranting more care.
- Train the people who do it. Every workforce member who disposes of patient information, or supervises someone who does, needs training on the disposal policy. That includes volunteers.
HIPAA does not say when a record may be destroyed. HHS says the Privacy Rule sets no medical record retention period and leaves that to state law, so the clock is set by your state’s Medicaid rules and by each broker contract; the NEMT documentation requirements guide lists those periods.
Paper: manifests, trip logs, and printed schedules
Paper with a rider’s name on it must be shredded, burned, pulped, or pulverized so it is “essentially unreadable, indecipherable, and otherwise cannot be reconstructed.” That is HHS’s standard, and its breach guidance treats paper destroyed that way as secured. The same guidance excludes redaction as a way of destroying data, so blacking out names on a manifest with a marker does not count.
What that looks like in a NEMT company:
- A locked shred bin in the office, emptied by a vendor or run through the office shredder on a fixed day. HHS also allows keeping paper in a secure area until a disposal vendor picks it up.
- A rule for paper in the vans. HHS says a covered entity may require staff who use patient information off-site to return it for disposal, or may let them shred it themselves where appropriate. Pick one and write it into the driver policy. Brokers expect the same: Modivcare’s Mississippi provider manual asks providers to shred trip logs, manifests, and other papers carrying rider information before throwing them out.
- Sanctions that are actually applied. HHS says that when workforce members ignore the disposal policy, the covered entity must apply appropriate sanctions (45 CFR 164.530(e)).
Locked dumpsters are a narrow exception. HHS allows them only in justifiable cases, based on the size and type of the business and the nature of the information, and only when the dumpster is reachable by authorized people such as the refuse workers. The HIPAA guide for drivers covers what drivers may leave in the van during the day.
Phones, tablets, laptops, and copier drives
Any device that held rider data needs that data removed before it is reused, returned, sold, or thrown out. HHS describes three ways to do it: clearing (overwriting the storage with non-sensitive data), purging (degaussing magnetic media with a strong magnetic field), or destroying the media by disintegrating, pulverizing, melting, incinerating, or shredding it. For practical detail it points to NIST Special Publication 800-88, whose second revision was published in September 2025.
The current NIST guide changes some old habits:
- Clear removes data using the device’s normal interface, such as overwriting it or a menu reset to factory state. On a basic phone or office machine that offers nothing else, a manufacturer reset counts, as long as the normal interface cannot bring the data back.
- Purge makes recovery infeasible even in a laboratory while leaving the device usable. NIST says purge should be used instead of clear whenever possible, and it singles out cryptographic erase, which sanitizes the encryption key on an encrypted device, for how fast it works.
- Destroy is the only method for paper and the fallback for broken or obsolete devices. Bending, cutting, or drilling a hole through a drive may leave parts of it readable.
- Flash storage is different. Phones, tablets, and solid-state drives spread data across spare cells, so overwriting cannot reach all of it, and degaussing should not be used on them at all.
Make an inventory of every device that touches rider data: driver phones, tablets mounted in vans, dispatch laptops, and the office copier, which may keep copies of scanned pages on an internal hard drive. Before a leased copier goes back, a phone moves to a new driver, or a van with its tablet is returned or sold, sanitize the device and record it. NIST counts a device returned from a lease, donated, or resold as leaving your control, and notes that some laws treat unsanitized media leaving your control as a data breach. How to lock and wipe a phone that goes missing is covered in company phones for NEMT drivers, and what to pull or wipe before a van changes hands is in selling a used wheelchair van.
Shredding vendors and certificates of destruction
Sign a business associate agreement with any shredding or e-waste company before it touches rider information. HHS confirms that a covered entity may hire a business associate to pick up paper or electronic media, shred, burn, pulp, or pulverize it, purge or destroy the media, and take the remains to a landfill, as long as a contract requires the vendor to safeguard the information through disposal.
To choose a vendor, borrow the due diligence the FTC lists for record destruction contracts under its Disposal Rule (16 CFR 682.3(b)(3)): review an independent audit of the vendor’s operations, check several references, look for certification by a recognized trade association, and read the vendor’s own security policies.
Ask for a certificate with every job and file it. NIST’s sample certificate of sanitization shows what a good one holds for each device: make, model, serial number, media type, the method used (clear, purge, or destroy), the technique and tool, how the result was verified, and the name, title, date, location, and signature of the person who did it. The same form works for paper, since NIST lists hard copy as a media type. Brokers can ask for this proof: WellTrans’s Indiana agreement requires a provider that destroys WellTrans rider data to certify the destruction.
Background reports and other driver records
Background check reports follow a second federal disposal rule. The FTC’s Disposal Rule (16 CFR Part 682) applies to any business that keeps information from a consumer report for a business purpose. A background report bought to decide whether to hire a driver is a consumer report as the Fair Credit Reporting Act defines it (15 U.S.C. 1681a(d)). “Disposal” includes selling, donating, or transferring a computer that holds them, not just throwing paper away. The rule’s examples of reasonable measures: burn, pulverize, or shred the paper, and destroy or erase the electronic copies, so the reports cannot practicably be read or reconstructed.
How long to keep those reports, and every other hiring and payroll record, is in employee record retention for NEMT companies. The background check guide covers ordering and reviewing them.
When records must not be destroyed yet
Destroy a record only after its longest retention period has run, and never while someone is looking at it. Watch for three situations:
- An audit, review, or investigation. WellTrans’s Indiana agreement forbids providers to destroy records while they are being audited, reviewed, or investigated. As soon as a lawsuit or claim looks likely, a litigation hold freezes trip records, GPS data, and video as well.
- A broker contract ending. At the end of the contract, a business associate returns or destroys all protected health information it still holds, where that can be done, and keeps no copies. Anything it has to keep stays under the contract’s protections for as long as it is kept (45 CFR 164.504(e)(2)(ii)(J)).
- Closing the business. HHS suggests a covered entity winding up its business consider giving patients the chance to pick up their records before disposal, and notes that many states require records to be kept and made available for a time after dissolution. The guide to closing a NEMT business covers the full sequence.
What disposal mistakes have cost other health businesses
HHS’s Office for Civil Rights has settled disposal cases with a health plan, a hospital system, a single-location pharmacy, and a dermatology practice. Three of these four turned on paper or printed labels, and one on copier hard drives:
| Case | Settlement | What went wrong |
|---|---|---|
| Affinity Health Plan, August 2013 | $1,215,780 | Returned leased photocopiers without erasing hard drives holding data on up to 344,579 people, and left the copiers out of its risk analysis |
| Parkview Health System, June 2014 | $800,000 | Left 71 boxes of records on about 5,000 to 8,000 patients unattended on a retiring doctor’s driveway, within 20 feet of the road |
| Cornell Prescription Pharmacy, April 2015 | $125,000 | Put unshredded papers on 1,610 patients in an unlocked, open container, with no written policies or staff training |
| New England Dermatology and Laser Center, August 2022 | $300,640 | Threw specimen containers labeled with patient names and birth dates into a parking lot dumpster from 2011 to 2021 |
Cornell was a single-location pharmacy, and OCR said at the time that organizations of any size may not abandon patient information or put it in containers the public can reach. The Parkview and Cornell settlements both required written policies and staff training. A five-van company can do the same work before anyone asks: write the disposal policy, make sure each driver and dispatcher has been trained on it, and keep the certificates.
Less paper in the vans with HealthRide
The fewer manifests you print, the fewer you have to shred. Drivers using the HealthRide driver app work from the day’s rides on their phone rather than a printed sheet, and rider details stay off phone lock screens. Back at the office, HealthRide is HIPAA compliant, and staff see only what their role allows.
Frequently asked questions
- Can shredded manifests go in the regular trash or recycling?
- Yes, once the shredding leaves them unreadable and impossible to put back together. HHS says paper with patient information may not go into dumpsters, recycling bins, or trash cans the public can reach unless it has been rendered essentially unreadable first. Whole manifests, trip logs, and printed schedules never go into a bin as they are.
- Is a factory reset enough before a company phone is reassigned or sold?
- Often it is the minimum, not the best option. NIST SP 800-88 Rev. 2 counts a manufacturer reset as a clear technique when that is all the device offers and the normal interface cannot bring the data back. NIST prefers purge methods, such as cryptographic erase on an encrypted device, whenever they are available. A phone that will leave your control for good, or that no longer works, can simply be destroyed.
- Do drivers have to bring printed manifests back to the office?
- That is your call, as long as the policy is written and followed. HHS says a covered entity may require staff who use patient information off-site to return it for disposal, or may let them shred it themselves when that is appropriate. Either way, drivers need training on the policy, and the company must apply sanctions when someone does not follow it.
- Does a shredding vendor count as a business associate?
- Yes, if it picks up or destroys rider information for you, so a business associate agreement comes first. HHS allows covered entities to hire a business associate to dispose of protected health information, and the arrangement requires a contract that obliges the vendor to safeguard the information through disposal. Have it signed before the vendor collects anything, and file each certificate of destruction it returns.
- Is there a minimum time to hold trip records before destroying them?
- Not under HIPAA. HHS says state law generally governs, and each Medicaid program or broker contract sets its own period: North Dakota seven years, New York six years from payment, and MTM and WellTrans contracts ten. HIPAA does require its own documentation, such as policies and risk analyses, to be kept six years.
- What happens to rider data when a broker contract ends?
- A business associate must, at the end of the contract, return or destroy all protected health information it still holds if that is feasible, and keep no copies. Where returning or destroying it cannot be done, the protections continue for as long as the information is kept. WellTrans's Indiana agreement adds that a provider who chooses destruction must certify it to WellTrans.